This content reflects the field as of October 2026.
Introduction
The moment to check a tool's data terms is before the first paste, and in practice most people check afterward or never. The check is short once you know what to look for.
This walkthrough follows one person through it. The coordinator, her company, her employer's policy, and the provider page she reads are all invented. The provider page is a composite, written to resemble the kind of page real providers publish, and it isn't any company's text. Where the walkthrough points to what real providers say, it cites their pages as read in October 2026.
The Starting Point
Renata is an HR coordinator at a company of about two hundred people. Each quarter she receives around sixty written comments from staff about their managers and teams, and she turns them into a two-page summary for the leadership group. It takes most of a day.
She has a personal subscription to an AI assistant that she uses at home, and it's good at summarizing. Her plan is to paste in the sixty comments and ask for themes. Before she does, she works through five checks.
Walking Through the Check
Step 1: Identify the arrangement
Renata's account is one she opened herself and pays for herself. That makes it a consumer account, under the provider's standard terms for individuals. Her company has no contract with this provider through her subscription, and nobody at the company has reviewed those terms.
She also checks whether the company has a tool of its own. It does. The intranet lists an AI assistant the company licensed last year, which staff reach through their work sign-in.
So the two options are different arrangements. The personal account is a consumer tool, and the company assistant is a work tool under a contract.
Step 2: Read the provider's data page for three things
She opens the privacy page for her personal assistant and looks for retention, human review, and training use. The invented page says the following.
Retention: Conversations are kept in your account until you delete them. Deleted conversations are removed from our systems within 30 days.
Review: A small share of conversations is read by trained reviewers to improve quality and safety. Reviewed conversations are stored separately for up to two years.
Training: Conversations may be used to improve our models. You can turn this off in your privacy settings.
Work accounts: Different terms apply to accounts provided by an organization.
Her answers are that the text would be kept, that a person might read it, and that it might be used for training unless she changes a setting.
Real pages follow a similar pattern. Google's page on its Gemini apps says human reviewers read some of the data it collects and asks users not to enter confidential information they wouldn't want a reviewer to see (Google 2026b). OpenAI's page on ChatGPT describes a training setting and says temporary chats may still be kept for up to 30 days (OpenAI n.d.-b). Anthropic's page on its consumer Claude products says a conversation flagged for safety review may be used whatever the user chose about model improvement (Anthropic 2026).
Step 3: Identify what's in the material
Renata looks at the comments as someone outside the company would. She finds three things.
- Names. Many comments name the writer's manager, and some name colleagues.
- Opinions about named people. "My manager cancels our one-to-ones" is personal information about the manager and, indirectly, about the writer.
- Employer-confidential content. Comments mention a planned reorganization and a client the company may lose.
The staff who wrote these comments were told they'd go to HR. Nobody told them the comments might go to an outside company.
Step 4: Check the employer's rule
She finds the company's policy on AI use. The invented policy says three things that apply here. Employee information may be processed only in company-approved systems. The licensed assistant is approved for internal documents. HR data may be entered into it only with identifying details removed and with the HR manager's agreement.
That settles the personal account, which isn't a company-approved system. Using it for these comments would break the policy whatever its settings were.
Step 5: Choose among the options
Three options remain.
- The approved tool, with the full comments. The policy rules this out for HR data.
- The approved tool, with de-identified comments. The policy permits this with her manager's agreement.
- No AI for this task. This is always available, and it costs her the day it costs now.
She chooses the second. She removes names, job titles, and team names from the comments, and takes out the two comments about the reorganization and the client, which she'll handle herself. Some comments could still identify a person through an unusual detail, so she rewrites those in general terms. She then asks her manager, who agrees.
Her personal assistant stays out of it. She'll go on using it for her own writing.
Key Considerations
The common mistake is to switch off training use and assume the material is now private. On Renata's invented page, turning off training would have left retention and human review exactly as they were. The same is true of the real pages cited above: each describes circumstances in which a conversation is kept or examined even though it isn't used for training. A training setting answers one question out of three.
A second mistake is to treat the provider's terms as the whole question. Even a provider with ideal terms wouldn't have made the personal account acceptable, because the employer's rule required an approved system. The provider's terms and the employer's rule are separate checks, and the material has to pass both.
The walkthrough doesn't show that consumer AI tools are unsafe. For Renata's own drafts the personal account is fine. The comments were the problem, because they contained other people's information held in confidence.
Summary
Renata identified the arrangement, read the terms for retention, review, and training use, looked at what the material contained, checked her employer's rule, and chose an option that passed every check. Her completed checklist follows.
- Arrangement: Personal consumer account. Not a work tool. The company has a licensed assistant.
- Provider terms: Conversations kept until deleted; some read by reviewers; used for training unless switched off.
- Material: Names, opinions about named colleagues, and employer-confidential content.
- Employer's rule: Employee information only in approved systems; HR data only de-identified and with the HR manager's agreement.
- Decision: Use the company's approved assistant with de-identified comments, after my manager agrees. Reason: the personal account fails the employer's rule and its terms allow retention and review; the approved tool is permitted for this material once identifying details are removed.
- Line 1 is answered before anything else, because the arrangement decides which terms apply.
- Line 2 records all three practices. The training setting alone would have answered a third of it.
- Line 3 describes the material by whose information it is.
- Line 4 comes from the policy's text.
- Line 5 gives the decision and a reason that refers back to the lines above it.
References
- Anthropic. 2026. "Is My Data Used for Model Training?" Anthropic Privacy Center. Updated March 16, 2026.
- Google. 2026b. "Gemini Apps Privacy Hub." Gemini Apps Help. Last updated September 24, 2026.
- OpenAI. n.d.-b. "Data Controls in ChatGPT." OpenAI Help Center. Accessed October 3, 2026.