Answers

Is Claude safe for confidential data? (and Gemini, Copilot, DeepSeek)

Published 18 July 2026 · Updated 18 July 2026 · Occlira team

Short version: on their consumer tiers, none of them are safe for raw confidential data — each stores your chats and most use them to train by default. Business tiers are much better, but the data still leaves your device. This page compares Claude, Gemini, Copilot and DeepSeek provider-by-provider (for ChatGPT, see does ChatGPT store your data?), and shows the one control that works for all of them.

Short answer. Claude, Gemini and consumer Copilot all train on your chats by default (opt-out); Gemini even warns you not to enter confidential data; DeepSeek stores data in China and is banned in several countries. Enterprise tiers don’t train on your data — but the surest protection is to anonymize confidential material locally before you send it to any of them.

Anthropic Claude

Claude changed course in August 2025: on consumer plans (Free, Pro, Max) your chats are now used to train Anthropic’s models unless you opt out — a choice users had to make by 8 October 2025, with the toggle defaulting to on. (Source: Anthropic; TechCrunch.) Allowing training extends retention from 30 days to five years; flagged content can be kept up to two years (safety scores up to seven). (Source: Anthropic Privacy Center.) The good news: Claude for Work, the API and Claude Gov are not trained on by default, with a DPA. (Source: Anthropic.)

Google Gemini

Gemini is unusually blunt: Google’s own help page tells you “don’t enter confidential information that you wouldn’t want a reviewer to see” — because a subset of chats are read by human reviewers, and reviewed chats are kept for up to three years even if you delete your activity. (Source: Google — Gemini Apps Privacy Hub.) Consumer Gemini activity is used to improve Google’s products by default (you can turn it off), and there’s a separate, off-by-default setting for training on your audio and screen shares. Enterprise is different: Gemini for Google Workspace isn’t used to train Google’s models and isn’t human-reviewed outside your domain, with EU data-residency options. (Source: Google Workspace.)

Microsoft Copilot

Copilot is really two products. Consumer Copilot (a personal Microsoft account) uses your conversations — including uploaded files and voice — for AI training by default unless you opt out. (Source: Microsoft.) Microsoft 365 Copilot (the enterprise tier) is the opposite: Microsoft states prompts, responses and data accessed through Microsoft Graph are not used to train the foundation models, under a data-processing addendum with Microsoft as processor. (Source: Microsoft Learn.)

DeepSeek

DeepSeek is a different kind of risk. Its privacy policy says personal data is collected and stored in China, and that was enough for Italy’s regulator to block it in January 2025 for GDPR breaches. (Source: The Record.) Government restrictions followed in several countries — Italy, Australia, Taiwan and South Korea among them. (Source: TechCrunch.) For confidential or regulated data, treat DeepSeek as a firm no.

Side by side

AssistantConsumer trains on your chats by default?Notable pointBusiness tier
Claude (Anthropic)Yes, since Aug 2025 — opt outAllowing training extends retention to 5 yearsClaude for Work / API: not trained on, DPA available
Gemini (Google)Activity used to improve Google’s products — opt out; some chats human-reviewedReviewed chats kept up to 3 years even if you deleteWorkspace: not trained on, EU data-residency option
Copilot (Microsoft)Consumer Copilot: yes — opt outIncludes uploaded files and voiceMicrosoft 365 Copilot: not trained on, DPA
DeepSeekData stored in China; retainedBanned/restricted by Italy and several governmentsAvoid for confidential data
ChatGPT (OpenAI)Yes — opt outSee our full retention guideEnterprise / API: not trained on, DPA

The common thread — and the one control that works for all of them

Notice the pattern: on every consumer tier your data is stored and usually used for training; the enterprise tiers fix the training question but the data still leaves your machine and lands on the provider’s servers. So the answer to “which assistant is safe for confidential data?” isn’t really about picking the right one — it’s about not sending the confidential data in the first place. Anonymize it locally, and Claude, Gemini or Copilot are all equally safe to use on the anonymized copy. That local anonymization is exactly what Occlira does — on your own machine, for any assistant. The general risk picture is in is it safe to use ChatGPT with confidential data?

How Occlira makes any assistant safe to use

Occlira detects and removes personal data from documents, spreadsheets, email, audio and images entirely on your own computer — no cloud, no account. You anonymize a file locally, run whichever assistant you like on the anonymized copy, then restore the real values on your machine. It’s assistant-agnostic: nothing sensitive reaches Anthropic, Google, Microsoft or anyone else.

Occlira flagging personal data — names, an organization, dates, an address and a phone number — in a document for local review before it is sent to Claude, Gemini or Copilot.
Anonymize on your device first, and any AI assistant is safe to use on the copy.

One honest caveat: Occlira’s anonymization is reversible — in GDPR terms, pseudonymization — so the mapping (kept on your device) is still personal data. It’s strong local control, not a loophole. The step-by-step is in anonymize before ChatGPT (it works the same for any assistant).

Frequently asked questions

On consumer Claude (Free, Pro, Max), since August 2025 your chats are used to train Anthropic’s models unless you opt out — and allowing training extends retention from 30 days to five years. Claude for Work, the API and Claude Gov are not trained on by default and offer a DPA. Either way, the reliable protection for genuinely confidential material is to anonymize it before you paste.

On consumer plans, yes by default since the 28 August 2025 terms change — you had to make a training choice by 8 October 2025, and the toggle defaulted to on. You can switch it off in settings; declining keeps the 30-day retention instead of five years. Commercial tiers aren’t trained on by default.

Google’s own help page tells users not to enter confidential information into Gemini “that you wouldn’t want a reviewer to see” — because a subset of chats are read by human reviewers, and those reviewed chats are kept for up to three years even if you delete your activity. Consumer Gemini activity is used to improve Google’s products unless you turn it off.

It’s much stronger than the consumer tier: Google states Workspace customer content isn’t used to train its foundation models and isn’t human-reviewed outside your domain without permission, with EU/US data-residency controls and enterprise certifications. It’s governed by a data-processing addendum.

It depends on the tier. Consumer Copilot (personal Microsoft account) uses your conversations — including uploaded files and voice — for AI training by default unless you opt out. Microsoft 365 Copilot (the enterprise tier) does not use your prompts or data to train the foundation models, under a data-processing addendum.

DeepSeek’s privacy policy says personal data is collected and stored in China, and Italy’s regulator blocked it in January 2025 over exactly that, with government restrictions following in several countries. For confidential or regulated data, treat it as a no.

For confidential work, an enterprise/business tier with no-training terms and a DPA (Claude for Work, Microsoft 365 Copilot, Gemini for Workspace) beats any consumer account. But the most private option of all is to not send the sensitive data — anonymize it locally first, then any assistant is safe to use on the anonymized copy.

Remove the confidential parts before they’re sent. Occlira anonymizes the file on your own computer; you run Claude, Gemini, Copilot — any of them — on the anonymized copy, then restore the real values locally. There’s then nothing sensitive to store or train on, whichever assistant you choose.

Use any AI assistant safely

Anonymize locally, then use Claude, Gemini or Copilot on the copy. Free for 14 days on Windows and macOS.

More: use AI without breaking the GDPR · what is PII? · shadow AI at work · how your data is handled