Pyyan The AI Index ← All boxes

Checked against the vendors' own terms · 17 August 2026

Is my data safe with ChatGPT, Claude
and Gemini
?

Somebody in your office pasted an invoice into ChatGPT this week. Somebody else uploaded a bill of quantities to Claude with the client's name still on it. Was that fine? For some of them, yes. For others, no. Here is which.

The pattern nobody says out loud

The more you pay, the less they use it

These companies are not charities and running this costs them real money. So somebody pays. If it is not your credit card, it is your documents. That one sentence explains every row in every table further down this page.

  1. Free
    They use your data to train their AI

    You pay nothing, so they take your data instead. Everything you send them counts: what you type, the files you upload, the photos, the voice notes. All of it goes into training their AI. That is the deal on every free version here. There is no free version where it is not the deal.

  2. Around $20 a month
    They still use it, unless you turn it off

    Twenty dollars does not cover their costs. So they keep using your data, exactly as they did when it was free. One difference: there is now a switch in settings to stop it. The switch works. Almost nobody finds it.

  3. A company account, billed per use
    They never use it, and it is in writing

    The expensive one. Also the only one where "we will not use your data" sits in the contract you sign, instead of in a setting an employee has to remember. Nothing to switch on, so nobody can switch it back.

Read it top to bottom or bottom to top, it holds either way. Which is why the answer to is my data safe has almost nothing to do with whether you trust Google or Anthropic, and almost everything to do with which of these three you are on.

The short answer

It depends on the account it went through. Almost nothing else.

6 of 6

personal and free accounts use your data to train the model. Every one we could verify. There is usually a switch to stop it. Almost nobody finds it.

0 of 8

business and API accounts train on your data. Not as a setting you enabled, but as a term in the contract you already signed.

So stop looking for a safer vendor. There isn't one. Move your staff off personal logins instead. That one change beats everything else on this page put together.

The three questions people actually ask

Straight answers, no jargon

Four tools. Three questions. If you read nothing else here, read this.

1 Is our data used to train the AI?

You are on The free version A paid personal plan
about $20 a month
A company or developer account

Look at the first two columns. They are identical. Anthropic and OpenAI put the free plan and the paid personal plan in the same line of their own terms. So your twenty dollars bought faster answers and longer limits. It bought nothing here. Only the third column changes anything.

2 If we pay for the company version, is it actually safe?

Company account Do they learn from our documents? How long do they keep them? Can we ask them to keep nothing?

Yes. On a company account it is in the contract, not in a settings page. Nobody has to remember anything. Nobody can undo it by accident. That is the whole difference, and it is the reason to move.

3 Can our documents stay inside the UAE?

Company account Can you choose the country? Can it be the UAE?

Microsoft is the only one that will actually run in the UAE. Azure has a UAE North region. OpenAI will store data in the UAE but processes it elsewhere, and only if their sales team approves you. Google has no UAE region at all, the nearest are Doha and Dammam. So if the documents must stay in the country, that decides it before you compare anything else. One warning: a region existing is not the same as your model running in it. Check your own portal.

The question under the question

And if they did learn from our invoice, what is the actual harm?

Everybody waves at danger here and nobody says what it is. So here is what it is, and what it is not.

What people picture: somebody asks Claude a question and your client's contract comes back out. Forget that. It is not the risk. These models train on a staggering amount of writing. One invoice of yours is a drop in an ocean. They do not file it away and read it back to anybody. Models do sometimes repeat text word for word, but almost always text that appeared thousands of times online, not one quotation that went through once. If your fear is that a competitor will extract your pricing by asking nicely, that is close to the least likely thing on this page.

So the training is not what hurts you. Three other things do, and all three happen whether the model learns anything or not.

  1. You promised a client you would not. This is the big one, and it has nothing to do with technology. Your contracts, NDAs and tender conditions say their information stays with you. Put it through an account with training on and you have broken that. Nothing bad has to happen. Breaking it is the bad thing.
  2. It is kept, and kept things come back. Anything sitting on a server can be pulled out later. By a hack. By a court order. By the other side's lawyer in a dispute three years from now. That is true of every system you use and it is not special to AI, but a free account is the one place you have no contract governing it.
  3. People read some of it. Several free versions say outright that staff may read what you send. One of them warns you on screen not to enter anything confidential. That is not a machine learning from your data. That is a person reading it.

Who cannot risk it at all. Anything with people's personal details in it. Anything your industry regulates. And the few documents where the information is the business: an unreleased design, a formula, a bid somebody would pay to see. For those, the answer is stricter and you should treat it that way.

For everybody else. Move off free accounts. Not because the model will memorise your quotation, it will not. Because you promised a client, because you cannot check what you do not control, and because being on the right side of it costs almost nothing.

The small print, if you want it

The exact wording, vendor by vendor

This part is for whoever has to check it, or argue it with a client. Every line comes from the vendor's own policy, with the date on that document. Where a vendor says nothing, this says nothing. No guesses dressed up as facts.

Green is good for you, red is not. Tap any line to jump to what that vendor actually says. The pattern is the point: the red band stops exactly where personal accounts stop.

uses your data for training   does not train, but there is an exception   promises in writing not to train   could not be verified

Before you forward that other chart

Charts going around that will mislead you

Charts like this get forwarded around offices and go stale fast. Here is one that is circulating, checked line by line against the actual terms. It is wrong in fourteen places. Two of them would send you to the more dangerous option.

More on the country question

Which countries each one will run in

The short version. Microsoft is the only one of these with a listed UAE region. If in-country processing matters to you commercially, that narrows the choice on its own, and it is worth checking model availability in your own portal rather than trusting a regional list, including this one.

What this page does not know

What we could not find out

Any chart that answers everything guessed somewhere. Here is what we could not pin down, and why.

Monday morning

What to actually do about it

  1. Move everyone off personal accounts. This is not one of four things. It is the thing. Every red row on this page is a personal account. Every green one is a company account. One purchase order fixes the lot, and it costs about what your staff are already paying out of pocket.
  2. A paid personal plan is not a company plan. Twenty dollars buys features. It does not buy a different contract. The no-training promise lives in the company terms only, and no personal plan has it at any price.
  3. Strip the client's name before you send. You almost never need it. A bill of quantities works exactly as well without the client name, the site address and the contract number. Send the numbers. Keep the identity. Costs nothing, and it still protects you when somebody uses the wrong account.
  4. Decide the country question once, now. If your clients need the data to stay in the UAE, that narrows you to Microsoft. Decide it before somebody builds a system on the wrong one.

One thing to remember. This is not about whether the AI company is trustworthy. It is about which contract you are standing inside when you press send. Your staff are already using these tools. The only choice left is whether they do it through an account you control.

These policies change, sometimes without announcement. Every row here shows the document and the date it was read. Check it yourself before you sign anything. This page is a starting point, not an authority.