No-training (training restrictions) explained — why one vendor gives two answers
Glossary entry 10. After entry 9 on zero operator access (not seen), this entry drills into requirement ③ of the four data-protection requirements: training restrictions. “ChatGPT trains on your chats but the API does not — is that true?” and “Am I safe on a paid plan?” have different answers for the same model from the same vendor, because the terms that apply depend on which layer you are using: consumer app, free tier, or API/commercial contract. This page splits OpenAI, Anthropic, Google, Microsoft and AWS into those three layers and quotes their own documents, including the exceptions that survive an opt-out so you can reuse the wording in internal reviews.
What decides whether your data trains a model is not which vendor you use but which contract and which layer.
Why the same vendor gives two answers
Training terms live in different documents per contract type. A consumer app's terms of service and a business commercial contract are separate documents with different content. There are three branches.
Branch ①
Consumer app, or API / commercial contract
The same vendor applies different documents to a consumer app (ChatGPT, Claude, Gemini) and to an API, Team or Enterprise contract. Generally the latter is the stricter, no-training side.
Branch ②
Free tier, or quota tied to a billing account
For Google the test is not whether money changed hands but whether a billing account is attached. Free usage can still be treated as a paid service, and this is the most misread part.
Branch ③
Exceptions that survive an opt-out
Even with training turned off, some vendors state that content you send as feedback or content flagged in a safety review is still used to train models.
Prerequisite
“Not trained on” is not “not seen”
Meeting requirement ③ says nothing about retention (①) or operator access (②). See the four requirements and ZOA.
Figure: the three branches. Which layer you use selects the document and therefore the answer (created by LLM Data Hub).
The answer up front: five providers split by layer
Confirmed from official documentation as of 2026-10-03. The key point of the table is that consumer terms and API/commercial terms are different documents.
| Provider | Consumer app / free tier | API / commercial contract |
|---|---|---|
| OpenAI | Services for individuals (ChatGPT, Sora, Operator) may be used to train models. Opt out via the privacy portal (“do not train on my content”) | Does not train by default (ChatGPT Team, ChatGPT Enterprise, API). Wording quoted in the body |
| Anthropic | Consumer (Free / Pro / Max) data may be used for training until you opt out. Even after opting out, feedback you send and content flagged for safety review are still used | Commercial terms prohibit training on Customer Content, except where the customer explicitly provides data (e.g. Development Partner Program) |
| Unpaid Services (AI Studio, free Gemini API quota) are used to provide, improve and develop products, with human review | Paid Services: prompts and responses are not used to improve products. Logged for a limited period only for abuse detection | |
| Microsoft | Consumer services under a Microsoft account (e.g. Copilot) are unverified on this page (separate document) | Azure AI services: “NOT used to train any generative AI foundation models without your permission or instruction.” Not shared with model providers |
| AWS | No consumer path (Amazon Bedrock is an API product) | “No, AWS and the third-party model providers will not use any inputs to or outputs from Amazon Bedrock to train Amazon Nova, Amazon Titan, or any third-party models.” |
← Scroll horizontally. “Unverified” means we could not confirm it in primary sources — not that the guarantee is absent.
Branch ① Consumer app, or API / commercial contract
This is where the split is sharpest, and one OpenAI sentence shows it best.
- It is not “free means trained on, paid means not trained”. OpenAI's line is consumer versus business (Team / Enterprise / API). A paid consumer plan still sits on the consumer side of that line by default.
- Anthropic puts the prohibition in the contract itself. Section B (Customer Content) of the Commercial Terms reads:
“As between the parties and to the extent permitted by applicable law, Anthropic agrees that Customer (a) retains all rights to its Inputs, and (b) owns its Outputs. Anthropic may not train models on Customer Content from Services.”— Anthropic, Commercial Terms of Service, B. Customer Content (retrieved 2026-10-03)Note the verb: “may not” — a contractual prohibition, which is a different kind of statement from a policy of “we do not train by default”.
- The exception is an explicit opt-in. Anthropic's own documentation explains that under commercial terms it does not train generative models on code or prompts unless the customer has chosen to provide their data for model improvement (for example the Development Partner Program, or feedback you send). An organisation admin can opt the organisation in.
- The resale paths work the same way. AWS states in its FAQ: “No, AWS and the third-party model providers will not use any inputs to or outputs from Amazon Bedrock to train Amazon Nova, Amazon Titan, or any third-party models.” Microsoft states that Azure customer data is “NOT used to train any generative AI foundation models without your permission or instruction.”
Branch ② “Free tier” is decided by the billing account, not the price (Google)
Google splits Unpaid Services from Paid Services, and the test is unusual enough that the wording is worth keeping.
- Free usage can be a paid service. The same document says access to Google AI Studio is a Paid Service even when offered free of charge, if the account has access to a Cloud project with an associated and active Cloud Billing account, or is a Workspace enterprise account. Gemini API access is a Paid Service only through a Cloud project tied to an active billing account.
- Paid services still log. For Paid Services Google “logs prompts and responses for a limited period of time, solely for detecting and preventing violations of the Prohibited Use Policy”. “Not used for training” is not “nothing is kept” — that is the retention question (see ZDR).
- Region changes the answer. For the EEA, Switzerland and the UK, the terms under “How Google uses Your Data” in Paid Services apply to all Services, including Google AI Studio and the unpaid quota, even though they are free of charge.
Branch ③ The two exceptions that survive an opt-out
Turning training off is not a blanket guarantee. Anthropic spells out two exceptions in its consumer terms, and this is the most practically useful part of the page.
- Exception 1: content you send as feedback. Ratings, corrections or bug reports you submit can be used for training even while you are opted out. Opting out does not protect what you volunteer.
- Exception 2: content flagged for safety review. Flagged content is used to improve harmful-content detection, enforce policies and advance safety research. This targets harmful use rather than ordinary business content, but it is written into the terms rather than left implied.
- Opt-outs are not retroactive. OpenAI: “Once you opt out, new conversations will not be used to train our models.” Content sent before the change is not withdrawn, so the setting belongs before the sensitive work, not after.
- There is also a “do not keep it” option. OpenAI describes Temporary Chat as not appearing in history, not using or creating memories and not being used to train models. That is a session-level workaround rather than a contractual guarantee.
“Not trained on” is a different promise from “not seen” and “not stored”
- On a free tier, training and human review happen together. The Unpaid Services section of Google's terms puts improvement use and human review in the same paragraph. From the start, those were two different promises.
- Even a no-training setup keeps abuse monitoring. Microsoft describes automated review (including by LLMs) as on by default, with human review only when the abuse monitoring system flags the data; approved organisations lose the storage and human review but automated review remains.
- Read them side by side: the four requirements, ZDR (not stored), ZOA (not seen).
A four-step check
- Pin down your layer. Consumer app, free tier, or API/commercial contract. The same tool changes layer with the login you use — signing in with a personal account to touch company code is the classic mistake.
- Decide “free tier” by billing, not price. For Google it turns on whether a Cloud Billing account is attached to the Cloud project.
- Check the current setting. Opt-out defaults have moved with vendor updates, so open the setting instead of trusting a change you made years ago. And remember the effect starts with new conversations.
- Confirm it in the contract and write it down. A settings toggle is not a term. For business use, read the relevant clause in the commercial terms or DPA and record which layer you use together with the clause you verified — that record is what disappears when people change teams.
Four common misconceptions
Misconception 1
“A paid plan means no training”
Paid consumer plans are governed by a different document from business contracts. OpenAI's line was consumer versus Team / Enterprise / API.
Misconception 2
“Opting out stops everything”
Anthropic states that feedback you send and content flagged for safety review are still used for training after an opt-out, and OpenAI's opt-out only covers new conversations.
Misconception 3
“Not trained on means nobody can read it”
Training terms (③) and operator access (②) are separate. Google's free tier combines improvement use with human review in one section.
Misconception 4
“Nothing is stored, so nothing trains”
Retention (①) and training (③) are separate clauses. “Stored but not used for training” is perfectly normal — and so is the reverse. → ZDR
Questions
- If I pay for ChatGPT Plus or Claude Pro, am I outside training?
- No. A paid consumer plan keeps consumer terms; business terms (Team / Enterprise / API) are a separate document. Consumer plans offer an opt-out, and defaults have moved with vendor updates, so check the current state of the setting before you rely on it.
- Is a “free tier” the same as a “free plan”?
- No. A free plan is a pricing tier of a consumer app (consumer terms). A free tier is quota on the API side (Unpaid Services for Google), decided by whether a billing account is attached. Both cost nothing and get different documents.
- What should I actually do if I do not want my data used?
- ① Use the layer the use case requires (API / commercial contract) ② check the opt-out setting if you use a consumer app, knowing it starts with new conversations ③ for business use, verify and record the relevant clause in the commercial terms or DPA. Settings alone, or clauses alone, leave a gap.
- Are “improving the product” and “training” the same thing?
- The English terms write these differently — “improve our products”, “develop … machine learning technologies”, “training our models” — so this page quotes the wording as written. Collapsing them in translation blurs whether review and evaluation use is included.
Sources
- OpenAI — How your data is used to improve model performance (business default, consumer opt-out, Temporary Chat / retrieved 2026-10-03)
- Anthropic — Commercial Terms of Service (B. Customer Content, “Anthropic may not train models on Customer Content from Services.” / retrieved 2026-10-03)
- Anthropic — Consumer Terms of Service (opt-out and its two exceptions / retrieved 2026-10-03) · Data usage (consumer vs commercial, 5-year vs 30-day retention / retrieved 2026-10-03)
- Google — Gemini API Additional Terms of Service (Unpaid vs Paid, human review, EEA/Switzerland/UK / retrieved 2026-10-03)
- Microsoft — Data, privacy, and security for Azure direct models (“NOT used to train any generative AI foundation models without your permission or instruction.”, abuse monitoring / retrieved 2026-09-29)
- AWS — Amazon Bedrock FAQs (“will not use any inputs to or outputs from Amazon Bedrock to train Amazon Nova, Amazon Titan, or any third-party models.” / retrieved 2026-10-03)
- Related: the four data-protection requirements · ZDR · ZOA · all glossary entries