Keino
Guide

Is Your Business Data Safe on ChatGPT, Claude or Gemini?

Ali3 min read

Illustration of a laptop showing an AI chat, with documents floating out of the screen and away.

Is your business data safe on ChatGPT, Claude or Gemini? Most business owners think they already have an answer to that. Probably, but only on the right kind of account, and hardly anyone checks that first. Australian employers estimate that 44% of their staff use personal AI accounts at work, and one in three employees admit doing it in secret, according to a national survey of more than 1,000 business leaders and 1,600 workers by Employment Hero. Most of those workers are also teaching themselves as they go, with many heading straight to "TikTok and YouTube and various blogs and websites" rather than anything their employer gave them, James Keene, Employment Hero's Asia Pacific managing director, told AAP.

That gap matters because the account someone's using decides what happens to whatever gets typed into it, and most small businesses have never checked which side of that gap they're on.

It's already gone wrong once, publicly

In 2023, engineers at Samsung's semiconductor division pasted confidential source code into ChatGPT to help fix a bug, on personal accounts, from company laptops. Bloomberg reported three separate leaks of sensitive company data inside three weeks. Samsung had a whole security team watching for exactly this. Most small businesses don't.

It's tempting to assume paying for a better plan already fixes this. Plenty of business owners have made that assumption without ever checking it, ChatGPT Plus costs $32 a month, so surely that buys proper business protections. Not really, not in the way that matters.

Paying for it doesn't make your business data safe

Here's the part that trips people up. ChatGPT Plus, Claude Pro and Gemini Advanced are all paid subscriptions, and every one of them is still a personal account. A proper Business, Enterprise or Team account is a different thing altogether, usually needing an actual company sign-up, not just a credit card.

On a personal ChatGPT account, OpenAI's own help centre confirms conversations may be used to train future models, unless switched off manually. On Business, Enterprise or the API, that's excluded automatically. Claude works the same way: personal Free, Pro and Max accounts train by default unless you opt out in Privacy Settings, and opting out also resets retention from five years back down to 30 days. Claude for Work and the API are excluded either way. Even opting out has a limit worth knowing: conversations flagged for safety review can still be used to improve Claude's safety systems regardless of that setting. Gemini follows OpenAI's pattern. Personal accounts train by default, and Google Workspace needs explicit permission first.

None of the three protect you by default on a personal account. The account tier is still the first thing to check, there's just no longer a "safe by default" option sitting among them.

ToolPersonal (Free/Plus/Pro/Advanced)Business/Enterprise/APIWhere to check
ChatGPTTrains unless opted outExcluded by defaultData Controls FAQ
ClaudeTrains unless opted out1Excluded by defaultPrivacy Center
GeminiTrains unless opted outExcluded without permissionGemini Apps Privacy Hub

This is the first thing we check when scoping a system for a client, not which AI looks impressive, but which account it's actually running through.

A different kind of fix

There's a way around all of this too. Run the AI model on a server the business owns, instead of sending anything to ChatGPT, Claude or Gemini's servers at all. No personal account to check, no vendor training policy to track, because the data never leaves the building in the first place. It's a bigger job than flicking a switch.

For now, the two-minute fix is simpler. Open the account behind that contract or that pitch deck and check whether it actually says Plus or Business. Paying for it was never proof of the other.

None of this means switching everything off tomorrow. It just means checking one setting most people have never looked at. If that's more than you feel like sorting through on your own, we're happy to help with, no strings attached.

Footnotes

  1. Even with training switched off, Anthropic's privacy policy allows conversations flagged for safety review to be used for training.