Data protection for AI beginners: what am I even allowed to type in?
Before you paste your CV, customer data or private chats into ChatGPT or Claude: an honest explanation of what happens to your inputs and how to switch training off.
The first question everyone who's new to AI asks me is not "how do I write a good prompt". It's "am I even allowed to put my real name in there". Good question. Because most people don't know that, on ChatGPT's default settings, their inputs get used as training material. Not secretly, it's in the terms of service, but written the way nobody ever reads.
This lesson clears that up. No panic mode, no "AI is evil", just the concrete facts: what happens to what you type, where the line is, and how three clicks switch training use off.
What "training" actually means
When a model like GPT-5 or Claude is built, it gets fed enormous amounts of text. After that comes the fine-tuning phase, and in the consumer versions real user conversations flow into it too. That means: what you type into the chat today can end up inside a later model version. Not word for word as a quote, but processed, yet the information was there.
The important point many people get wrong: this is a one-way ticket. Once your input has been processed in a completed training run, you can't pull it back out. A later opt-out only works going forward, not retroactively. That's why the right order is: check your settings first, then type in sensitive things. Not the other way round.
What you'd better NOT type in
Whatever your setting: there are categories that simply don't belong in a consumer chatbot. Passwords and login credentials are obvious. But also: ID numbers, complete bank account numbers, health data about you or others, and above all personal data of third parties that isn't yours.
The last point is the one people most often overlook at work. When you paste a customer email into ChatGPT to have a reply drafted, you're passing your customer's data to a third party. If your employer hasn't cleared that and has no contract with the provider, then in case of doubt that's a GDPR problem. Not yours personally, but one that can get expensive. Rule of thumb: anything you wouldn't write on a postcard belongs in anonymized or not at all.
ChatGPT: the hidden switch
With ChatGPT, on free accounts as well as Plus and Pro, your conversations are used by default to improve the models. That's the default setting, you have to actively object.
The way there: Settings, then Data Controls, then flip the "Improve the model for everyone" toggle to OFF. From that moment on, new conversations are no longer used for training. Important: this only applies going forward, old conversations that were already in a training run stay in.
There's a second option almost nobody knows about: the temporary chat. It's deleted after 30 days, has no history, no memory, and is never used for training. For a quick question with sensitive content, that's the cleanest way, without touching the settings.
And the big difference: the business variants. ChatGPT Team, Enterprise and the API do NOT train on your data by default. If you work with AI a lot professionally, that's the real reason for a Team account, not the handful of extra features.
Claude: opt-out too since August 2025
With Anthropic's Claude it was different for a long time, but in August 2025 a change came. For consumer accounts it's now an opt-out arrangement as well. If you don't actively object, your new and resumed chats plus coding sessions can be used for training.
The difference is in retention. If you consent to training use, your data is stored for up to five years. If you object, it's 30 days. That's a substantial difference, and the switch for it sits in the Privacy Settings.
Two things for honesty's sake: first, conversations that were flagged for safety reasons can still be used regardless of your setting. Second, the commercial variants Claude for Work Team and Enterprise are exempt from training use, exactly like at OpenAI.
The practical test before you type
Before you type in anything sensitive, run through these three questions. Does the data belong to me, or to another person? If it belongs to another person and I have no clearance: don't put it in, or anonymize it first. Have I switched off training use for this account? If not and it matters: switch it off first or use a temporary chat. Would it harm me if this text were sitting somewhere in a model two years from now? If yes: anonymize.
That sounds cumbersome, but after three days it becomes reflex. And the big win: you can then use AI with a clear conscience, because you know where the line is.
What's next
You now know what happens to your inputs and how to switch off training use. That puts you ahead of the majority of AI users, who never set this up. If you want to use AI specifically for your job application, take a look at the playbook on applying with AI, where we go step by step through the CV and cover letter, with exactly this data-protection caution built in.
Source
The details on the data policies were checked against the providers' official documentation (as of July 2026):
- OpenAI Data Controls FAQ: https://help.openai.com/en/articles/7730893-data-controls-faq
- OpenAI, How your data is used to improve model performance: https://openai.com/policies/how-your-data-is-used-to-improve-model-performance/
- Anthropic, Updates to our Consumer Terms (August 2025): https://www.anthropic.com/news/updates-to-our-consumer-terms