Keep Your Customer Data Out of ChatGPT and Claude
Free ChatGPT and Claude accounts can train on what your team types in. Two switches turn that off for nothing. Here is where to find both tonight.
Your service advisor has a customer on hold and a warranty claim she cannot word. Into the free ChatGPT account she opened with her Gmail in 2023 go the customer’s name, address, and vehicle history. Nobody told her that the login she picked makes a difference, and it does. On free and personal accounts, ChatGPT and Claude can use what she types to train their models. Two switches turn that off, they cost nothing, and every account in your shop can be flipped tonight.
Cyberhaven tracked billions of real data movements into AI tools for its 2026 AI Adoption & Risk Report. It found that 39.7% of everything employees put into these tools involves sensitive data, and that 32.3% of ChatGPT use and 58.2% of Claude use runs through personal accounts rather than company ones. Odds are good that describes somebody in your shop.
Quick verdict
What this is: Free and personal-paid ChatGPT and Claude accounts may train on your conversations unless somebody turns that off. Business plans do not, by default. What it is worth to you: Zero to fix the accounts you already have. About $25 per person a month if you move the shop to a business plan, which buys you control of the account. What to do this week: Ask every person which account they are signed into, then flip one switch on each personal one.
Same app, two different contracts
The ChatGPT your advisor uses at her desk and the ChatGPT a hospital system runs on are the same screen under two different contracts. Free and Plus accounts sit under the personal contract. Business, Enterprise, and Edu accounts sit under the business contract.
OpenAI does not train its models on Business, Enterprise, or Edu content, and that is the default, not a request you have to file. On a Free or Plus account, your conversations may be used for training unless the account holder turns off Improve the model for everyone in Settings, under Data Controls.
Anthropic works the same way with one wrinkle. When it updated its consumer terms, Claude Free, Pro, and Max accounts flipped to on by default: conversations feed training unless the user says no. Say no and Anthropic keeps that data 30 days. Leave it on and it keeps it up to five years. Claude for Work, which covers the Team and Enterprise plans, sits outside all of it, as does anything your software vendor runs through a paid business connection to either company, including the developer API, Amazon Bedrock, and Google Vertex.
| Trained on by default? | Where the switch is | |
|---|---|---|
| ChatGPT Free / Plus | Yes | Settings → Data Controls → Improve the model for everyone |
| ChatGPT Business / Enterprise / Edu / API | No | Nothing to change |
| Claude Free / Pro / Max | Yes | Settings → Privacy → Help improve Claude |
| Claude for Work (Team, Enterprise), API, Bedrock, Vertex | No | Nothing to change |
Two minutes per account. No IT person, no vendor call, no meeting.
Count the records, not the incidents
Take an independent auto repair shop: eleven people, three service advisors, roughly 420 repair orders a month at a $480 average ticket. Cyberhaven found employees push sensitive data into AI tools about once every three days. Your three advisors are almost certainly heavier users than that, because writing to customers is most of their job. Hold the conservative number anyway.
Three advisors, once every three days, across a working year is about 240 customer records a year going into accounts that may be set to train by default. Names, addresses, vehicle histories, and whatever else sat in the paragraph they pasted.
Nothing has gone wrong yet. What you have is a pile of customer information sitting in accounts your business does not own, cannot audit, and cannot delete, held by a company running a five-year clock on it. When the advisor quits in March, she takes the login with her.
The number vendors will quote at you
IBM’s Cost of a Data Breach Report 2025 found that one in five breached organizations had shadow AI involved, meaning AI tools employees started using without anyone approving them, and that those incidents added as much as $670,000 to the average breach cost.
Read the scope before you read the number. IBM studied 600 breached organizations, most of them far larger than your shop, and $670,000 is an increase on an average breach cost most small businesses will never see. Run the same test you would put on any vendor’s ROI slide and keep the part that travels: the tools nobody approved are the ones nobody can clean up afterward. That holds at eleven employees exactly as it holds at eleven thousand.
The realistic version for you is smaller and duller. A customer asks what you did with their information. Your insurer sends a questionnaire. A fleet account’s paperwork person wants your AI policy in writing. “I don’t know which account my staff used” is the wrong answer in all three, and it is the answer most shops have today.
The switch does not make everything safe
Two things it does not do, and I would rather you hear them from me.
It is not permission to paste anything. Training is one risk. How long a vendor keeps your data, who on their staff can see it, and how carefully they guard it are separate risks, and a vendor can be careless with data it never trained on. That was the lesson of the notetaker that left 181,874 meetings readable. Card numbers, full Social Security numbers, and patient health details do not belong in any chat tool at any price. Strip them before you paste. Every time.
It does not give you control of the account. A personal login with training turned off is still a personal login: no visibility for you, no way to revoke it when somebody leaves, no record of what went in. Control is what the business plan actually sells, and the seat math is worth running honestly before you buy eleven of them. ChatGPT Business runs $25 per user monthly, or $20 billed annually. Claude’s Team plan is priced the same, $25 monthly and $20 annually, for 2 to 150 seats.
Three people using AI seriously means three seats at $25, or $75 a month. You do not have to license the whole roster.
What to do this week
- Take the inventory. Fifteen minutes. Ask each person two questions: do you use ChatGPT or Claude for work, and which email address did you sign up with. Write the answers on paper. Most owners find two or three accounts they knew about and one they did not.
- Flip both switches on every personal account today. ChatGPT: Settings, Data Controls, turn off Improve the model for everyone. Claude: Settings, Privacy, turn off Help improve Claude. Watch them do it, because “I’ll get to it” means it does not happen. Then put the one rule that matters on the whiteboard: no card numbers, no Social Security numbers, no medical details, on any account, ever.
- Price a business plan for the two or three people who actually use it. Get the quote, compare it to what an hour of your bookkeeper’s time costs, and decide before the next customer list gets typed into a free account.
Your team will keep using these tools whether you approve them or not. The only real choice in front of you is whether the account they use is one you can see.
TAGS
What is this worth in your business?
The free Build Audit is 30 minutes. You leave with a ranked list of the automations worth doing in your business, whether or not we build them.
Related Articles
How to Tell If an AI Vendor's ROI Claim Is Real
Learn the three-question test that separates a real AI vendor ROI number from a marketing one, before you sign the contract or approve the next renewal.
Thomson Reuters Just Answered Your Build vs. Buy Question
Thomson Reuters spent $40M fine-tuning an open-source model on Westlaw data to match frontier performance. Compare that build vs. buy math against your own.
AI 'Thinking' Blocks Just Leaked 182 Credentials
Researchers decoded 315,320 encrypted AI reasoning blocks from public agent logs and recovered 182 credentials. See the audit to run on your repos this week.