The first real conversation about Claude at my company was not about what it could do. It was our security team asking one question, does our data train their models, and me not having a crisp answer. That gap stalled a pilot for two weeks over something that had a clear, checkable answer, purely because I had not done the homework. The data question is always the first question, and not knowing it cold is how good tools die in review.
So this guide is the homework. What Claude does with your data across three axes, training, retention, and zero data retention, and how the defaults differ by tier. It is the foundation for the harder governance questions, because you cannot reason about compliance or putting customer data in until you know the data story. And because terms change, the constant advice is to confirm the current specifics in Anthropic's documentation.
The question everyone asks first
Any time you bring an AI tool into a company, the first serious question is about data: what happens to what we put in. It comes from security, from legal, from a cautious exec, and it is the right question, because feeding a tool your pipeline, your customer records, your call transcripts is a real trust decision. If you cannot answer it plainly, the tool does not get adopted, no matter how good it is.
The answer has three parts that people tend to blur together: whether your data is used to train the models, how long it is retained, and whether you can turn retention off entirely. They are separate questions with separate answers, and being precise about which is which is most of sounding credible in that review.
Training: who uses your data to train
Training is the question with the most fear attached, the worry that your confidential data ends up baked into a model. The important fact for a company: business and API usage is not used to train Anthropic's models by default. When you use Claude through a business tier or the API for your work, your inputs are not feeding model training as a matter of the default terms.
Consumer plans are different, which is exactly why the tier you use matters. Consumer accounts have a setting that governs whether your conversations can be used to improve the models, and it is something you control. The practical upshot is that where the data comes from your company, you want to be on a business footing, not a personal account, so the no-training default applies.
Consumer vs business defaults
The single most useful thing to internalize is that the defaults differ by tier, so who is asking and on what plan changes the answer. A person on a personal Pro account and a company using the API are governed by different terms, and treating them as the same is where confusion and bad assumptions start.
For anything involving company or customer data, the guidance is simple: use a business tier, Team, Enterprise, or the API, where the no-training default and stronger data terms apply, rather than a personal consumer account that happens to be logged in. The capability is the same; the data posture is not, and the posture is what your security team cares about.
TipCompany data belongs on a business tier, not someone's personal Pro account. The model is identical; the data terms are not, and the terms are the whole point in a review.
Retention: what's stored and for how long
Retention is a different question from training, and people constantly conflate the two. Training is whether your data shapes the model; retention is how long your inputs and outputs are stored at all, for things like operating the service, safety, and abuse prevention. A tool can not train on your data and still retain it for a period, and those are separate assurances.
Retention periods vary by tier and configuration, so this is one to confirm rather than assume. The reason it matters to a security team is that stored data is data that could, in theory, be subject to a breach or a legal request, so how long anything is kept is a real part of the risk picture, independent of the training question.
Zero data retention
For teams with strict requirements, zero data retention is the strongest posture: eligible accounts can arrange for inputs and outputs not to be retained after the request is served. Nothing is kept, which removes the stored-data risk almost entirely and is often what a cautious security team is really looking for when they push on retention.
ZDR is typically an enterprise-level arrangement rather than a checkbox on a personal plan, and eligibility and specifics are governed by your agreement, so it is a conversation to have with Anthropic, not an assumption to make. But knowing it exists is important, because it is frequently the answer that turns a no into a yes for a regulated buyer.
TipIf your security team's real worry is stored data, ask about zero data retention early. It is often the specific assurance that clears a strict review, and it is an enterprise conversation to start, not a setting to hunt for.
What this means for GTM data
Translate all of this to the concrete GTM question: can I put our customer and pipeline data into Claude. The answer, for most teams, is yes, provided you do it on the right footing, a business tier, where the no-training default holds and the data terms are enterprise-grade, and with the retention posture your policy requires, up to ZDR if you need it.
The mistake is doing it casually on a personal account because that is what someone had open. The same prompt, the same customer data, run through a personal consumer login instead of your company's business tier, is a different data-terms situation and the kind of thing a later audit flags. Get the footing right once, and the day-to-day use is clean.
How to check and set your posture
The practical work is short. Confirm which tier your team is actually using, and make sure company data flows through the business tier or API, not personal accounts. On consumer plans that individuals use, check the training setting. And for anything sensitive, read the current data terms in Anthropic's Trust Center and documentation rather than relying on a summary, including this one, because terms evolve.
This is also where you get ahead of the security review instead of being stalled by it. Walking into that conversation already knowing your tier, your training default, your retention posture, and whether you need ZDR is the difference between a two-week stall and a same-day yes. The homework is small and the payoff is adoption that does not get blocked.
Where people get it wrong
The most common error is assuming instead of checking, either assuming the worst, our data must be training the models, and avoiding a useful tool, or assuming the best and putting sensitive data through a personal account with no idea of the terms. Both come from not having read the actual current terms for the actual tier in use.
The second is conflating training and retention, so a security answer addresses one and leaves the other open, which reads as not knowing the material. And the third is letting company data run through personal consumer logins, the shadow-account problem, which quietly creates a data-terms gap no one chose. Know the three axes, use the right tier, and check the current terms.
- Assuming rather than checking the current terms for the tier you actually use.
- Conflating training and retention, and answering only one when asked about data.
- Company data flowing through personal consumer accounts instead of a business tier.
- Treating a summary as authoritative; the Trust Center and docs are the source of truth.
The GTM version
For a GTM operator, the data story is not bureaucracy, it is what lets you actually use Claude on the work that matters, the real accounts, the real transcripts, the real pipeline. Get the footing right, a business tier with the no-training default, the retention posture your policy needs, ZDR if the data is sensitive, and you can put your genuine GTM data in and get genuine value, with an answer ready for anyone who asks.
The two weeks I lost were not to a hard problem, they were to a homework problem I had not done. Do the homework once and the data question stops being a blocker and becomes a box you check confidently. What is the data question your security team would ask tomorrow, and could you answer it cold today?
How to set it up
Confirm which tier your team actually uses
Find out whether company work runs on a business tier or the API, versus personal consumer accounts. This one fact determines your training and data-terms defaults.
Put company data on a business footing
Route customer and pipeline data through Team, Enterprise, or the API, where the no-training default and enterprise data terms apply, not a personal Pro login that happens to be open.
TipIf people are using personal accounts for company work, that is a data-terms gap you did not choose. Move that usage onto the business tier before it shows up in an audit.
Set the retention posture you need
Confirm the retention terms for your tier, and if your data is sensitive, start the zero-data-retention conversation with Anthropic. On consumer plans individuals use, check the training setting.
Read the current terms before you commit
Verify training, retention, and ZDR specifics in Anthropic's Trust Center and documentation rather than a summary, since terms change. Walk into your security review already knowing the answers.
Frequently asked questions
Does Claude train on my data?
Business and API usage is not used to train Anthropic's models by default. Consumer plans have a setting you control. So the answer depends on your tier, which is why company data should be on a business footing.
Is training the same as retention?
No. Training is whether your data shapes the model; retention is how long your inputs and outputs are stored at all. A tool can not train on your data and still retain it for a period. They are separate assurances.
What is zero data retention?
An arrangement for eligible accounts where inputs and outputs are not retained after the request is served. It removes the stored-data risk almost entirely and is typically an enterprise-level conversation with Anthropic.
Can I put customer data into Claude?
For most teams, yes, on the right footing: a business tier where the no-training default holds, with the retention posture your policy requires, up to ZDR if the data is sensitive. Avoid doing it on personal accounts.
Why does the tier matter so much?
Because defaults differ by tier. The same prompt and data through a personal consumer login versus your company's business tier are governed by different terms, and the terms are exactly what a security review cares about.
How long is my data retained?
Retention periods vary by tier and configuration, so confirm the current terms rather than assume. Stored data is part of the risk picture independent of training, which is why security teams ask about it.
Where do I find the authoritative answer?
Anthropic's Trust Center and documentation, for the tier you actually use. Terms evolve, so treat any summary, including this one, as a starting point and verify the current specifics there.
What is the most common data mistake?
Company data running through personal consumer accounts, which creates a data-terms gap no one chose, and assuming instead of checking the current terms. Use a business tier and read the actual terms.
Sources & further reading
Claude ships fast. This page was last reviewed Aug 23, 2026; verify time-sensitive details against the official docs above before relying on them.