Last reviewed
The short answer. Claude can be safe for approved work on Team, Enterprise, or the API, where Anthropic states it does not train on inputs or outputs by default. Free, Pro, and Max accounts follow consumer terms, where chats can train models if the user allows it and be kept up to five years. Connectors extend what Claude can read.
The plan decides the data terms, so write the approved plan down. The guide to stopping data leaking into AI covers the data that stays out of every plan.
What Claude can access
Claude works with what a person gives it: prompts, uploaded files, and project knowledge. Chat uploads allow up to 20 files of 500MB each. Files added to a project stay available across that project’s chats (upload limits; projects). Memory is on by default for Free, Pro, and Max, and on Team and Enterprise it is available when an owner enables it. Each project has its own memory (projects).
Connectors add reach. The Google Workspace connector reaches only the Gmail, Calendar, and Drive data of the Google account that was connected, and only when a request needs it. With Microsoft 365, Claude can only see data the person’s own account can see. Data retrieved through connectors is stored with its chat, so deleting the chat deletes it (Google Workspace connectors; Microsoft 365).
Claude Code, the coding agent, reads files and runs commands, which is a separate question covered in the Claude Code security guide. For the cloud agent, see Claude Cowork security.
Data handling by plan
Free, Pro, and Max. As of 2026-10-10, deleted conversations leave the history immediately and are removed from Anthropic’s back-end storage within 30 days. When a user allows model training, chats and coding sessions started or resumed after that point can be kept in de-identified form for up to five years. Inputs and outputs flagged by trust and safety systems can be kept for up to two years, and their classification scores for up to seven (consumer retention).
Team and Enterprise. Anthropic states it will not use inputs or outputs from its commercial products to train models by default. If a user reports feedback, such as a thumbs up or down or a bug report, Anthropic may use that conversation for training. Feedback conversations are stored for up to five years and de-linked from user and customer IDs first, and Team and Enterprise owners can turn feedback submission off under Rate chats in Organization settings (model training). Saved chats stay in the product until deleted, and deleted chats leave back-end storage within 30 days (commercial retention).
API. The same default applies to training. Inputs and outputs are deleted automatically within 30 days of receipt or generation, with exceptions for retention the customer controls, such as the Files API, agreed terms such as zero data retention, enforcing the Usage Policy, and legal requirements (commercial retention).
Where data is stored and processed
For commercial products, Anthropic states that it may route customer traffic to select countries in the US, Europe, Asia, and Australia unless otherwise agreed or instructed, and that data is stored in the US. Safety review, product support, and incident response can take place in the countries where Anthropic or its affiliates operate (Anthropic Privacy Center).
API customers have two settings. Inference geo controls where model inference runs, with global as the default and us available per request or as a workspace default. Workspace geo controls where data is stored at rest, and us is the only value available today (data residency). Third-party services reached through connectors process data on their own infrastructure under their own terms.
For health information, see Is Claude HIPAA compliant?
Safe setup for company work
- Choose the plan. Use Team, Enterprise, or the API for company data, and record the plan, owner, and organization settings.
- Keep personal accounts out unless the policy approves them, because consumer terms allow training when a user opts in.
- Turn off feedback submission for the organization if feedback conversations should not leave it.
- Review connectors and memory before enabling them, and test deletion with made-up data.
- Pin API inference to the US if a contract requires it.
- Write the rule down. Add Claude to the AI acceptable use policy and compare plan terms in Is ChatGPT safe for work?
Frequently asked questions
Is Claude safe to use?
For approved work, yes, on the right plan. Anthropic states that it does not use inputs or outputs from its commercial products to train models by default, with an exception for feedback a user submits. Free, Pro, and Max accounts follow consumer terms, where chats and coding sessions can be used for training when the user allows it.
Does Claude train on my conversations?
On Free, Pro, and Max, only when the user allows it, and then de-identified chats and coding sessions can be kept for up to five years. On Team, Enterprise, and the API, Anthropic states that it will not use inputs or outputs to train its models by default. Feedback such as a thumbs up or a bug report is the stated exception.
How long does Claude keep my data?
Deleted conversations leave the history immediately and are removed from back-end storage within 30 days. Saved conversations on Team and Enterprise stay in the product until deleted. API inputs and outputs are deleted within 30 days, with exceptions for longer retention the customer controls, agreed terms, usage-policy enforcement, and legal requirements.
Where does Anthropic store data?
For commercial products, Anthropic states that customer traffic may be routed to select countries in the US, Europe, Asia, and Australia unless otherwise agreed, and that data is stored in the US. API customers can pin inference to the US with the inference_geo setting.
Is Claude Code safe?
Claude Code reads files and runs commands, so it has its own boundaries to set. The Claude Code security guide covers file permissions, sandboxing, and credentials.
Next
Keep going
Sources
All read on 2026-10-10.
- Anthropic Privacy Center, How long do you store my data? (consumer, updated July 1, 2026)
- Anthropic Privacy Center, How long do you store my organization’s data? (commercial, updated July 1, 2026)
- Anthropic Privacy Center, Is my data used for model training? (updated August 18, 2026)
- Anthropic Privacy Center, Where are your servers located? (updated June 15, 2026)
- Claude Platform Docs, Data residency
- Claude Help Center, How can I create and manage projects?
- Claude Help Center, Upload files to Claude
- Claude Help Center, Use Google Workspace connectors
- Claude Help Center, Connect to Microsoft 365