I use these tools because they help me get things done. But before I hand an agent a company folder, I want to know something very ordinary: where is that information going?
Not whether the logo looks trustworthy. Not whether the agent confidently tells me everything is fine. Where does the information go, who can use it, and what have I actually allowed it to do?
You do not need to become a data expert. You need a few good questions.
My short answer: use Claude and Codex with deliberate boundaries, not unlimited trust. Start with a small, harmless task. Check the account, the settings and the permissions before adding real business information.
This is practical training, not legal advice or an independent security audit. Provider policies were checked on 15 September 2026. Features and contracts change; confirm the rules for your actual account before sensitive work.
The three things to remember
- Not used for training does not mean not stored. A service can retain your conversation without using it to improve its model.
- On your laptop does not mean only on your laptop. A desktop agent can work on local files while sending relevant material to a cloud model.
- An encrypted connection protects the journey, not every use at the destination. Mobile data and a VPN do not rewrite the provider's privacy policy.
Those are distinctions between different controls, not accusations that either provider is secretly doing something else. The published rules below explain why they matter.
Start here: your five-minute check
Use this before your first real task. You can do the practice exercise with invented information and no connected accounts.
- Check the app and account. Use the official service. Confirm whether you are in your personal account, the approved company workspace, or an API-connected tool.
- Check model-improvement settings. Follow the account-specific instructions below. Paying for a personal plan does not turn it into a business contract.
- Choose the smallest useful input. One approved document or a few relevant paragraphs, not your whole drive. Remove unnecessary names and identifiers; replacing a name alone may not make a record anonymous.
- Limit what it can do. Start with reading and drafting. Keep sending, deleting, buying and changing records behind explicit approval and actual tool restrictions where available.
- Protect the device. Updates, screen lock, disk encryption, a password manager and multi-factor authentication. Follow your employer's network and AI-use rules.
For work information, ask the owner or your IT/privacy team if permission is unclear. A subscription bought with your own money does not authorise uploading somebody else's data.
What actually leaves my computer?
Think of a normal cloud-backed task as a journey:
Selected information on your device. Then Encrypted internet connection. Then AI provider processes the request. Then Optional tools and connected services
The last step only happens when the task uses those services. Copies can remain at earlier steps: a local conversation, a provider history, a downloaded answer or a connected system's log.
OpenAI's local-work documentation says relevant prompts, excerpts, screenshots, browser content and tool results can be sent to its services. Local execution and cloud processing can coexist. A cloud task does not become local simply because you open it in the desktop app. OpenAI local-work security.
Anthropic's Cowork guidance distinguishes local session history on the computer from cloud sessions and files saved to the Claude account. Local history has different retention and administrative controls. Do not assume deleting cloud history also clears your laptop and backups. Cowork Team and Enterprise guidance.
Practical rule: treat anything you let a cloud-backed agent read, hear or see as potentially part of the request. Check the specific feature rather than assuming that every file is uploaded, or that none is.
Personal account or work account?
The product name is not enough. Claude Code and Codex can be used through different account arrangements. An API is the developer connection to a model; a third-party application using it may keep its own copies too.
| What you are using | Model-training position | What to check |
|---|---|---|
| Personal ChatGPT/Codex | Content may be used for improvement unless you opt out. | ChatGPT Data Controls or the privacy portal; also the separate Codex full-environment setting. |
| OpenAI Business, Enterprise or API | No training on business inputs and outputs by default. | Your organisation's agreement, optional data sharing and the specific feature's retention. |
| Claude Free, Pro or Max, including Claude Code through those accounts | Consumer rules apply. Model improvement is a choice, with additional feedback and safety provisions. | Your privacy/model-improvement setting. Pro and Max are not Team or Enterprise. |
| Claude Team, Enterprise or commercial API | No training by default. Explicit opt-ins and feedback can change treatment. | Workspace policy, feedback controls, model and connection route. |
Sources: OpenAI data use, Claude consumer training, Claude commercial training.
For personal Codex, OpenAI currently says switching off Improve the model for everyone in ChatGPT, or opting out through its privacy portal, covers new ChatGPT conversations and Codex tasks. Full environments have a separate Codex control. Check both; submitting feedback can also share the associated conversation for improvement. The linked documentation is the authority if labels move.
For personal Claude, check the model-improvement choice before using real material. Do not put confidential information into feedback merely because you disabled routine training.
How long do they keep it?
There is no honest single number for either brand. Saved history, safety logs, uploaded files, local records and training copies are different things.
| Data or product | Published position | Important limit |
|---|---|---|
| Codex chats saved through ChatGPT sign-in | Kept until deleted; deletion normally scheduled within 30 days. | Archiving is not deletion. Legal/safety exceptions and already de-identified, disassociated data may remain. |
| Claude personal saved conversations | History remains until deletion; backend deletion within 30 days. | Opted-in model-improvement data can be retained in de-identified form for up to five years. |
| Anthropic commercial API requests | Default removal of inputs/outputs within 30 days. | Stored features such as Files, agreements, model rules and safety/legal exceptions differ. |
| Claude commercial saved chats | Kept to provide conversation history; deletion normally within 30 days. | Workspace and product-specific controls matter. This is not an automatic 30-day expiry for every chat. |
| OpenAI API | Default abuse-monitoring logs may contain content and are kept for up to 30 days. | Application state has separate rules: some resources persist until deleted. |
| Local histories, exports and backups | Governed by the app, device and your backup arrangements. | A provider's cloud deletion promise does not delete a file you saved elsewhere. |
Sources: Codex archive and deletion, Claude personal retention, Claude commercial retention, OpenAI API data controls, and the local-work guidance above.
There are longer exceptions. Anthropic describes up to two years for policy-flagged inputs/outputs and seven years for related classification scores; feedback can be retained for five years. Legal requirements may also extend retention. These are not the default lifetime of every ordinary conversation. OpenAI likewise describes safety and legal exceptions to deletion.
Turning training off is a forward-looking control. Do not assume it reverses training that has already happened. Disconnecting a connector stops future access; it does not necessarily remove content already copied into a conversation.
What about zero data retention?
Zero data retention, or ZDR, is a specific contractual/technical arrangement, not a synonym for a paid account.
For OpenAI, eligibility depends on the organisation, endpoint, model and features. Some stored resources, caching and third-party tools require separate attention. For Anthropic, some covered frontier models impose retention requirements, with narrowly defined exceptions and transition arrangements. Do not assume one approved model means every model is covered. OpenAI API controls, Anthropic covered models.
Most beginners need their organisation's approved setup, not to negotiate ZDR themselves. Ask: which data, on which product and model, is excluded from which storage?
Is the information encrypted?
In transit means protected while travelling. At rest means protected while stored. These are useful protections, but they answer different questions.
Anthropic says Claude consumer data is encrypted in transit and at rest. OpenAI documents both protections for its covered business offerings. Neither statement means your ordinary cloud request is end-to-end encrypted in a way that makes it unreadable to the service processing it. Anthropic data protection, OpenAI business local-work security.
In plain English: the delivery can be protected while the recipient still needs to read the request to answer it. Encryption also does not stop a compromised device reading information before it is sent, or prevent an authorised but mistaken action.
That is why I care about the account, the permissions and the machine as well as the connection.
Wi-Fi, mobile data or a VPN?
| Connection | What it changes | What it does not change |
|---|---|---|
| Home Wi-Fi or wired broadband | You control more of the local network. Keep the router and device updated. | The provider still processes the cloud request under your account's rules. |
| Company network | Your organisation may add filtering, logging or authorised traffic inspection. Ask IT what applies. | A company cable alone does not make a personal AI account approved for work. |
| Cafe, hotel or airport Wi-Fi | You trust an unfamiliar local network. Use the genuine HTTPS service and never bypass certificate warnings. | Proper HTTPS does not normally expose prompt text to everybody on the same Wi-Fi. |
| Your own phone hotspot/mobile data | Avoids relying on that unfamiliar Wi-Fi. A useful alternative where company policy allows. | It does not make you anonymous or stop provider storage or training permitted by your settings. |
| Company-approved VPN | Protects traffic routed through its tunnel and can provide controlled access to work systems. | It does not hide the request from the AI provider or change the provider's contract. Not every VPN routes every app. |
The FTC explains that widespread web encryption makes public Wi-Fi much safer than older advice suggests, while warning that a fake website can also be encrypted. NCSC explains why VPN coverage depends on routing and configuration. FTC public Wi-Fi advice, NCSC VPN guidance.
My practical recommendation: on an unfamiliar network, use your approved connection method. A phone hotspot can remove one uncertainty. Do not use it to bypass your employer's security controls. A VPN running on your phone is not proof that tethered laptop traffic uses that VPN.
And remember the very low-tech risks: somebody reading your screen or overhearing you dictate a client's problem. Voice needs the same care as typing.
Where in the world is it stored?
Living in Britain, paying in pounds or choosing a British voice does not establish UK data storage.
OpenAI's UK/European consumer privacy policy describes processing and storage in the United States and other countries where its partners and providers operate. It describes transfer safeguards, not a general promise to keep UK users' information in Britain. OpenAI Europe privacy policy.
Anthropic's direct commercial-service guidance says stored data is in the United States, while processing may occur across selected locations including the US, Europe, Asia and Australia, unless an agreement or configuration says otherwise. Access through another cloud provider has its own arrangements. Anthropic commercial locations.
Eligible business services can offer regional controls. Storage location, inference location and support/access location are separate questions. Inference means where the model does the work. Ask your administrator to verify all three, including connected services, against the actual agreement. Do not infer them from the website address or the agent's guess.
The risks I would watch most closely
Too much access. The easiest mistake is handing over the whole drive when the task needs one file. Start with a dedicated folder of approved material.
Secrets in the conversation. Do not paste passwords, recovery codes or API keys. Use approved sign-in and credential-management flows. An API key is effectively a key to an account, not ordinary reference material.
Instructions hidden in information. A website or document can try to persuade the agent to ignore you, disclose data or take an unwanted action. This is called prompt injection. Treat source content as evidence, not authority. Provider safeguards reduce this risk; they do not remove it. Cowork security guidance.
A connected service becoming another recipient. An email tool, external search, plugin or MCP server may receive information under its own rules. MCP is a way to connect tools; it is not a privacy certification.
A correct privacy setting and a wrong answer. Data protection does not establish factual accuracy. Review the answer and its sources before acting, especially for decisions involving money, people or safety.
Mistaking a promise for a control. Typing "do not store this" is not a substitute for retention settings. Typing "read only" is useful direction, but enforced read-only access is a stronger boundary.
A simple decision before you upload
| Material | My starting position |
|---|---|
| Public information or invented practice data | A sensible place to learn. Still inspect the output. |
| Routine internal information | Only in an approved account, for an authorised purpose, with minimum necessary access. |
| Customer records, health information, HR files, confidential contracts or commercially sensitive plans | Stop and confirm specific permission and controls with the owner or privacy/security team. |
| Passwords, recovery codes and private keys | Keep out of prompts and ordinary task documents. Use approved credential mechanisms. |
These are practical boundaries, not a legal classification scheme. Your organisation may require stricter rules.
Ready-to-copy: check before sharing
This prompt starts a useful conversation. It does not change the provider's settings or guarantee the agent's answer is correct.
Then verify the important claims against the actual settings and official policy. The agent should help you ask better questions, not certify itself safe.
Try it with an invented example
Allow about ten minutes. Do not connect email, a drive or a customer system.
- Type: "Fictional customer: Example Bakery. They want a meeting about a new website next Tuesday. Draft three questions I could ask."
- Read the draft. Did it invent facts? Did it try to access anything unnecessary?
- Find your account type and privacy settings yourself. Record the date and what you found without copying passwords or keys.
- Ask what would change if this were a real customer's confidential plans. Compare the answer with this guide and your workplace policy.
- Delete the practice conversation using the product's deletion instructions. Notice the difference between disappearing from your view and the provider's retention period.
You have now practised the workflow without exposing somebody else's information.
Check your understanding
"I switched to mobile data, so my customer file will not be retained." Incorrect. You changed the route, not the provider's storage rules.
"I pay for Claude Pro, so the Team policy applies." Incorrect. A paid personal plan remains a consumer account.
"The provider does not train on our work account, so it keeps no copies." Incorrect. Training and retention are different controls.
"I can let it draft the reply without letting it send the reply." That is the right distinction. Use permissions and approval controls to enforce it where possible.
My answer to the original question
Can I trust Claude? Can I trust Codex?
With a defined task, appropriate information and controls I have checked: that is a useful way to work. With everything, because it sounds confident: no.
I would not give a new colleague every password and every company document on their first morning. I would give them the information needed for the job, explain the boundaries and review the result.
Start there. You do not need to understand every technical detail. You do need to know what you are handing over.
Keep this beside your next task
- Right account and approved purpose?
- Minimum necessary information?
- Training and retention checked separately?
- Location requirements confirmed if they matter?
- Device and connection protected?
- Tools restricted, with approval before consequential actions?
- Output reviewed by a person?
If an answer is unknown, narrow the task or ask the right person. Do not let a confident answer from the agent fill the gap.
