Is Claude Safe? Privacy, Training & Security Explained

Claude is one of the stronger mainstream AI choices if privacy matters to you, particularly because Anthropic gives consumers a clearer say over whether ordinary chats can be used to improve its models. I still wouldn’t treat a personal Claude account as confidential, though.

On this page, I’ll walk you through what Claude collects, how its model-training choice and Incognito mode work, what happens to uploaded files and Projects, and explain where Claude’s privacy protections are genuinely stronger and where the same cautions still apply.

Summarize with AI Summarize

Table of Contents

Last Updated on August 11, 2026 by Jade Artry

Quick points

At a glance

  • DSS verdict: Strongest consumer training consent among mainstream AI tools; not appropriate for under 18s.

  • Model improvement: User choice. Ordinary consumer chats are used for model improvement only if you choose to allow it, aside from separate safety-review circumstances.

  • Standard deletion: Normally removed from backend systems within 30 days after deletion; longer retention can apply to model-improvement data, feedback and flagged content.

  • Minimum age: 18, under Anthropic's Consumer Terms.

What Data Does Claude Collect?

Claude collects your account details, conversations, uploaded files, usage and device information, and any feedback you submit.

  • Account details: your email address and any billing information tied to a paid plan.
  • Conversations: everything you type and everything Claude generates in response.
  • Uploaded files: documents, images and other material you attach to a chat or a Project.
  • Usage and device information: ordinary technical data about how you access Claude, similar to what most online services collect.
  • Feedback: anything you submit via a thumbs up or down, or a bug report, retained separately for up to five years.

That's the foundation the rest of this page builds on.

How Does Claude Handle Uploaded Files and Projects?

Files uploaded to a standard Claude chat are tied to that conversation, while files added to a Project become part of a persistent knowledge base that Claude can reference across every conversation in that Project.

A Project bundles that knowledge base with custom instructions and its own conversation history, so you don't have to re-upload the same files every time. Free accounts can create up to five Projects; paid plans allow more. Files you add to a Project's knowledge base are indexed and referenced automatically across every conversation inside that Project, which is different from a standard chat, where an uploaded file is scoped to that single conversation and isn't available once you start a new one.

Whether Project content can be used for model improvement follows the same account-level choice covered below, applied to the whole Project rather than decided per file. Deleting a Project removes its knowledge base and associated conversations. If you're storing anything regulated or genuinely confidential in a Project's knowledge base, that's exactly the kind of use that belongs on Claude for Work or Enterprise rather than a personal account, given the stronger contractual protections those tiers carry.

Does Claude Use Your Data for AI Training?

Only if you choose to allow it. Consumer accounts are asked to make an active decision rather than being placed into training by default, and that's a deliberate design choice Anthropic made in 2025.

Until August 2025, Anthropic's position was that consumer conversations weren't used for model training at all. That changed with an update to its Consumer Terms, which asks users to actively choose whether their chats and coding sessions can be used to improve Claude, rather than placing everyone into training by default. Existing users were given a window to make that choice, and new users now make it as part of using the product.

How I checked Claude. I checked Claude.ai's current UK consumer settings in August 2026, including the model-improvement choice, Incognito mode, retention behaviour and account deletion, and compared what appears in the product with Anthropic's current Privacy Centre documentation. See how we research AI safety for our full methodology.

Is Claude Secure? Account Security and MFA Explained

Claude supports multi-factor authentication, and for most users the biggest practical account-security risk is someone gaining access to their login rather than a weakness in Claude's privacy controls. Nick, who leads our testing on the security side, was genuinely more impressed by this than he expected going in. His usual complaint with AI privacy settings is that companies bury the meaningful choice behind three menus of noise; his note on Claude specifically was that the account-security basics sit exactly where you'd look for them first.

Account security is separate from Claude's privacy controls: strong data settings don't help if someone else can access your account. If someone gets into your account, they get your conversation history, anything sitting in your Projects, and whatever billing details are attached. Review active sessions periodically, and treat any unexpected password-reset email as a reason to check your account directly rather than clicking through it.

What Is Safe to Share With Claude?

I'd use Claude for ordinary writing, research and brainstorming on a personal account; I'd redact personal documents and keep credentials, client data and other confidential material out unless I was using an organisation-approved work product.

CategoryDSS guidance
General writing, research, brainstormingFine on a personal account
Personal questions, uploaded personal documentsThink first; redact identifying detail where you can
Client or company materialUse an approved work product, not a personal account
Credentials or identifying secretsDon't share, on any account tier

Claude Free vs Pro vs Max vs Enterprise: Which Is More Private?

Claude Free, Pro and Max versus Work differ in privacy far more than they differ in capability for a paying consumer. Free, Pro and Max are all governed by the same consumer terms covered throughout this page, including the same model-improvement choice and the same 30-day standard deletion window. What genuinely changes the privacy picture is moving to Claude for Work, Claude Enterprise or API access, which sit under separate commercial terms that exclude training by default and typically include a proper data processing agreement. If your reason for upgrading is privacy rather than a better model, a personal Pro or Max subscription isn't actually what achieves that.

What Happens if You Allow Claude to Use Chats for Model Training?

If you choose ‘Allow', eligible new or resumed chats and coding sessions can be used to improve Claude and retained for that purpose for up to five years. Here's what that actually means. Eligible new or resumed chats and coding sessions become part of Anthropic's model-improvement pipeline, and are retained in de-identified form for up to five years. This only applies going forward from the point you make that choice; conversations that had no further activity beforehand aren't pulled in retroactively.

What Happens if You Turn Off Claude Model Training?

If you choose ‘Don't Allow', ordinary chats are excluded from Anthropic's model-improvement pipeline and standard deletion rules continue to apply. It's the choice I'd make if privacy matters more to you than contributing chats to model improvement. Conversations are removed from your visible history immediately when deleted, and from Anthropic's backend systems within 30 days. See how to delete your data from AI chatbots for the exact steps. It doesn't, on its own, make Claude a confidential space.

Claude model improvement privacy setting
Claude gives consumers a specific choice over model improvement. Choosing ‘Don’t Allow’ keeps ordinary chats out of Anthropic’s model-improvement pipeline, although separate safety-review circumstances can still apply.

 

Can Anthropic Review Your Claude Chats if Training Is Off?

Even if model improvement is switched off, conversations flagged by Anthropic's automated trust-and-safety systems can still be reviewed, and feedback you submit is handled separately. This is the part I wouldn't skip, because it explains why ‘I turned training off' and ‘Anthropic can never review this conversation' are different claims. Anthropic states that conversations flagged by its automated trust and safety systems for a Usage Policy violation can still be analysed to improve safeguard detection and enforcement, independent of your general training choice. Inputs and outputs from a flagged conversation can be retained for up to two years, and the trust and safety classification scores generated from that review can be kept for up to seven years. Separately, if you submit feedback through a thumbs up or down, or a bug report, that submission is retained for five years. Incognito is the clear exception when it comes to model improvement: Anthropic states Incognito chats are never used to improve Claude, regardless of your other settings.

How Long Does Claude Keep Your Data?

Deleted Claude chats are normally removed from Anthropic's backend systems within 30 days, but chats used for model improvement, feedback and flagged safety content can be retained for longer. The exceptions are what make the table look more complicated.

SituationRetention
Deleted conversation, training not allowedRemoved from backend within 30 days
Conversation used for model improvementUp to 5 years, from new or resumed chats only
Flagged Usage Policy violation, inputs and outputsUp to 2 years
Trust and safety classification scores from a flagged conversationUp to 7 years
Feedback you submit (thumbs up or down, bug reports)5 years
Incognito chatsNever used for training; deleted within 30 days unless flagged

Those longer figures relate to specific trust-and-safety circumstances, not ordinary chats sitting around for seven years by default. One point worth being precise about: if you allowed training and then change your mind, Anthropic states it won't use previous or new chats going forward, but data already included in a training run that's already happened, or a model that's already been trained, can't be retroactively removed.

Is Claude Incognito Mode Private?

More private, yes, but not private in an absolute sense, since it's still processed on Anthropic's servers to generate a response. Incognito is the mode I'd reach for if I wanted a one-off conversation kept out of model improvement. I still wouldn't use it as a substitute for deciding whether the information needed to be shared at all.

Claude Incognito chat mode
Claude’s Incognito mode keeps a conversation out of model improvement, but the chat still has to be processed on Anthropic’s servers. I’d treat it as an extra privacy control rather than confidentiality.

 

What Privacy Controls Does Claude Have?

Claude's main privacy controls are the model-improvement choice, Incognito mode, and straightforward conversation and account deletion. Checked against the other mainstream tools, Claude is clearer than most about separating its model-improvement choice from Incognito. The controls don't make the service confidential, but I had less trouble working out what each setting was supposed to change. Deletion is straightforward too: removing a conversation from history is a single action, with the 30-day backend window disclosed rather than buried.

Is Claude Safe for Work?

Not on a personal account, but yes on the right commercial tier. If you're considering Claude because your team already uses it for work, check which version you're actually using before applying anything in this consumer guide. Anthropic states that commercial products, Claude for Work, Claude Enterprise, Claude for Education and API access including through Amazon Bedrock or Google Cloud Vertex AI, aren't used for model training by default and sit under separate commercial terms entirely. See our guide on what AI safety means for organisations.

Is Claude Safe for Kids and Teenagers?

No. Claude.ai's consumer service requires users to be at least 18 years old under Anthropic's Consumer Terms. This is a firmer line than some other mainstream AI tools, and it means Claude isn't an appropriate choice for a child or teenager to use independently, regardless of supervision.

Is Claude Safer Than ChatGPT?

Claude currently has an advantage over ChatGPT on consumer training consent, but neither personal account should be treated as confidential and both can produce inaccurate answers.

CategoryClaudeChatGPT
Training consentOpt-in requiredOpt-out available, on by default
Minimum age1813, with parental permission under 18
AccuracyNeither should be assumed correct without checkingNeither should be assumed correct without checking
Confidentiality on a personal accountNot confidentialNot confidential

See Are AI Chats Private? for the full four-tool comparison, what information you should never share with AI regardless of which you choose, Best Private AI Chatbots if privacy is the deciding factor, or the AI Safety hub for more on AI safety.

Is Claude Safe? Our Final Verdict

For an adult using AI for ordinary writing, research and planning, I think Claude is a reasonable choice and one of the clearer mainstream services when it comes to model-improvement consent.

I'd still keep genuinely sensitive information out of a personal account, and I wouldn't confuse Incognito or a training opt-out with confidentiality. Claude gives you useful choices. The important part is making them deliberately.

Frequently Asked Questions

Does Claude use my chats for training?
Only if you choose to allow it. Consumer accounts are asked to make an active decision rather than being placed into training by default.
Your chats are excluded from training, and deleted conversations are removed from Anthropic's backend systems within 30 days, subject to the separate safety-review exception for flagged conten

Yes. Conversations flagged by automated trust and safety systems for a Usage Policy violation can be analysed independent of your general training choice, with inputs and outputs retained for up to two years and classification scores for up to seven years.

Not on a personal account. Use Claude for Work or API access under a signed agreement, which excludes training and offers stronger contractual protection.
Claude currently has the edge on training consent specifically. On accuracy and confidentiality, neither tool should be treated as a special case; both need the same caution
No. Claude.ai's consumer service is restricted to users 18 and over under Anthropic's Consumer Terms. If you're weighing up AI tools for a younger user in your household, our Family Guide to AI and Is ChatGPT Safe for Kids? cover the age-appropriate options.

Ready to level up your safety kit?

Whether you’re protecting your family, your business, or just staying ready for the unexpected, our digital safety shop is packed with smart, simple solutions that make a real difference.
From webcam covers and SOS alarms to portable safes and password keys, every item is chosen for one reason: it works. No tech skills needed, no gimmicks, just practical tools that help you stay one step ahead.