It depends on which account you are signed into, and the consumer default is usually yes.
But this is the question everyone asks and it is the least important of the three that matter. The other two almost never get asked.
Every major vendor draws the same line in the same place — between the account you sign up for yourself and the account your employer pays for.
| What you're using | Used to train models? |
|---|---|
| Consumer accounts the free tier, and the personal paid tiers | Usually yes, by default, with a setting to opt out. The setting is often not where you would look for it, and turning it off does not delete what was already sent. |
| Business tiers team, enterprise and education plans | Generally no, by default. Not using business content for training is the main thing these tiers are selling. |
| The API anything your developers built on | Generally no, by default, across the major providers. |
Deliberately stated as categories rather than a table of current vendor settings. Those settings change, sometimes quietly, and a page that lists them accurately today is a page that misleads people next year. The section below tells you how to check yours, which is the part that keeps working.
"They don't train on it" gets treated as the all-clear. It answers about a third of the problem.
The question everyone asks. It matters because a model trained on your text has, in principle, absorbed something from it — though a model regurgitating one company's pasted secret to another user is far rarer than the fear suggests, and is not the main risk here.
This is the one that gets skipped. Providers who don't train on your inputs still retain them — commonly for a period measured in weeks — and still allow human review for abuse monitoring. Both are legitimate and both are disclosed in the documentation. Neither is what people picture when they read "not used for training".
Some enterprise arrangements offer zero-retention processing. It is usually something you have to ask for and sometimes something you have to qualify for. It is almost never the default.
Your text reaches the provider's subprocessors, in whichever countries they operate. For personal data under GDPR, UK GDPR, the Australian Privacy Act or India's DPDP Act, that is a transfer with its own requirements — lawful basis, transfer mechanism, and a record of processing that names the recipient.
If the text was about someone else, you disclosed their data to a company you have no agreement with. Whether a model learned from it is a separate question, and answering that one does not answer this one.
Your customer did not agree to their record being sent to an AI vendor. Your patient did not. Your employee did not. The obligation you are under is to that person, and it isn't discharged by a setting in your account.
That is why the answer pages here are organised by whose data it is rather than by which tool you were using. The tool's training policy is a detail inside a decision you already made when you pressed paste.
Four steps that work for any vendor and keep working after the menus move.
The opt-out is per account, and so is the mistake. Your organisation can hold an enterprise agreement with every protection negotiated, and it protects exactly nothing when somebody pastes a spreadsheet into their own personal account on their own laptop at half past nine at night.
This is the single most common shape of the problem, and it is not a technology failure — the person was trying to get their work done and used the tool that was open. It is why the useful intervention is a habit and a link rather than a policy nobody reads: don't paste that, and here's the thing to check it with.
Redact before you send, not after you worry. The answer you get back is the same.
Write a follow-up email
to Alex Morgan at
[email protected]
about invoice INV-40021,
84,000 outstanding since
2026-05-14. Write a follow-up email
to a business customer
about an overdue invoice,
around 90 days late, for
a significant amount.
Firm but not aggressive,
we want to keep them. If you'd rather see what's in a block of text before you decide, the checker reads it in your own browser and tells you. It sends nothing anywhere, and you can watch the network panel to confirm that while you use it.
Don't spend the evening trying to work out how bad it was — that assessment usually isn't yours to make alone, and the clock is the thing that matters.
If it was a key or a token, rotate it now. If it was someone's personal data, tell whoever handles privacy at your organisation today; breach notification clocks run from discovery and they are short. Turning off the training setting afterwards does not undo the disclosure, and nobody assessing it will treat it as though it did.