It is transmitted, stored, possibly read by a person, and possibly used for training. In that order, and the last one matters least.
Which of the four apply depends on your account tier and on whose courts can reach the servers. Neither is on the screen while you're typing.
These happen to every prompt you send to a hosted AI tool. Not to the risky ones — to all of them.
The connection is encrypted, which protects it from everyone except the party you're sending it to. That is the whole point of the connection. "It's encrypted" answers a question nobody was asking: the vendor receives your plaintext, because they have to in order to answer you.
The moment it arrives, your organisation has disclosed it to a third party. If the text was about a customer, a patient or an employee, that disclosure needed a lawful basis and probably a data processing agreement — and neither of those is something you can grant by clicking send.
Effectively every provider retains prompts for some period, commonly measured in weeks, and commonly even when they do not train on them. Retention exists for abuse investigation, debugging and legal obligation, all of which are legitimate. It also means the text exists on someone else's disks for longer than your conversation did.
Zero-retention processing exists at the enterprise tier of several providers. It is generally something you request and qualify for, not something that is on by default.
This is the one that gets skipped, and it is more consequential than training. Most providers reserve the right to have staff or contractors review conversations flagged for abuse or sampled for quality. Again: legitimate, disclosed in the documentation, and not what anybody pictures when they read "we don't use your data".
"We don't train on your data" and "no human will ever see it" are different promises, and only the first one is usually being made.
The question everyone leads with. On consumer tiers it is commonly yes by default with a setting to turn it off; on business tiers and APIs it is commonly no by default. The longer version is its own page.
It matters least because by the time you're asking it, the first three have already happened. Training is a question about what the vendor does with a disclosure you have already made.
Three things, and they are the three worth asking about. Everything else is interface.
| Question | What you're actually asking |
|---|---|
| Training | Will this text influence a model other people use? Usually determined by your tier, not the product. |
| Retention and human review | How long does it sit there, and who is allowed to open it? The question most likely to have an answer you didn't expect. |
| Jurisdiction and subprocessors | Which country's servers, which country's courts, and who else in the supply chain gets a copy? The question almost nobody asks. |
Not a table of products — those change. A table of arrangements, which don't.
ChatGPT, Claude, Gemini, Copilot and the rest, on a free or personal paid plan. The most permissive defaults, the shortest terms, and no agreement between the vendor and your employer. This is where almost every real incident happens, because it is the account people already have open.
Team, enterprise and education plans. Not training on business content is the main thing these are selling, and they usually come with a data processing agreement, which is the document that makes the arrangement lawful rather than merely reassuring.
What your developers built on, or a managed model service inside a cloud account you already hold. Generally the strongest position, because it inherits the agreements, region controls and audit trail your organisation already negotiated with that provider.
Nothing leaves. This is the only arrangement where the four things above genuinely do not apply — the trade is that you own the security of the machine instead, and "it's local" stops being true the moment someone points it at a hosted API for the hard questions.
The under-asked question, and the one that changed most in the last two years as capable models started shipping from more places.
Chinese-operated services — DeepSeek, Moonshot's Kimi, Alibaba's Qwen and others — are frequently excellent and frequently free, which is exactly why they get used at work. The material point is not the model. It is that when the service is operated from the PRC, the data lands on infrastructure subject to PRC law and PRC legal process. Several governments reviewed that and restricted these tools on official devices during 2025; whether that reasoning applies to you depends on what you handle, not on where you live.
And the same question has a US answer. A US-operated service is reachable by US legal process, including for data held outside the country. A European regulator has already found aspects of a major AI service's processing unlawful. There is no jurisdiction-free option on this list — there is only knowing which one you have chosen.
The honest version: "don't use the Chinese one" is not the lesson, and a policy built on it will be wrong in both directions — it bans a capable tool for the wrong reason while waving through a US consumer account that leaks the same data. The lesson is that a hosted model is a disclosure to a company operating under some government's law, and you should know which one before the customer list goes in.
Open weights complicate it further in a useful way: a Chinese-developed model running on your own hardware, or inside your own cloud region, sends nothing to China. The model's origin and the service's jurisdiction are different questions, and conflating them is how organisations end up with a rule that protects nothing.
Four steps that work on any vendor and survive the menus moving.
There is no unsend. Every arrangement above, at every tier, in every country, shares that. A prompt is a disclosure at the moment you press send, and no setting applied afterwards retracts it.
Which is why the useful habit is upstream of all of this: know the five categories that shouldn't go in, and check the text before it goes anywhere. That check runs in your browser and sends nothing to anyone — you can watch the network panel while it works, which is a claim worth making a vendor prove before you trust theirs.