Claude and Your Privacy: What Anthropic Sees and What You Control
Privacy with any cloud AI comes down to three questions: what leaves your device, who is allowed to use it, and what you can switch off. Claude is made by…
Claude guide · as of July 10, 2026 · 5 minutes read · details change — confirm current specs on claude.ai
Privacy with any cloud AI comes down to three questions: what leaves your device, who is allowed to use it, and what you can switch off. Claude is made by Anthropic, a public-benefit company whose whole pitch is AI safety — but "safety-focused" is not the same as "your data never leaves." This guide is the plain version: the defaults, the controls, and the short list of things actually worth doing.
The one fact that shapes everything: Claude is cloud-only
Claude runs on Anthropic's servers, not on your phone or laptop. There is no offline mode. Whatever you paste — a contract, a doctor's letter, source code, a list of customers — travels to the cloud to be processed and answered. For most everyday use that is completely fine. For a narrow slice of sensitive work it is a dealbreaker, and I will be honest about that near the end.
Training: the default depends on which door you came through
The biggest privacy question people ask is whether their conversations are used to train future models. The honest mid-2026 answer: it depends on your account type, and the consumer default has shifted over time. So the reliable move is to check your own setting rather than trust any article, including this one.
| Account type | Used to train models by default? | Where you control it |
|---|---|---|
| Free / Pro / Max (consumer) | It has changed over time — treat it as your choice to set | Settings → the data/privacy controls toggle |
| Team / Enterprise | No, per the commercial terms | Your workspace admin settings |
| API / Claude Code (commercial) | No, per the commercial terms | Org settings; ask about zero-retention options |
A few things that are true across the board:
- Commercial use (API, Team, Enterprise) is not used to train models by default — that is a long-standing part of Anthropic's commercial terms.
- Consumer plans (Free, Pro, Max) have a data-use setting you can open and read for yourself. Because the default has moved, do not assume — go set it.
- Feedback is different from training. When you click thumbs-up/down or submit a flag, you are explicitly handing that conversation to Anthropic for review. Do not rate a reply that contains something you would not want a human to read.
- Conversations are retained so you can see your history, and you can delete them. Deletion removes them from your view and purges them on a schedule (check the current policy for the exact window). Content flagged for safety may be kept longer — that is standard for trust-and-safety at every major provider.
Because specifics like retention windows and defaults get updated, stamp everything here as of July 2026 — confirm at claude.ai / anthropic.com.
Projects, files, images, and memory
Projects let you attach persistent knowledge — documents, notes, instructions — that Claude can draw on across chats. That content lives in your account and is used to answer your prompts inside that project. Whether any of it feeds model training follows the same account-level setting as your chats, so set that toggle once and it governs the lot.
Files and images you upload are processed the same way as text: sent to the cloud, read, answered. Claude has strong vision (it reads images and documents), but reading is still sending — an uploaded passport photo or a screenshot of a private thread has left your device.
Treat a Project like a shared drawer, not a vault: convenient, searchable, and only as private as the account it sits in. Do not stock it with secrets you would not want tied to your login.
Connectors, MCP, and web search
Claude can reach outside its own chat window, and each bridge is a place data moves:
- MCP / connectors link Claude to your own tools and data (files, calendars, internal systems). That is powerful, but it means Claude can read whatever you connect. Grant the narrowest access that does the job, and disconnect what you are done with.
- Web search sends query text out to fetch current results. Assume the substance of a search leaves the conversation.
- Claude Code operates on real files in your repo. It is agentic, so review what it can touch before you point it at anything sensitive.
When Claude is the wrong tool
This is the candid beat. If you have data that legally or contractually cannot leave your machine — regulated health or legal records without the right agreement in place, classified material, or anything under an air-gapped requirement — a cloud service is the wrong choice, full stop. No settings toggle changes the fact that the data is transmitted and processed off your device.
In that situation, reach for a local model you run yourself (see the sibling guide below), or use Claude only on redacted, non-identifying versions of the material. Convenience is not worth breaking a compliance rule or a promise you made to someone whose data it is.
What to actually do
- Open your data/privacy settings once and set the training toggle deliberately — do not leave it on a default you never chose.
- Keep secrets (passwords, full account numbers, other people's private data) out of chats, Projects, and uploads.
- Remember thumbs and flags hand a conversation to humans — skip them on anything sensitive.
- Give connectors and MCP the least access needed, and disconnect them when finished.
- For truly can't-leave-the-building data, use a local model instead of Claude.
- Re-check the policy periodically — defaults and retention windows change.
