Lesson 6 of 6 · Working with Documents and Data
Privacy for your files
Uploading a file is not like opening it. It is like mailing a copy. This lesson is where the copy goes, which switch controls it in each tool, and the short list of things a business should never send.
Trust and limits gave you the short version: treat a chatbot like a smart contractor you just met. This lesson is the long version, for files specifically, because a file carries more than a chat message does. A customer list is hundreds of people's information in one tap. A tax return is your whole year. Knowing exactly what happens after upload lets you use these tools freely for the ninety percent of files that are fine and confidently keep out the ten percent that are not.
What happens after you tap upload
Three things can happen to an uploaded file, and every tool does some combination of them:
- It is stored. The file sits on the company's servers, attached to your account and that chat, for some period. That is how the chat can still reference it tomorrow.
- It may be reviewed. Some companies have people read a sample of conversations to improve the product or check for abuse. Google's help pages say this plainly for Gemini.
- It may be used for training. The company may use your chats and uploads as examples when it teaches its next model. This is the one most people worry about, and it is the one you usually get a switch for.
None of that means an employee is reading your invoice tonight. It means you should assume the file is out of your hands the moment it is uploaded, and decide accordingly.
Sort the file: safe to upload on a personal account, or never?
Your published price sheet
A customer list with phone numbers and addresses
A blank version of your service agreement
Last year's tax return
A photo of a job site with no people in it
An employee's doctor's note
Your own draft blog post
A spreadsheet of customer card numbers
0 of 8 sorted.
Assumes a consumer (personal) account. A business plan where your company controls the data changes the rules, as the lesson explains.
The training switch in each tool, as of August 2026
These settings change, and their names change more often than the settings do. This is what the official help pages said on the date this lesson was updated.
- ChatGPT. The setting is called "Improve the model for everyone," under Settings, then Data Controls. It is on by default for Free, Plus, and Pro accounts. Turning it off stops new conversations from being used for training; it is not retroactive. For a one-off sensitive question, Temporary Chat is never used for training and is deleted within 30 days.
- Claude. In August 2025 Anthropic changed its consumer terms so that Free, Pro, and Max chats can be used to improve Claude, and asked every user to make an active choice in Privacy Settings. If you allow it, those chats are kept for five years. If you do not, the retention period is 30 days. It applies only to new or resumed chats, and it does not apply to Claude for Work, Government, Education, or the API.
- Gemini. The setting is now called "Keep Activity," found at myactivity.google.com under Gemini. For adults it is on by default. Since September 2, 2025, a sample of uploads (files, photos, screens) can be used to improve Google services, with the help of human reviewers, when it is on. With it off, chats are still kept for 72 hours to respond and for safety. Chats a reviewer has already read are kept up to three years, disconnected from your account. Temporary Chats are not used for training or personalization.
Flip the switch once, today, in each tool you use. It takes a minute. Then keep reading, because the switch is not the whole story.
Consumer plans versus business plans
The rules above are for personal accounts. Business plans are a different contract. As of August 2026, OpenAI states that ChatGPT Business, Enterprise, and Edu data is not used to train its models by default, and Anthropic's Claude for Work plans (Team and Enterprise) were explicitly carved out of the consumer training change. Google's work and school accounts run under Workspace terms, where the administrator controls the activity setting.
For a small business, this is the actual decision. If you will ever want the AI to read customer records, payroll, or contracts with names in them, you want a plan where your company controls the data and training is off by contract, not by a toggle you hope nobody reset. If you only ever upload public material and your own drafts, a personal account with the switch off is fine.
What a business should never upload
On a personal or consumer account, keep these out, no exceptions:
- Other people's personal information. Customer lists with phone numbers or addresses, employee records, anything with a Social Security number. They did not agree to it.
- Financials. Tax returns, bank statements, payroll, unreleased revenue. The question is usually answerable without the file: describe the situation in round numbers instead.
- Medical information. A doctor's note, an insurance claim, anything about someone's health with their name on it.
- Passwords, card numbers, account numbers. Never in a chat, never in a file.
- Signed contracts with the other party's details. Upload the blank template instead. It answers the same questions.
The pattern behind the list: the AI almost never needs the identifying details to help you. It needs the structure. Strip the names, round the numbers, and the file that was off limits becomes a file you can use freely.
Shared links, shared devices, and deleting
The training switch gets all the attention, but the two most common ways a file actually gets out have nothing to do with training. First, shared links. Every major tool lets you share a conversation by link, and the link usually includes the attached files or their contents. A shared chat about "my pricing strategy" that was meant for your business partner is one forward away from a competitor. Share chats the way you would share a document: check what is in them first.
Second, shared devices and logged-in browsers. Your chat history is a list of everything you have uploaded, readable by anyone who opens the app on your phone or your front-desk computer. A tint shop's shared iPad with ChatGPT logged in is a filing cabinet with no lock. Log out on shared devices, or use a separate account for the shop.
And when something does slip through, delete it. Every tool lets you delete a conversation, and the attached files go with it. As of August 2026, OpenAI says deleted chats are scheduled for permanent removal within 30 days. Anthropic's 30-day retention applies to consumer users who have not opted into training. Google keeps Gemini chats 72 hours after deletion when Keep Activity is off. Deleting is worth doing for anything sensitive that slipped through. It is not a substitute for not uploading it.
Try this yourself
A five-minute settings check, once per tool. Then, for the next file you are unsure about, paste this into the chat before you attach anything:
I want to ask you about a document but I am not going to upload it. Here is what it is: [type of file, e.g. a customer invoice, a lease, a staff schedule]. Here is what I need: [your question]. Tell me what information from the document you actually need to answer, and suggest how I can give you that with names, contact details, account numbers, and exact dollar figures removed or replaced with placeholders.
Most of the time the answer is "I only need the dates and the clause about X." Give it that. You get the same help, and the file stays on your computer. That is the whole module: know what the AI can see, give it exactly that, and nothing more.
Last updated August 24, 2026