Whether your business data is safe with AI depends on the account you use, not the tool. A personal ChatGPT, Claude or Gemini login can use what you type to train the next model when the training setting is on. A business login does not by default.
Is it safe to put customer data into ChatGPT, Claude or Gemini?
It is much safer on a business account, because the account decides whether the company can train on what you type.
All three companies run a personal account and a business account. On the personal one, the company keeps some of what you type to improve its models. On the business one, your content stays out of training by default.
Paying does not turn a personal account into a business one. ChatGPT Free, Plus and Pro, Claude Free, Pro and Max, and Gemini on a personal Google account (including a paid Google AI plan) are all personal accounts. Business accounts are ChatGPT Business or Enterprise, Claude Team or Enterprise, and Gemini through a Google Workspace work login. Apps connected to these companies through a developer (API) account fall under the business rules too.
| Tool | Personal account | Business account |
|---|---|---|
| ChatGPT | New chats can be used to train OpenAI's models unless you turn off "Improve the model for everyone" | OpenAI says it does not use ChatGPT Business, Enterprise or Edu content to train its models by default |
| Claude | Used to improve Claude if you allow it. Kept up to 5 years if you allow it, 30 days if you do not | Anthropic says that by default it does not train on chats from Claude Team, Enterprise or developer (API) accounts |
| Gemini | With Keep Activity on, Google uses your chats to improve its AI, including training, and reviewers may read some. Chats are kept 18 months by default. Any a reviewer has seen are kept up to 3 years, even if you delete them | Google says chats and files on a Workspace work account are not read by reviewers or used to train its AI outside your organisation without permission |
How do you switch off training in the app you already use?
Open the data setting in ChatGPT, Claude and Gemini and turn off the option that lets the company train on your chats.
In ChatGPT, open Settings, then Data controls, and turn off "Improve the model for everyone". OpenAI's help page says that once it is off, your new conversations won't be used to train its models, though they still show in your chat history. For a one-off question about a client, a Temporary Chat is not used to improve the models, and OpenAI may keep a copy for up to 30 days for safety. Data controls is also where you manage any chats you have shared by link. In mid 2025, shared ChatGPT chats were reported turning up in Google search results, and OpenAI removed the option that allowed it, so treat a Share link as a public web address.
In Claude, open Settings, then Privacy, and turn off "Help Improve our AI models". Incognito chats are not used to improve Claude even when that setting is on. Anthropic can still use any chat its safety systems flag, whatever the setting.
In Gemini, go to myactivity.google.com/product/gemini and turn off Keep Activity. That protects future chats and does not pull back the old ones, and chats a reviewer has already seen stay for up to 3 years.
One thing applies to all three. Rating a reply with thumbs up or thumbs down sends that conversation to the company, and it can be used to improve their models even with training switched off. Anthropic keeps feedback for up to 5 years and Google for up to 3. Skip the rating on any chat that has a client's details in it.
Does the Privacy Act cover a small business using AI?
Usually not, if your business turns over $3 million or less a year. Some businesses are covered at any size.
The Office of the Australian Information Commissioner (OAIC) lists those exceptions: health service providers, businesses that trade in personal information, and several others. Allied health professionals are on the OAIC's list of health service providers, so a clinic that holds health information is covered at any size. The OAIC's small business page gave the $3 million threshold when we checked it on 2 October 2026. A draft privacy bill closed for comment on 18 September 2026, so check again before you rely on it.
Your customers are unlikely to know whether you are exempt. The OAIC's 2026 community survey of 1,511 Australians, run in March, found 93% think it is unfair for a business to take details collected to serve them and use them to train AI. It also found trust in AI companies at 4%. If the Act does cover you, a data breach likely to cause serious harm has to be reported to the people affected and to the OAIC.
On public tools, the OAIC is direct: "As a matter of best practice, the OAIC recommends that organisations do not enter personal information, and particularly sensitive information, into publicly available generative AI tools, due to the significant and complex privacy risks involved." Treat a personal ChatGPT, Claude or Gemini login as one of those tools.
What do health clinics need to do before using AI?
Get the patient's informed consent first, and note their answer in their health record.
The Australian Health Practitioner Regulation Agency (AHPRA) says an AI scribing tool that uses generative AI will generally need personal data put into it, and so needs informed consent from your patient or client. It also asks you to find out whether what you record is used to train the model for future patients. If you run a clinic, that conversation comes before the tool does. Our piece on what AI can take off a clinic's front desk covers where the time goes.
What are the real risks for a business your size?
The biggest risk is a staff member using a personal AI login for work you never agreed to.
Nobody set out to cause a problem. They pasted a client's email or a quote into the free version because it was open on their phone, and now it sits in an account you cannot see and cannot delete. Health notes, ID documents and bank details are the ones to keep out of any tool you have not chosen.
The second is a tool that reads your email and can also send emails or open links. Instructions can be hidden inside an email, and an assistant that follows them can hand over information. In June 2025, researchers at Aim Labs disclosed a flaw in Microsoft 365 Copilot, known as EchoLeak, where a single email, with no click, could make it hand over confidential data. Microsoft fixed it on its side, and the published research found no sign it was used against anyone. A tool that can only read, and drafts that wait for your approval before anything is sent, limit what a hidden instruction can do. They do not remove the risk.
The third is the login itself. Anyone who gets into your AI account can read every chat in it, so turn on two-step login for it, the same as you would for Xero or your booking system.
Those three, a staff member's personal login, a tool that can act on what it reads, and a stolen login, are where the real risk sits for a small business.
What should you ask anyone who builds AI into your business?
Ask whose accounts the system runs in and what it can change.
| Ask | A good answer | A bad answer |
|---|---|---|
| Whose accounts is it built in? | Yours. The builder never holds your passwords | The builder's own accounts, or a request to send them your logins |
| Can it change my books or jobs? | No. The connections are read-only, you create them, and you can switch them off at any time | Write access to your accounting or booking system "to save time" |
| What happens when the build ends? | Any temporary access is removed at handover and everything keeps running without them | It only works while you keep paying them |
| Does anything reach my customers without my approval? | No. Nothing reaches a customer without your approval | Replies and emails that send automatically from day one |
Those are the answers we give for the systems we build. They run in your own accounts, on your own server in the cloud, for a small monthly fee.
Our own setup follows the same rules. Our AI runs on our own server, with its own logins and security. When a password or API key (the code one app uses to log in to another) has to go onto that server, it is typed into a hidden prompt on the server itself, where nothing shows on screen. It is saved to a locked file only the server's administrator can open, and never pasted into a chat with the AI. Do the same in your business: a password, API key or customer's details should never go into an AI chat, even on your own account.
Where to start
Ask your staff which login they use for AI at work, then turn off the training setting in each app above. Then give everyone a rule they can follow without thinking about it. Something like: "Client names, health notes, ID documents and bank details do not go into any AI tool unless the owner has chosen it for work. Use the business login, not your own." Copy it, change the wording to suit, and put it where your staff will see it.
If you are deciding what to hand to AI first, what a small business should automate first puts the jobs in order.
Data safety is one part of putting AI to work in a business. Every business is unique, so what we build for yours is customised to how you work, and the only limit is your imagination. The Engine is $3,500 and each element pack is $950, listed on the automations we build for small business.
We are based on the Sunshine Coast and work Australia-wide by screen share. Answer a few short questions and we will provide a free custom audit of your business.
Sources
- OpenAI: Data controls in ChatGPT (help.openai.com), read 2 October 2026.
- Anthropic: Updates to our Consumer Terms and Privacy Policy (28 August 2025); Is my data used for model training? and Is my data used for model training? (commercial) (privacy.claude.com), read 2 October 2026.
- Google: Gemini Apps Privacy Hub (support.google.com/gemini/answer/13594961, updated 24 September 2026); Generative AI in Google Workspace Privacy Hub (updated 14 August 2026), read 2 October 2026.
- OpenAI: How your data is used to improve model performance (help.openai.com), read 2 October 2026.
- OAIC: Small business; Guidance on privacy and the use of commercially available AI products (published 21 October 2024, updated 17 January 2025); Notifiable data breaches; Australian Community Attitudes to Privacy Survey 2026 (published 28 May 2026).
- Attorney-General's Department: Privacy reform consultation, exposure draft closed 18 September 2026.
- AHPRA: Artificial intelligence in healthcare (page reviewed 22 August 2024).
- Aim Labs, EchoLeak (CVE-2025-32711), Microsoft 365 Copilot, June 2025, as described in the published research paper (arxiv.org/abs/2509.10540).
- Bitdefender: Your shared ChatGPT chats may be publicly searchable (1 August 2025).
What we build AI search and SEO · Email marketing · AI automations · Web design