Copilot vs ChatGPT vs Gemini vs Claude: Which Is Safest for Confidential Client Data?

Use Cases|10 min read|Updated 2026-07-19
Written byMoneli Automation
Technically reviewedMoneli Automation
Last verified2026-07-19
This guide is notlegal advice

Disclaimer: This content is for educational purposes only and does not constitute medical, legal, or financial advice. CPT descriptions are original summaries — not official AMA text. Always verify billing and credentialing details with your payer. Read full disclaimer

If you own a clinic, a law firm, or an accounting practice, the AI question you actually have isn't "which chatbot is smartest." It's narrower and more nervous: if I paste a client's file into this thing, where does it go, who reads it, and could it ever be handed to someone in a lawsuit? Copilot, ChatGPT, Gemini, and Claude all answer that question differently — and each of them answers it differently again depending on whether you're on the free app or a paid business plan. This page is a plain-language custody scorecard for all four, with every claim linked to the vendor's own current policy.

The short answer: on their paid business tiers, all four assistants commit — in their own documentation — not to train their foundation models on your content by default. On the free consumer apps, the protections are weaker and uneven: consumer ChatGPT may train on your text unless you opt out, and Google flatly tells consumer Gemini users not to enter confidential information at all. So the honest ranking isn't Brand A over Brand B — it's paid business tier over free consumer app, across the board. And underneath even the best of them sits one fact none of the four escapes: your text is processed and stored on the vendor's servers, where legal process can reach it. The only setup with no third party in custody is a model running on hardware you own.

Why does the tier decide the answer, not the brand?

This is the single most important thing to understand, because it's where most "is ChatGPT safe?" arguments go wrong. Every one of these companies runs two very different products under one familiar name: a free consumer chat app aimed at the public, and a paid business or enterprise tier sold to organizations. The privacy guarantees you've heard about — "they don't train on your data" — almost always attach to the business tier. The free app you signed up for with a personal email usually operates under looser defaults.

You can see the split most clearly with Anthropic. Its consumer-plans article (covering Claude Free, Pro, and Max) is a separate document from its commercial terms — and the company says so explicitly, noting that the consumer article covers "our consumer products such as Claude Free, Pro, Max," while commercial products are governed elsewhere. The commercial Terms of Service then state plainly that "Anthropic may not train models on Customer Content from Services," and that the customer "retains all rights to its Inputs" and "owns its Outputs." Same brand, two custody stories. Which one covers you depends entirely on which door you walked in.

So when you compare these products, compare tiers — not logos.

What does each assistant actually do with your text?

Here's the per-product scorecard. Every cell is the vendor's own published position, linked. Where a claim is specific to one tier, the tier is named.

Assistant (tier cited)Trains on your content?RetentionData location noteWhere it's documented
Microsoft 365 Copilot (commercial)No — prompts, responses, and Microsoft Graph data "aren't used to train foundation LLMs," and feedback isn't eitherGoverned by your Microsoft tenant commitmentsRoutes within the EU Data Boundary for EU usersMicrosoft Learn
ChatGPT Business / Enterprise / APINo by default — "we do not train on any inputs or outputs from our products for business users, including ChatGPT Business, ChatGPT Enterprise, and the API"Deleted conversations removed within 30 days unless legally required to retainAES-256 at rest, TLS 1.2+ in transit; SOC 2 Type 2OpenAI Help / Enterprise privacy
ChatGPT (free / Plus consumer)Yes by default — your content "may" be used to train, with an opt-outStandard deletion; see the legal-hold note belowSame encryption, consumer termsOpenAI Help
Claude (commercial / Team / Enterprise / API)No — "Anthropic may not train models on Customer Content from Services"; you keep rights to Inputs and own OutputsGoverned by commercial termsCustomer retains rights to contentCommercial Terms
Gemini Apps (free consumer)Human reviewers read some conversations; Google warns you not to enter confidential informationConsumer retention termsConsumer appGoogle Support
Gemini (business, via Workspace)Governed by separate Workspace termsSeparate Workspace termsSeparate Workspace termsWorkspace terms (not scored here)

A few things this table is careful about. On business-tier Gemini, we deliberately don't assert a no-training guarantee, because the document that makes such a claim is a Workspace business page — and the honest position is to point you to those separate terms rather than assume the consumer warning applies to the paid product, or that the paid product's protections apply to the free one. And note the phrasing difference on OpenAI: the help-center wording above is the verbatim business-tier statement, while OpenAI's enterprise privacy page frames the same commitment as "we do not train our models on your data by default." Two pages, two sentences, same promise.

What about the consumer version I'm probably already using?

This is where the picture gets uncomfortable, because the free apps are exactly the ones people quietly paste client details into. Practitioners admit it among themselves — as one commenter on r/Accounting put it: "Should be fine, I guarantee a lot of people put clients info into ChatGPT. Just don't do it again."

Two consumer facts are worth stating plainly:

  • Consumer ChatGPT trains on your content by default. OpenAI's own documentation says that "when you use our services for individuals such as ChatGPT and Codex, we may use your content to train our models" — there is an opt-out, but it's a toggle you have to find and set. (OpenAI Help)
  • Consumer Gemini asks you not to enter anything confidential. Google's Gemini Apps notice states that "human reviewers (including trained reviewers from our service providers) review some of the data we collect" and asks you, verbatim, not to "enter confidential information that you wouldn't want a reviewer to see or Google to use to improve our services." When the vendor itself writes that sentence, the decision is made for you.

There's also a myth worth clearing up, because it circulates in professional forums: that Claude's Projects feature is "completely private, so there's no risk of exposing confidential information." That's a user's belief, not a technical fact — privacy on any of these products is governed by the tier's terms, not by a folder in the interface.

Can any of this be subpoenaed?

Yes — that's the fact none of the four brands can design away, and it's the whole reason custody matters more than any feature. Because your text lives on the vendor's servers for some period, it can be pulled into legal process aimed at the vendor. The clearest recent illustration is OpenAI's litigation with The New York Times. A court order required OpenAI to retain consumer ChatGPT and API content — including deleted chats. But by OpenAI's own account, that's over: in an update posted October 22, 2025, OpenAI said it is "no longer under a legal order to retain consumer ChatGPT and API content indefinitely," and that its "obligations under the earlier order ended on September 26, 2025" — standard 30-day deletion has resumed, though OpenAI notes it must still securely store a limited set of April–September 2025 data the Times continues to demand. Notably, the order had reached Free, Plus, Pro, and Team plans and the API without a zero-data-retention agreement — but not ChatGPT Enterprise or Edu.

Don't read that as "ChatGPT stores everything forever." It doesn't, and the order ended. Read it as the structural lesson it teaches: a lawsuit you are not a party to can, for a time, override the delete button on servers you don't own. That risk exists in principle for any of these four, on any tier. Our subpoena walkthrough traces exactly what that would look like for a professional holding privileged files.

Doesn't a paid business tier solve the compliance problem?

It solves part of it, and honestly, for many offices the business-tier-plus-signed-contract route is legitimate — if you've actually read the terms. But it doesn't remove the vendor from your accountability picture. Canada's federal privacy law is a useful anchor here because it's explicit about this. The Office of the Privacy Commissioner's summary of PIPEDA lists ten fair-information principles — among them Accountability, Consent, Safeguards, and Limiting use, disclosure, and retention. Under Accountability, your business stays responsible for personal information even when a third party processes it on your behalf (PIPEDA, Schedule 1, s.4.1.3). A no-training commitment and a data-processing agreement are how you discharge that duty responsibly — they are not a way to hand the duty off. The vendor is still in custody of the data; you are still on the hook for it. (The PIPEDA guide goes deeper on what makes an AI tool defensible under that law.)

That's the common thread across all four products, stated cleanly: the protections attach to the paid tier, but a third party is always holding your data.

Is there an option where no vendor holds your data?

Every path above — best case, business tier, contract signed, encryption on — ends with your client's text sitting, for some window, on a machine someone else owns. There is exactly one way to change that: run the model on hardware you own, so the prompt never leaves your building. When there's no vendor, there's no vendor policy to read, no training default to toggle, no retention window to trust, and nothing on a third party's server for anyone's court order to reach. It's the setup one trial lawyer on r/LawFirm was pointing at: "sharing that information with ChatGPT (OpenAI), is not a good idea. Using your own self-hosted language model would be better."

The honest trade-offs, because there are real ones. Going local costs money up front instead of monthly — a capable small machine starts around $799 for a base M4 Mac mini, with more headroom from $1,599 for the M4 Pro — and it gives you a machine to maintain and models a step behind the absolute frontier. Cloud AI on a business tier is more capable, cheaper to start, and maintained by someone else, and for work that touches nothing confidential it's often the right call. The choice isn't "cloud bad, local good." It's: for the specific pile of work that involves client data you're obligated to protect, do you want a vendor's promise about that data, or no vendor at all? If you want to see how the deployment categories stack up beyond these four brands, the private AI options comparison lays them out side by side.

Next step

Wondering if this fits your office?

The readiness assessment walks through your data sensitivity, current AI use, and what a local setup would actually involve — with an engineer, not a salesperson.

Assess your readiness →

Frequently Asked Questions

Ask about this article

Get a plain-language answer drawn from this article. Answers are AI-generated from the text on this page.

Please don’t paste confidential or client information.

500 left

External Resources

Authoritative references and tools related to this documentation type.