On July 8, 2026, a new Anthropic Privacy Policy took effect for everyone using Claude on a Free, Pro, or Max plan. It added a data category few people expect a chatbot to need: an image of your government ID, a photo or video of your face, and “facial geometry templates.” If you kept using Claude after that date, those are the rules your data now lives under.
Keeping up isn’t easy. Claude’s rules are spread across the Consumer Terms of Service (effective October 8, 2025), the Privacy Policy, the Usage Policy, and a stack of help-center articles that hold the actual numbers, like how many years a chat can be kept. This guide pulls from all of them as they stood on September 10, 2026.
Below are ten clauses, what each one means in plain English, and what to do about it. Each made the list for two reasons: it should change how a regular user behaves, and it’s traceable to Anthropic’s own documents. A note on scope: this covers personal accounts. Claude Team, Enterprise, and API customers sign Anthropic’s Commercial Terms, and several of these rules work differently there. This is a plain-language guide, not legal advice.
1. Claude Uses Your Chats for Training Unless You Opt Out
In August 2025, Anthropic changed the rules for Free, Pro, and Max accounts. The Consumer Terms now say Anthropic may use your chats to train its models “unless you opt out of training through your account settings.” That includes coding sessions in Claude Code on those accounts.
The retention window grew too. If you allow training, Anthropic’s privacy center says your data can stay in its training pipelines, in de-identified form, for up to five years. Before the change, deleted chats were cleared from Anthropic’s back end within 30 days, according to TechCrunch.
The way people were asked matters. As The Verge first observed, the pop-up that introduced the change paired a large black Accept button with a much smaller training toggle that was already switched on. If you clicked Accept fast in fall 2025, you may have opted in without noticing.
What to do: Open Settings, go to Privacy, and find the Model Improvement toggle (the direct link is claude.ai/settings/data-privacy-controls). Anthropic says that once it’s off, new chats won’t be used for future training. The announcement doesn’t promise to pull back anything already used.
ChatGPT runs on the same opt-out model. OpenAI’s Terms of Use let it train on your content unless you turn off its “Improve the model for everyone” setting.
2. Rating a Claude Reply Stores the Entire Conversation for Five Years
Turning off Model Improvement doesn’t close every door. The Consumer Terms name two exceptions where Anthropic will still train on your chats: when you give feedback, and when a conversation is “flagged for safety review.”
Feedback is the one people trip over. Tap the thumbs-up or thumbs-down icon on a single reply, and Anthropic stores the entire related conversation, including any content, custom styles, and conversation preferences, per its privacy center. Feedback data is kept for five years. Anthropic says it separates that conversation from your user ID before using it for training. The terms also say it may use your feedback “however we choose without any obligation or other payment to you.”
So a one-second rating on a chat where you pasted a client contract, a medical bill, or an unpublished course outline can put all of it into a five-year training pool. Your privacy toggle doesn’t change that.
What to do: Don’t rate chats that contain private material. If a reply was bad and you want to report it, recreate the problem in a clean chat and rate that one.
3. Safety-Flagged Claude Chats: Two Years for Content, Seven for Scores
Deleting a normal chat works quickly. Anthropic says a deleted conversation leaves your history immediately and its back-end systems within 30 days.
A safety flag changes that. If Anthropic’s automated trust and safety systems flag a chat as violating the Usage Policy, Anthropic keeps the inputs and outputs for up to two years and the trust and safety classification scores for up to seven years, according to its retention page. Flagged chats can also be used for training no matter how your settings are set. The same page says Anthropic may keep chats longer “as required by law, to resolve disputes, or as necessary to combat violations of our Usage Policy.”
The Usage Policy says Anthropic’s Safeguards Team runs “detection and monitoring” to enforce the rules. Anthropic doesn’t publish a list of what trips a flag.
Google has its own version of this carve-out. Its Gemini Apps Privacy Hub says human reviewers read a subset of chats, and those reviewed chats are kept for up to three years and aren’t deleted when you delete your activity.
What to do: Use delete for everyday cleanup, and know its limit. Once a chat is flagged, deleting it won’t erase what Anthropic keeps.
4. Anthropic May Ask for Your Government ID and a Selfie
The July 8, 2026 Privacy Policy added a category called Verification Data. If Anthropic asks you to verify your age or identity and you do, it may collect an image of your government ID and the details on it (including your ID number and date of birth), a photo or video of you, and facial geometry templates, which the policy says “may be considered ‘biometric data’ in some jurisdictions.”
Anthropic’s help center says the request can appear “when accessing certain capabilities, as part of our routine platform integrity checks, or other safety and compliance measures.” Checks run through Persona Identities, an identity verification company. Anthropic says Persona, not Anthropic, holds your ID and selfie, and that identity data isn’t used to train its models.
Two questions are still open. Anthropic hasn’t published which “certain capabilities” trigger a check. And as The Register reported in April 2026, Anthropic hasn’t said how long that verification data is retained. The Privacy Policy describes verification as something you choose to do. The help center doesn’t spell out what happens to your access if you decline.
What to do: If you get a prompt, you’ll need a physical government photo ID and a camera for a live selfie. If handing over biometric data is a dealbreaker, contact Anthropic support first and ask what your options are.
5. When Anthropic Can Share Your Claude Data With Law Enforcement
The previous Privacy Policy, effective January 12, 2026, said Anthropic may disclose personal data to “governmental regulatory authorities as required by law,” in response to their requests, or to assist in investigations. It also allowed disclosure to protect “the health and safety of you or any other person.”
The July 8 version is broader and more direct. Anthropic may now share personal data with “government authorities, law enforcement, or other third parties” when it has “a good-faith belief” that disclosure is reasonably necessary. The listed reasons are complying with the law or an enforceable government request, preventing serious harm to a person or property, addressing fraud or other illegal activity, and enforcing Anthropic’s terms or protecting the rights, property, or safety of Anthropic, its users, or others.
Our read: the phrase doing the work is “good-faith belief,” because Anthropic makes that call. Enforcing its own terms also sits on the list next to legal process. Separately, the Usage Policy commits Anthropic to reporting child sexual abuse material to authorities.
What to do: Everyday use isn’t the concern here. The practical rule is simple: if you’d only say it to your lawyer, say it to your lawyer instead of a chatbot.
6. You’re Responsible for What Claude in Chrome and Connected Apps Do
Claude can now click through websites in Claude in Chrome, pull from connected apps, and run multi-step tasks. The Consumer Terms call these “Actions,” and the rule is blunt: “You are responsible for all Inputs you submit to our Services and all Actions.” The same section warns that Actions “may not be error free or operate as you intended.”
Anthropic’s safety guide for Claude in Chrome adds detail. The extension takes screenshots of your active tab, so whatever is visible “becomes part of the conversation.” Hidden instructions on a website or in an email could trick Claude into actions you didn’t intend, a problem known as prompt injection, and Anthropic says “the risk is not zero.” It advises against using the extension for financial accounts, legal documents, medical information, or sensitive work accounts. And it says: “You remain responsible for all browser actions taken by Claude performed on your behalf.”
Connected apps add another layer. The Privacy Policy says Claude may send your inputs, outputs, and instructions to third-party services, and each service processes that data “according to its own privacy policy.” The Consumer Terms say Anthropic doesn’t accept responsibility for losses from third-party integrations.
One detail cuts the other way. Anthropic says raw content from connectors such as Google Drive isn’t used for model training, though anything copied directly into the conversation can be. Claude in Chrome data, on the other hand, falls under your Model Improvement setting.
What to do: Keep Claude in Chrome away from your bank, payroll, and client inboxes. Review the apps connected to your Claude account and disconnect the ones you don’t use.
7. The $100-or-Six-Months Liability Cap and Claude’s Indemnity Clause
If something goes wrong, the Consumer Terms cap Anthropic’s total liability to you at the greater of what you paid in the six months before the problem started, or $100. For a free user, the ceiling is $100.
The terms set no similar limit on what you might owe in the other direction. They require you to indemnify Anthropic, which means covering its losses and “reasonable attorneys’ fees,” for claims tied to your “breach or alleged breach” of the terms, your “use of, or alleged use of” Claude, and products you build with it.
This is where the ChatGPT comparison helps. OpenAI’s Terms of Use, effective January 1, 2026, set their liability cap using a 12-month window, and their indemnity clause applies only “If you are a business or organization.” Claude’s Consumer Terms don’t carve out individuals.
Two caveats. Claude’s terms acknowledge that some jurisdictions don’t allow these limits, so “some or all” of them “may not apply to you.” And disputes go to state or federal courts in San Francisco under California law, with a line saying “you waive any claims that may arise under the laws of other jurisdictions.”
What to do: Don’t treat Claude as the final check on anything expensive. If your business depends on Claude, have a lawyer compare the Consumer Terms with Anthropic’s Commercial Terms for Team and Enterprise plans.
8. Anthropic Can Close Your Claude Account Without Notice
The Consumer Terms let Anthropic suspend or terminate your access “at any time without notice” if it believes you broke the terms or if the law requires it. After that, Anthropic “may at our option delete” your chats and other account data.
Payments are “non-refundable,” except where the terms or local law say otherwise. Residents of Brazil, Mexico, South Korea, and Taiwan can cancel a new subscription within seven days for a full refund. Free accounts inactive for more than a year can be closed as well, though Anthropic says it will send notice first.
Months of project files, research threads, and prompts you’ve tuned all sit inside an account that can be closed on Anthropic’s judgment.
What to do: Export your data on a schedule. In the web or desktop app, go to Settings, then Privacy, then Export data. Anthropic emails a download link that expires after 24 hours, per its help center. Exports can’t be started from the iOS or Android apps.
9. Claude’s Terms Change Often, and Continued Use Counts as Consent
Anthropic may revise the Consumer Terms “at our discretion.” If you keep using Claude after new terms are posted or you’re notified, you’ve agreed to them. If you don’t accept, the terms say you must stop using the service.
Anthropic uses that power regularly. Its Privacy Policy has taken effect in four new versions in under a year: September 28, 2025; October 8, 2025; January 12, 2026; and July 8, 2026. The terms also say Anthropic may add or remove features, “increase or decrease capacity limits,” and change or suspend the service “at any time without notice to you.”
Subscription prices get a bit more protection. Anthropic can’t change your fee during a current billing term, and it has to give at least 30 days’ notice before an increase.
What to do: Bookmark Anthropic’s “Updates to our Privacy Policy” page in its privacy center. It lists each change by date, which is far faster than rereading the full policy.
10. Who Owns Claude’s Output: Two Words Creators Should Read
The Consumer Terms assign you Anthropic’s rights in Claude’s outputs, “if any.” Those two words matter more than they look.
In the United States, copyright requires a human author. The U.S. Copyright Office’s January 2025 report on copyrightability said prompts alone aren’t enough to make AI output protectable. A federal appeals court upheld the human-authorship requirement in Thaler v. Perlmutter in March 2025, and the Supreme Court declined to hear the case on March 2, 2026. Anthropic can hand you every right it has, and for text Claude generated on its own, that may amount to nothing.
For anyone selling ebooks, courses, templates, or newsletters, the real risk is copying. Text Claude wrote without meaningful human input may be hard to defend if someone lifts it.
Two more output rules are worth a look. The terms warn that outputs “may contain material inaccuracies even if they appear accurate because of their level of detail or specificity.” They also bar using Claude to build competing products, “including to develop or train any artificial intelligence or machine learning algorithms or models,” and they say you can’t rely on Claude to buy or sell securities.
What to do: Put your own work into anything you plan to sell: your structure, your examples, your edits. Keep the drafts that show your contribution.
Three Parts of Claude’s Fine Print That Favor Users
The fine print isn’t all bad news. Three details are worth knowing before you decide how worried to be.
The Consumer Terms have no arbitration clause. Disputes go to court in San Francisco, while OpenAI’s terms require binding arbitration and bar class actions unless you opt out within 30 days.
Anthropic says incognito chats aren’t used to train Claude, even when Model Improvement is on. They don’t appear in your history or memory, and Anthropic retains them for 30 days by default.
On February 4, 2026, Anthropic committed to keeping Claude ad-free, with no sponsored links and no advertiser influence on responses. The Privacy Policy says Anthropic doesn’t “sell” personal data, though you can opt out of data sharing for ads that promote Anthropic’s own products.
Your Five-Minute Claude Privacy Checklist
Turn off Model Improvement at claude.ai/settings/data-privacy-controls if you don’t want your chats used for training.
Start an incognito chat (the ghost icon at the top of a new chat) for anything sensitive.
Skip the thumbs-up and thumbs-down on chats with private information.
Export your data from Settings, then Privacy, then Export data.
Disconnect apps you don’t use, and keep Claude in Chrome off financial, medical, and legal sites.
If someone on your team pastes client work into Claude, send them this before their next chat. And if you want plain-English breakdowns like this whenever an AI company rewrites its rules, subscribe to Academy of AI.






