Answer
How do you find out whether an AI vendor trains on your data?
Read the terms that apply to your plan, not the marketing page. The answer usually differs by tier and by feature.
Find the terms that govern your specific plan and read three things separately: retention, human review, and use for model improvement. They have different answers, and the marketing page usually addresses only the third.
The question people ask is whether the vendor trains on their data, and it is the least useful of the three questions bundled inside it. Training is the one vendors most readily disclaim because it is the cheapest to give up. Retention — how long inputs and outputs are stored and where — is a different commitment with different consequences, and it is what determines whether your material appears in a discovery request against the vendor or in a breach they suffer. Human review — whether staff or contractors can read your inputs, for abuse monitoring, quality or support — is a third, and it is the one most often left unmentioned.
The tier is the variable that decides the answer more than the vendor is. Nearly every provider offers different terms on consumer, business and enterprise plans, and the difference is usually exactly this: consumer tiers may use inputs for improvement by default, business tiers do not, and the enterprise tier adds contractual commitments about retention and jurisdiction. A business whose staff signed up individually is on the consumer terms whatever the business believes about the vendor, and this is the single most common gap between a policy and what is happening.
The document to read is the one that governs, and it is rarely the page that comes up first. In descending order of authority: the signed agreement or order form, the data processing terms it incorporates by reference, the product-specific terms for the feature in question, and only then the published policy pages. Marketing claims about privacy sit below all of these and bind nobody. A vendor that will not tell you which document governs has answered the question.
Features change the answer within a single plan, which is why a blanket answer about a vendor is usually wrong. Connectors that read a mailbox or a document store, an agent that can browse, a beta feature, a model from a third party offered inside the product, and anything labelled research preview commonly carry different terms from the core product. The specific question to ask is whether the commitment applies to every feature or to the base product, and the answer is frequently the second.
Subprocessors are the part that decides how many organisations the answer actually concerns. A vendor's commitment not to train binds the vendor; the list of subprocessors tells you who else receives the data and under what onward terms. That list is usually published because enterprise customers require it, and reading it is the fastest way to discover that a tool you assessed as one company's product routes through three.
Finally, verify rather than believe, because verification is cheap here and belief is not. The settings your account is actually running under are visible in the admin console, the retention period is usually stated per workspace, and whether staff are signed into a business account is answerable in an afternoon. A vendor's terms describe what is permitted; the console describes what you configured, and the gap between them is where the exposure sits.
Not training on your data, retaining your data, and having staff who can read your data are three separate commitments, and a vendor can honestly make the first while doing the other two.
Siddharth Sharma, Context Theory
Related questions
Is an enterprise plan always the safer answer?
It is usually the plan the commitments attach to, which is not the same thing. What makes it safer is the contract, the admin controls and the audit surface it brings, and a business that buys the plan without configuring retention or restricting connectors has paid for controls it did not switch on. The plan is a precondition for the answer, not the answer.
What if we cannot get a clear answer from the vendor?
Treat that as the answer for anything sensitive and use the tool for everything else. There is a large class of work — drafting with no client particulars, thinking, summarising public material — where the question does not matter, and confining an unclear vendor to that class is a real decision rather than a stalemate. A vendor that cannot say what happens to inputs is telling you something about how well they know.
METHOD
Every figure below carries its source and the date it was verified. Nothing on this page is asserted.
The numbers on this page.
| What | Value | Specific to |
|---|---|---|
| Realistic monthly lead-gen software spend | $1,500–$5,000 | Category-wide |
| US SMB retainer, focused one-to-two-service engagement | $1,500–$4,000 | Category-wide |
2026 real estate operating cost survey · plus $1,000–$8,000 variable · verified
2026 agency pricing survey · per month · verified
What is specific to this page.
| Kind | Claim | Check it against |
|---|---|---|
| Procurement | Whether inputs are used for model improvement, how long they are retained, and whether vendor staff can read them are three separate commitments with different consequences, and a vendor can accurately disclaim the first while doing both of the others. | The retention, human review and improvement clauses of the vendor's data processing terms, read as three separate questions. |
| Software | Terms commonly differ between consumer, business and enterprise tiers of the same product, so an organisation whose staff registered individually is governed by consumer terms regardless of what the organisation believes about the vendor. | Checking which plan each staff account is actually signed into, against the tier the organisation's assessment assumed. |
| Constraint | Within a single plan, connectors, browsing agents, third-party models offered inside the product and anything labelled preview frequently carry different terms from the base product, so a vendor-level answer is usually wrong at feature level. | The product-specific or supplemental terms for each feature the business has enabled. |
| Workflow | The subprocessor list determines how many organisations the commitment actually concerns, and reading it commonly reveals that a tool assessed as one company's product routes data through several. | The vendor's published subprocessor list, compared against the parties named in the signed agreement. |
Each row would be wrong on another industry's page. Where a sourced figure exists it is in the table above instead; these are the constraints that shape the work and do not happen to be numbers.
Start with the measurement.
Reading about a benchmark is not the same as knowing your own number. The audit produces yours, measured rather than estimated.
$497 · delivered in 5 business days · credited against month one