Mastering Claude (Anthropic)Safety, privacy and team adoption · Lesson 19 of 20

Privacy and data controls

Article · 15 min · 9 min lecture

Video lecture

Privacy and data controls

14 chapters · about 9 min · full transcript

Coming soon

Chapter 1 of 14

Privacy and data controls

  • Know the rules
  • Set your controls
  • Share less, safely

The narrated lecture is in production

Every chapter is scripted and ready. Browse the chapters and read the full transcript now — the video will appear here when it’s published.

Chapters

How your data is handled depends on the account type

Anthropic treats consumer accounts (Free, Pro, Max) differently from commercial offerings (Team, Enterprise, the API, and Claude through cloud platforms). The broad pattern, which you must confirm against Anthropic's current privacy policy, terms and your organisation's agreement:

  • Consumer plans: you choose in privacy settings whether your chats and coding sessions may be used to improve Anthropic's models. Anthropic's policy describes different retention periods depending on that choice, and deleted conversations are not used for future training. Incognito chats are not saved to your history or memory.
  • Commercial plans and the API: covered by commercial terms, under which customer content is not used to train models by default. Organisations can agree additional controls (for example, custom retention on Enterprise, or zero-data-retention arrangements for eligible API use).

Policies change; read the current versions before telling a client how their data is handled.

Your personal data-control check-up (10 minutes)

  1. Model-training preference (consumer plans): decide deliberately.
  2. Chat history: delete conversations you no longer need; export your data if you want a copy.
  3. Memory: review categorised entries, edit topics, set the sensitive-topics preference, or turn memory off.
  4. Incognito: know how to start it for sensitive one-off questions.
  5. Connectors and skills: disconnect anything unused; review permissions.
  6. Shared links and published artifacts: revoke any you no longer want accessible.
  7. Profile preferences: remove anything confidential.

Classify before you share

Use a simple four-tier classification:

ClassExamplesRule
PublicPublished posts, press releasesAny approved tool
InternalPlans, drafts, non-sensitive metricsApproved work account
ConfidentialClient contracts, unreleased campaigns, pricingApproved commercial workspace only; minimise
RestrictedPasswords, API keys, payment card data, government IDs, health data, special-category personal dataNever in general AI chats

Minimise, anonymise, excerpt

  • Minimise: share the clause, not the whole contract; the columns you need, not the full CRM export.
  • Anonymise: replace names and emails with IDs ("Customer 014"); remove identifiers from survey data.
  • Aggregate: "42 complaints about delivery in March" rather than 42 named complaints.
  • Excerpt: paste the relevant section with context instead of uploading every attachment.

Law and contracts

Data protection laws apply to personal data you process with AI: for example UK GDPR and the Data Protection Act 2018, the EU GDPR, the UAE's Federal Decree-Law No. 45 of 2021 on personal data protection (and DIFC/ADGM rules in those free zones), Saudi Arabia's Personal Data Protection Law, and Pakistan's evolving framework. Client contracts often add stricter rules, including bans on third-party AI processing. Involve your data protection lead and read the contract before using client data in any AI tool.

For API builders

  • Send only the data each call needs; strip identifiers where you can.
  • Keep keys server-side; log without personal data where possible.
  • Check data residency and retention options that apply to your use (for example, where inference runs), and document them in your records of processing.

Worked example: survey analysis done right

A marketing assistant at a Dubai retailer needs themes from 2,000 open-text survey responses. She exports only the response text and a customer segment column, removes names, emails and order IDs, and uses the company's Claude Team workspace (not her personal account). She asks for themes with example quotes (which contain no identifiers), documents the method for her manager, and deletes the working file from her downloads afterwards.

Questions to ask before approving any AI tool

  • Is customer content used to train models, and can that be switched off contractually?
  • How long is data retained, and can we set or shorten retention?
  • Where is data processed and stored?
  • Which sub-processors are involved?
  • What admin controls, audit logs and SSO options exist?
  • Is there a data processing agreement we can sign?

Record the answers in a simple register so you can answer client questionnaires quickly.

Hands-on

Complete the 10-minute check-up above, then write a one-paragraph personal data policy for your own AI use using the four classes. Share it with your manager or data protection lead.

Pitfalls

  • Using a personal account for client work "just this once".
  • Uploading full CRM exports when three columns would do.
  • Assuming incognito satisfies contractual or legal obligations.
  • Quoting old privacy terms to clients.

How to measure success

You can state, for each AI tool you use, which data classes are allowed; no restricted data has entered an AI chat; and your settings are reviewed at least quarterly.

Key takeaways

  • Consumer plans (Free, Pro, Max) let you choose whether chats train models; commercial plans and the API do not train on customer content by default. Always confirm current terms.
  • Run a quarterly check-up: training preference, history, memory, incognito, connectors, shared links and profile.
  • Classify data as public, internal, confidential or restricted; never put restricted data in general AI chats.
  • Minimise, anonymise, aggregate and excerpt; check data protection law and client contracts before using client data.

Check your understanding

Quick questions to lock in the lesson. They don’t count towards your certificate.

  1. Which item should never be pasted into a general AI chat?
  2. A consultant needs AI help with client contracts. What is the best practice?
  3. Where can you reliably confirm how your Claude data is retained and used?

Put it into practice

Open your Claude settings and review each data control listed in this lesson. Write a one-paragraph personal data policy for your own AI use.

Enrol for free to save your progress

Reading is always free. Enrol to keep your place, take the final assessment and earn a verifiable certificate.