The personal matters you told the AI were used for training
You have asked AI about what you feel uncomfortable, quarreled with your partner, whether you still want to do the job, how to manage your children. You have asked AI all these things that you are embarrassed to ask. Where are those words now? I read the original agreement of the seven mainstream AI assistants one by one: It is the norm to use your input for training by default, but Tencent Yuanbao is an exception. Its agreement states in black and white,"Unless you start an experience optimization plan, we will not Use the foregoing content for model optimization." I can turn off the other few stores. I have listed all the switching paths. Only the text part of Qianwen needs to contact customer service. There are two other places that you can't control even if you turn off the switch. You press one almost every day.
You must have asked AI something that is embarrassing to ask people.
If you feel uncomfortable, send in the symptoms and let it check first, which is faster than registering. After arguing with your partner, post your chat history in and ask who the problem is. Should we talk about salary, and whether we should continue to do the job. The child's report card is back, what should I tell him? The old man at home found something wrong, and you asked it again half-heartedly.
Add the contract that has not yet been signed, the resume with the mobile phone number, and the code that the company has not yet released.
Where are these words now?
I opened the user agreements and privacy policies of the seven mainstream AI assistants and read them one by one, and copied everything I could quote from the original text. The conclusion is that it is normal to use your input to train the model by default. But one family is not.
first said that one is different
The first sentence of Article 5.4 of Tencent Yuanbao's User Service Agreement reads as follows:
"Regarding the content you upload to this service platform and the content you generate using this service, we will not use the aforementioned content for model optimization unless you activate the Experience Optimization Plan." 」
The weight of this sentence lies in the three words: unless you.
The logic of other families is "We know how to use it, you can turn it off", while Yuan Bao's logic is "We don't use it unless you turn it on." The default state is reversed.
It also states at the end of the terms that if you actively join the experience optimization plan, you can call it back at any time through the "Settings-Data Management-Experience Optimization Plan". After closing, your subsequent content will not be used for model optimization.
The update date of this agreement is December 6, 2025, and will take effect on December 13. It is the current version.
After a full round of investigation, only one in the seven families agreed to it.
There are six ## companies left, the difference is how difficult it is to lock them up
DeepSeek writes the switch position directly into the policy. Its privacy policy (February 10, 2026 version) recognizes the following purposes:
"On the premise of processing and de-identifying through secure encryption technology, we may use the inputs and corresponding outputs collected by the service for DeepSeek model training and service optimization."
Immediately after, the exit method is given: turn off "Data for Optimizing Experience", and the path is avatar area, settings, and data management.
Bean buns also have switches, called "Help models improve effects" in Settings, Privacy and Permissions. Its policies were just updated on July 15. Note that voice is another switch, two score switches.
The terms of Zhipu Qingyan are a bit convoluted, but there are switches. It first said that the data is no longer personal information after being anonymized, and it is not necessary to obtain your additional consent to use it according to the law; then it added:
"If you do not want your data to be used for the above purposes, you can turn off this setting by: (1) APP: Click the third tab-Settings-Data Management-Data Use switch at the bottom (2) PC: Personal avatar in the upper right corner-Data Management-Data Use switch."
According to it, it could have been refused to give it, but it was given anyway. This policy was just updated on August 5 and is the latest one among these seven families.
ChatGPT default training. The words of the help center are very straightforward:
"ChatGPT, for instance, improves by further training on the conversations people have with it, unless you opt out. "
The place to close is Data Controls in the settings, or go to the privacy portal to click "do not train on my content".
Claude lets you choose it yourself, and switch it to Model Improvement in Privacy Settings.
There is only Qianwen in the seven families, and there is no switch in the text section. Its privacy policy (updated July 14) says this:
"We may randomly select a small number of input content and conversation contexts for product analysis, model evaluation and functional optimization... If you do not want your input content to be used for model optimization, please refer to Article 9 of this policy and contact us. 」
Article 9 is contact information. In other words, if you want to quit, you have to contact customer service.
However, there are two points that need to be made clear for it. First, the phrase "randomly select a small part" is the most restrained by the seven families. Other families all write a full expression of "input and corresponding output." Second, its voice and knowledge base are very clear: there is a "Improve Audio and Video Call Service" switch for voice that can be turned off at any time, and the knowledge base one is more direct,"We will not use your knowledge base content without your separate authorization and consent." Use content for algorithm analysis or model training."
There are two places in QKPFX7 and QK. Even if the switch is turned off, it can't control it.
This part is what I want you to know most after reading this time, because they are all in the detailed rules and I didn't know before.
The first one is the praise you click on.
Original OpenAI:
"Even if you have opted out of training, you can still choose to provide feedback... If you choose to provide feedback, the entire conversation associated with that feedback may be used to train our models. "
Even if you have turned off training, as long as you like or click on a reply,the entire conversation associated with this feedback may still be used to train the model. It's the whole paragraph, not the one you liked.
This is not what OpenAI wrote alone. Article 1.10 of the bean bag policy divides this matter into two sections a and b: section a is the feedback that you like, click on, and report, and section b is the content data you enter "when you have not provided the feedback described in section a." The "Help model improve the effect" switch is hung under the b model.
The two houses have the same structure: feedback is the other path.
So that convenient action is equivalent to opening a separate back door for this conversation.
Second, you may be lonely.
Still the original version of OpenAI:
"Codex has separate controls for allowing training on full environments... Note that adjusting your settings in the ChatGPT interface or privacy portal will not affect these full-environment Codex settings. "
Codex's complete environment has an independent set of training controls. You can't control what you turn off in the ChatGPT interface or the privacy portal. People writing code should pay special attention.
By the way, OpenAI's instructions also wrote an easily overlooked sentence: Yourcustomer service conversations may also be used to improve the model.
spend money may not buy out
Many people have an intuition: take my data for free, I should be safe if I pay.
This instinct is half right and half wrong.
The half right is thatenterprise versions and APIs do generally default to no training. OpenAI makes it clear that ChatGPT Business, Enterprise and API platforms do not use your input and output training models by default unless the organization actively chooses to join. Like Anthropic, commercial products are not used for training by default.
The half wrong is thatpersonal subscriptions are not commercial terms.
In the August 2025 Consumer Terms update, Anthropic put Free, Pro, and Max together and fell under the Consumer Terms. Pro and Max have paid for it, but the classification is still consumer-grade and not in the "commercial terms no training" category.
There was also a set of numbers worth looking at in that update: those who agreed to use the data to improve the model had a five-year retention period; those who disagreed had 30 days.
After ## is closed, what should I do with the previous ones?
This is the most helpless one.
Article 6.1 of the bean bag policy is clearly written:
"After withdrawing the authorization, we will no longer collect information related to these permissions, but it will not affect our previous processing of personal information based on your authorization. 」
OpenAI's statement is that after it is turned off, the "new conversation" is no longer used for training. Anthropic's argument is that training that has already begun and models that have already been trained are not affected.
So the time direction of this matter is one-way. You turn off the switch today, you care about tomorrow. Those that stuck in yesterday will not be recovered.
So what should we do?
First, find the switch and turn it off. It takes ten minutes. The paths of the six families are all in the picture above. Just follow them. If you use Qianwen, you can only go through customer service for the time being.
Second, control your hands and don't like them. This is more important than turning off the switch because it bypasses the switch. I really want to give feedback, but I know that this conversation will be sent out completely.
Third, important things should be held in ad hoc dialogue. ChatGPT's Temporary Chat clearly does not enter history, build memories, or be used for training, and so does Claude's Incognito model. The lowest cost isolation method.
Fourth, don't stick to the truly sensitive ones. Unsigned contracts, ID cards, medical records, company codes not disclosed. The risk is not which one takes it for training, but that once it goes in, it will not get out. This has nothing to do with whether you trust a certain family or not. It is a matter of irreversibility itself.
Fifth, the company's business is based on API or Enterprise Edition. By default, there is no training clause, only the commercial terms will be given.
few sentences boundary
The content in each quotation mark above comes from the user agreement or privacy policy currently in effect on each official website. I opened it and read it one by one, and the version date is also marked in the picture.
But these policies are changed frequently. Among these seven copies, Doubao was updated on July 15, Thousand Questions was updated on July 14, and Zhipu Qingyan was updated on August 5. The OpenAI page was just changed the day before I verified it. What I wrote down is the status of August 19, 2026. The switch name and path may change.
If you really want to confirm, refer to the current settings page of the App on your mobile phone. This is the only advice this article can give you that won't expire: go and have a look in the settings for yourself.