AI Assistants That Don't Train on Your Conversations

Which AI assistants train on your chats by default, which keep data only briefly, and where the real opt-out toggle actually lives.

Updated September 16, 2026

Every mainstream consumer AI assistant ships with a default. Some train on your conversations unless you find a hidden toggle. Some keep your data on disk long after the chat is over. A small handful don’t train at all, and a few even delete the prompt before the model finishes answering. The differences are not in marketing copy; they are in the privacy policy, the opt-out page, and the small print about retention. This guide walks through each of the major consumer AI assistants, what the policy actually says, and where to find the real switch.

TL;DR

  • Default-on for training, but with an opt-out toggle: ChatGPT (Free / Plus / Pro / Team), Claude (Free / Pro / Max), Gemini. Toggling it off only affects future conversations; past chats already in training sets stay there.
  • ChatGPT Enterprise / Edu do not train on chats at all. Gemini Temporary Chat does not train. Anthropic reserves the right to use safety-flagged or feedback-flagged content for training even after you opt out.
  • Default-off for training by contract: DuckDuckGo Duck.ai (provider agreements prohibit training), Venice AI Private mode (zero retention, contract-enforced). Mistral Le Chat’s training policy is opaque; its retention policy is published.
  • “Don’t train” is not the same as “delete fast”. Read the retention section before you trust the marketing.

ChatGPT (OpenAI): opt-out toggle, not opt-in

OpenAI documents the opt-out on a help page under “How do I opt out of my data being used to train future models?” The toggle lives at Settings → Data Controls → “Improve model for everyone.” When enabled (the default for new accounts), OpenAI may use your conversations to train future models. Toggling it off stops future conversations from being used. Conversations remain in your account until you delete them; deletion removes them from view but they stay on OpenAI servers for up to 30 days for safety and legal reasons.

Plan matters. Free, Plus, Pro, and Team train by default; Enterprise and Edu do not train on your chats at all (admins control retention instead). The API is different again: the standard API retains inputs and outputs for 30 days for abuse monitoring, then deletes them and does not train on them. A separate “Zero Data Retention” tier exists only for qualifying business customers.

Two footguns worth flagging:

  1. Past chats already used for training are not retroactively removed when you toggle off. OpenAI’s help page is explicit that the control affects future data.
  2. Even with the toggle off, OpenAI may still review flagged conversations. A federal court order in the NYT v. OpenAI copyright case required OpenAI to preserve all ChatGPT logs between April 2025 and September 2025, including deleted chats; in November 2025 the court ordered OpenAI to hand over 20 million de-identified logs to the plaintiffs. The preservation order has been lifted, but the data already handed over remains in the litigation record.

The honest read: ChatGPT is opt-out, and “opt-out” only protects future you.

Claude (Anthropic): opt-out, with two carve-outs

Anthropic’s Consumer Terms of Service for EEA / Switzerland users, effective October 8 2025, are explicit: “We may use Materials to provide, maintain, and improve the Services and to develop other products and services, including training our models, unless you opt out of training through your account settings.” The opt-out toggle lives in Claude’s in-product privacy settings.

Two carve-outs matter:

  1. Feedback flag. “If you rate an Output in response to an Input - for example, by using the thumbs up/thumbs down icon - we will store the related conversation as part of your Feedback.” That conversation is used for training regardless of your general opt-out preference. If you turn off training and then click thumbs down on one bad response, you have trained Anthropic on that chat.
  2. Safety flag. “Even if you opt out, we will use Materials for model training when… your Materials are flagged for safety review to improve our ability to detect harmful content, enforce our policies, or advance our safety research.” Content that tripped a policy filter goes into training.

Claude does not publish a fixed retention window in the consumer terms. The terms do say inactive accounts (over a year, no paid plan) may be terminated, and that material may be deleted on termination “at our option.” That is a different promise than “we delete your chats after 30 days.”

The honest read: Claude is opt-out, but the carve-outs make “opt-out” mean “opt out of voluntary training only.”

Gemini (Google): the Keep Activity toggle and the 72-hour window

Google’s Gemini Apps Privacy Hub is the most detailed of the three. Gemini ships with a “Keep Activity” setting that is on by default. When on, your saved chats are used to “provide, develop, and improve its services (including training generative AI models).” When off, future chats “won’t be used to train our AI models, unless you choose to send Google feedback.” Temporary chats are not used to train at all.

The retention story is the part most readers miss:

  • When Keep Activity is off, your conversations are “retained with your account for 72 hours” so Gemini can carry last-day context and respond. After 72 hours, the underlying data is gone from the Gemini side.
  • When Keep Activity is on, Activity auto-deletes after 18 months by default. You can shorten it to 3 months, lengthen it to 36 months, or keep it indefinitely.
  • Human review data is different. A subset of chats are reviewed by trained reviewers. The reviewed conversations are “retained for up to three years” and “disconnected from your account before being sent to service providers.” Deleting your Gemini activity does not delete the human-review copy.
  • Even with Keep Activity off, Gemini still uses chats “to respond to you and help protect Google, our users, and the public, including with help from human reviewers.”

The honest read: Gemini gives you a sharper retention number than the other two (72 hours when off) but the human-review carve-out is permanent, account-disconnected or not.

Duck.ai: local by default, providers cannot train

DuckDuckGo’s Duck.ai privacy and terms page reads differently from the three above. Chats are stored locally on your device by default, not on DuckDuckGo’s servers. If you turn on “Sync & Backup,” chats are stored encrypted in the cloud; the decryption key lives only on your devices, so DuckDuckGo cannot read them. Shared chat links store the chat encrypted on DuckDuckGo servers with the key embedded in the URL itself, and auto-delete after 30 days.

On the training question, DuckDuckGo says plainly: “Providers cannot use your data to train models.” All metadata containing personal information is stripped before prompts are sent to the underlying model providers. The provider agreements prohibit using prompts or outputs for model improvement. Named model providers include Anthropic, Azure OpenAI, OpenAI, and Together.ai. Specifically named models include Mistral AI and GPT-OSS 120B (both Apache 2.0) and Gemma 4 (Apache 2.0).

Provider-side retention: DuckDuckGo’s policy says provider-side data is deleted when no longer needed, “at most within 30 days,” with limited exceptions for safety and legal compliance.

The honest read: this is the closest thing to “don’t train on me” in a consumer AI assistant today. The catch is that you are trusting DuckDuckGo’s contract with the upstream providers, not auditing the providers themselves.

Venice: Private mode is zero retention; Pro adds E2EE

Venice’s privacy page makes tiered claims rather than a blanket one. The default mode for non-Pro users is Private, and the page is explicit: “No prompt or response is stored.” Conversations “stay on your device. Venice never stores it on its servers.” Zero data retention is described as “contract-enforced” with the GPU providers.

Pro subscribers get two additional guarantees. TEE mode runs inference inside a Trusted Execution Environment with “GPU providers cannot access your prompts. Verified by remote attestation.” E2EE mode adds end-to-end encryption such that “no one (including Venice) can see your data.”

There is also an Anonymous mode on the public tier, and it carries a warning that “Provider sees and likely saves your prompt.” Anyone who needs the no-training guarantee on Venice needs to confirm they are using Private (free default) or TEE/E2EE (Pro), not Anonymous.

The honest read: Venice’s Private mode is the strongest no-training, no-storage claim in the consumer space. Verify which mode you are actually in before relying on it.

Mistral Le Chat: opaque on training, published on retention

Mistral’s training policy on Le Chat is not as clearly documented as the others above. The company does publish retention windows on its help center:

  • Civil identity data (name from account creation): 5 years after the end of the user contract.
  • Other account data (e.g. email used for password reset): 1 year after account deletion.
  • Technical data (protocol types used to connect): 1 rolling year from each connection operation.
  • Invoices and related correspondence: 10 years from the close of the relevant financial year.

For La Plateforme (Studio and the API), Mistral retains inputs and outputs for 30 rolling days after the request, primarily for abuse detection. For Le Chat itself, Mistral has not published a fixed retention window; conversations remain in your sidebar until you delete them. The training question for free-tier Le Chat is best answered by asking Mistral directly or by treating free-tier Le Chat the way you would treat ChatGPT Free: assume the default is permissive.

What “don’t train on your data” actually means

Marketing claims and policy text use the same words to mean different things. Five distinctions that matter:

  1. No training vs. no retention. Venice Private says no retention; Duck.ai says no training but provider-side data lives up to 30 days. Both are defensible privacy postures; they are different promises.
  2. Default-off vs. default-on with opt-out. Duck.ai and Venice Private are default-off. ChatGPT, Claude, and Gemini are default-on with opt-out. The difference is the friction to stay private.
  3. Future conversations vs. past conversations. Every opt-out toggle only protects future data. Past chats may already be in training sets; toggling it off does not extract them.
  4. Training opt-out vs. human-review opt-out. Gemini Keep Activity off still allows human review of flagged chats. Claude’s safety-flag carve-out allows the same. Disabling training does not always disable review.
  5. Carrier data vs. provider data. Duck.ai strips personal metadata before sending prompts to upstream providers. Even if a provider later trains on something, your DuckDuckGo identity is not attached to it.

The honest questions to ask of any AI assistant:

  • Is training on by default? Where is the toggle?
  • What is the retention window in days or months?
  • Are human reviewers involved? Can I opt out of that?
  • Does the toggle cover past data, or only future?
  • Is there a separate “temporary” or “incognito” mode that skips all of the above?

The Bottom Line

If you want a consumer AI assistant that does not train on your conversations today, the safest options are Duck.ai (provider contracts prohibit training, chats saved locally by default) and Venice AI in Private mode (zero retention, contract-enforced). The rest - ChatGPT Free / Plus / Pro / Team, Claude, Gemini - ship with training on by default and rely on an in-product toggle to turn it off. None of those toggles reach back into past conversations, and all three reserve carve-outs for human review or safety-flagged content. Read the toggle. Read the retention number. Read the carve-outs. Then decide whether “opt-out” matches the privacy you actually wanted.