AI companies vary significantly in how their agreements handle user data. ConductAtlas reviewed the documents to compare what each platform actually authorizes.
ConductAtlas monitors the privacy policies and terms of service of 38 AI platforms daily. We track every clause, every change, every obligation. Below is what the documents say, organized around four questions: Does this company train on your data? How long do they keep it? Can you take them to court? And what happens if something goes wrong?
Data current as of April 29, 2026. ConductAtlas monitors these policies daily. If anything changes tomorrow, we will detect it within 24 hours.
The summary
| Platform | Trains on your data? | How long they keep it | Forced arbitration? | Liability cap |
|---|---|---|---|---|
| ChatGPT (OpenAI) | Yes, by default | 30 days post-deletion | Yes + class action waiver | $100 or fees paid (whichever is greater) |
| Gemini (Google) | Yes | 18 months to 3 years | No | Capped at fees paid; disclaims AI errors |
| Character.AI | Yes, all conversations | Content survives deletion | Yes + class action waiver | $100 total, ever |
| Copilot (Microsoft) | Yes | Standard Microsoft policy | Yes + class action waiver | Capped at fees paid; disclaims AI errors |
| Midjourney | Perpetual license to everything | Minimal disclosure | Yes + jury waiver | $100 or fees paid; 1-year claim deadline |
| Claude (Anthropic) | Free tier only | 30-day backend purge | No | Fees paid in prior 12 months |
| Stability AI | Yes | Not specified | No | Fees paid in prior 12 months |
| Hugging Face | Yes | Not specified | No | Greater of $100 or fees paid |
| Cohere | Enterprise opt-out available | 30 days (SaaS) | No | Fees paid in prior 12 months |
| Mistral AI | Paid: no. Free: opt-out | Varies by data type | No | Fees paid in prior 12 months |
| DeepL, Cursor, Replit, Groq, and 20+ others | No (under standard terms) | Varies | No | Varies; see individual terms |
Red rows highlight platforms with the broadest terms across all four categories. See the full cross-platform comparison.
Three clauses worth reading yourself
Out of 845 provisions across 38 platforms, three stand out.
Character.AI caps its total liability at $100. That is the total ceiling under the agreement, not per incident. The cap applies regardless of the nature or severity of the claim. Character.AI is widely used by younger audiences, which makes this limitation notable. Read the actual clause.
Google Gemini keeps your conversations for up to 3 years. The default retention period is 18 months. Some data stays for 3 years. Deleting a conversation from your Gemini history does not remove it from Google's systems right away. Under the stated retention terms, conversation data from early 2026 could remain in Google's systems into 2029. Read the actual clause.
OpenAI trains on your conversations unless you find the setting. The default is on. To turn it off: open ChatGPT, tap your profile icon, go to Settings, tap Data Controls, toggle off "Improve the model for everyone." Most people never find this. Everything typed before you toggle it off has already been used. Read the actual clause.
Which AI companies train on your conversations?
At least 8 of the 38 platforms we track grant themselves the right to train on what you type.
ChatGPT. The default settings authorize the use of conversations for future model training. This setting is not prominently surfaced during signup. OpenAI also reserves the right to have employees review conversations for safety and quality purposes. See the provision.
Gemini. Same basic approach, but Google holds onto it longer. Your conversations train their AI and human reviewers can access them. The 18-month default retention is the longest of any major AI platform we track.
Claude. Anthropic's terms differentiate between tiers. If you pay for the API, your data stays out of training entirely. Free tier data may be used. One detail worth noting: providing feedback (thumbs up or thumbs down) on a response may flag that conversation for retention. The feedback is linked to the conversation content. See the provision.
Character.AI. The agreement asserts that all content trains the model under a perpetual and irrevocable license. No opt-out mechanism is documented in the current terms. The enforceability of perpetual content licenses may vary by jurisdiction, particularly under GDPR's right to erasure. See the provision.
Midjourney. The agreement asserts a perpetual, royalty-free license to every prompt and generated image for any purpose. As with similar content licenses, enforceability may depend on jurisdiction and applicable intellectual property law. See the provision.
Most enterprise-focused platforms do not train on your data under standard terms. Cohere, Mistral AI, DeepL, Cursor, Replit, Databricks, and Groq either default to no training or restrict controls to enterprise contracts.
How long do AI companies keep your data?
Google Gemini is the outlier. 18 months is the default. Some categories go to 3 years. A question you asked Gemini about a health concern in January 2026 could still be on Google's servers in July 2028. See the provision.
OpenAI and Anthropic both commit to 30-day deletion windows. But OpenAI has a catch: data already built into a trained model stays in the model. Your words shaped how the AI responds. Deleting your account does not undo that influence.
Character.AI has its own version of this problem. Under the terms, AI characters you created may remain accessible on the platform after account deletion, continuing to be available to other users. See the provision.
Midjourney barely addresses retention at all. If you are evaluating this platform for business use, the absence of a clear retention schedule is the kind of gap that should show up in a vendor assessment.
Can you sue an AI company if something goes wrong?
Four of the 38 force arbitration: OpenAI, Character.AI, Microsoft Copilot, and Midjourney.
Arbitration directs disputes to a private proceeding rather than court, typically without a jury or public record. All four also include class action waivers. If the same issue affects multiple users, the agreement directs each to pursue claims individually.
Under these agreements, if ChatGPT generates false claims about you, the terms direct disputes to individual arbitration rather than court. If Character.AI produces harmful content, the agreement limits collective legal action. If Midjourney uses your creative work, the terms designate individual arbitration as the dispute resolution mechanism. Enforceability may vary by jurisdiction. Compare arbitration clauses across all platforms.
The other 34 platforms, including Anthropic, Google Gemini, Cohere, and Mistral AI, do not include mandatory arbitration in their consumer terms.
How hard is it to opt out of training?
One toggle: Anthropic has a clear setting. OpenAI has one located under Settings > Data Controls > "Improve the model for everyone."
No opt-out: Character.AI and Midjourney. Content is licensed upon submission. No setting changes that.
Enterprise contracts only: Cohere, Databricks, and Scale AI limit training controls to paid enterprise agreements with separate DPAs. Free and standard plans get the defaults.
Off by default: Mistral AI does not train on paid customer data. Training is opt-in. This is still the exception in the industry, not the rule.
What does the law say about this?
GDPR Articles 13 and 22. Any AI platform processing data of people in the EU must disclose what it does with that data and whether automated decision-making is involved. Training on conversations is processing. The transparency requirements under these articles are relevant to platforms that train on conversation data. See GDPR coverage.
CCPA and CPRA. If you are in California, you have the right to know what is collected, to delete it, and to opt out of its sale or sharing. Using conversations to train models likely qualifies as a "business purpose" requiring disclosure. Depending on the specifics, it may also engage opt-out requirements under the "sale" or "sharing" provisions. See CCPA/CPRA coverage.
EU AI Act. Enforcement began in phases in 2025. Providers of general-purpose AI must disclose training data sources. Platforms training on conversations without clear disclosure face growing compliance exposure as enforcement scales. See EU AI Act coverage.
If you use AI tools personally
Review training settings in ChatGPT. Open ChatGPT. Tap your profile icon. Settings. Data Controls. Toggle off "Improve the model for everyone." Takes 30 seconds. Content submitted before changing this setting may have already been used for training. Disabling it applies to future interactions.
Check Claude's settings if you use the free tier. Go to claude.ai, open settings, review your privacy preferences. If you pay for the API, training is already off.
If you need to ask about something personal, know which platforms protect you most. Not all AI chatbots treat your data the same way. Anthropic's paid tier does not train on your inputs. Mistral does not train on paid customer data. OpenAI and Google train by default. If you plan to discuss sensitive topics with an AI, consider reviewing which platforms authorize training on your inputs under their current terms.
Check your arbitration opt-out window. OpenAI, Character.AI, and Midjourney all have opt-out periods. They are typically 30 to 60 days from account creation. If you are still in the window, send your opt-out in writing. Once the window closes, the arbitration terms apply under the agreement.
Request your data. Under GDPR, email the company's privacy contact and ask for a copy of everything they hold on you. Under CCPA, look for the "Do Not Sell My Personal Information" link in their privacy policy footer. The response can provide useful context about what data the company holds.
If your organization uses these as vendors
Review whether your DPA covers AI training. If your team uses ChatGPT, Gemini, or Copilot and the data processing agreement does not explicitly exclude training on your inputs, it may be happening. Enterprise agreements may include this carve-out, but it is worth verifying explicitly.
Add these to your vendor due diligence questionnaire:
- Does the platform train on our inputs and outputs? Under which conditions?
- Can human reviewers at the vendor access our data?
- What is the data retention period after deletion or account closure?
- Does the agreement include mandatory arbitration or a class action waiver?
- What is the dollar liability cap? Does it cover AI output errors specifically?
Flag Character.AI and Midjourney for internal review. A $100 liability cap and a perpetual irrevocable content license are provisions that should trigger a risk assessment before either platform is approved for business use. If employees use these on company devices or with company data, that is a vendor risk issue worth raising.
Compare enterprise terms before procurement. Anthropic, Cohere, and Mistral AI currently offer the clearest contractual separation between consumer and enterprise data handling. This is based on their published terms as of April 2026. Terms change. Verify current terms before relying on this for procurement decisions. Browse all 204 monitored platforms.
How we verified this
ConductAtlas archives the full text of privacy policies and terms of service for 204 platforms daily, including 38 AI companies. Every version is cryptographically hashed, timestamped, and assigned a stable record identifier. When a document changes, we generate a structured diff, extract the affected clauses, and produce analysis with specific regulatory citations.
This post is based on 845 active provisions across 55 AI platform documents. Every claim links to the provision page with the original clause language and full analysis.