Before any B2B team deploys Claude, someone asks the same question: what happens to our data? It's the right question to ask, and the answer isn't one-size-fits-all. It depends on which Claude product you're using, what you connect to it, and how you've configured your account. Here's a plain-English breakdown of what Claude can see, what it can't, and what the actual privacy controls are.
The short answer
If you use the Claude API or Claude for Teams, Anthropic does not use your conversations to train its models by default. Your data stays out of the training pipeline. If you use the free Claude.ai tier, Anthropic may use your conversations to improve Claude — you can opt out, but the default is different from the business products.
For most B2B teams, the relevant products are Claude for Teams and the Claude API. Both are designed for business use with data privacy as a baseline, not a paid add-on.
What Claude actually sees during a conversation
Claude is not always watching. It only knows what is present in the active context window during a session. That includes:
- The system prompt — instructions set by whoever configured the tool
- The conversation history from the current session
- Any content explicitly passed in: documents, data, tool outputs
- Data pulled by connected systems during that session (via MCP servers or connectors)
Historically, Claude did not retain memory across separate conversations by default. That changed with an August 2026 update: Claude now carries relevant context forward between sessions across Claude.ai and Cowork, on by default, though it's a separate, user-visible feature and doesn't change the training policy described above. See what Claude's new memory update actually remembers, and how to control it for the details.
Claude also has no access to your internal systems — your CRM, file server, email, or databases — unless you connect those systems deliberately. Connecting Claude to HubSpot, Slack, or your own data via an MCP server is an explicit action, not something that happens automatically.
What Claude can't see
- Anything from before memory was turned on for your account
- Systems you haven't connected to it
- Other users' conversations — sessions are isolated
- Your organizational data outside the current context window
- Anything that wasn't explicitly passed into the active conversation
The product breakdown: consumer vs. business
Not all Claude products have the same privacy posture. Here's where each one stands.
Claude.ai free
The consumer product. By default, Anthropic may use conversations to train and improve its models. You can opt out in your privacy settings, but it's not off by default. This is the appropriate product for personal use — it is not designed for business data, client information, or anything you'd consider confidential.
Claude.ai Pro
The paid consumer tier. Conversations are not used for training by default at the Pro tier. Better than free, but Pro is still a personal product — no organizational admin controls, no data processing agreement, no audit capabilities.
Claude for Teams
Anthropic's business subscription, designed for companies. Conversations are excluded from model training by default. Team admins can manage users, see usage, and configure settings centrally. This is the right product when you want a managed Claude workspace for your organization without building anything custom.
Claude API
What developers use to build custom Claude tools, Skills, automations, and integrations. API inputs and outputs are not used to train Anthropic's models by default. The API gives you the most control: you define what goes into the context, you manage data flow, and you can implement zero data retention by not logging on your end. This is what TEG uses when building Claude implementations for clients.
Claude Enterprise
Anthropic's largest tier, for organizations that need SSO, expanded context windows, enhanced audit controls, and formal contractual data governance. Enterprise includes access to a Data Processing Addendum and, for eligible use cases, a HIPAA Business Associate Agreement. If your organization has procurement or legal requirements around AI vendor data handling, Enterprise is where those conversations happen.
How data retention works
Anthropic retains API inputs and outputs for a limited period for safety and trust and safety review purposes — this is disclosed in their usage policies. The default retention window is not indefinite. If your use case requires zero retention (certain legal, healthcare, or government contexts), that's a conversation for Anthropic's Enterprise team and is covered under a formal agreement rather than a standard API subscription.
For Claude for Teams, data handling is governed by Anthropic's standard business terms. For Enterprise customers, a Data Processing Addendum covers specifics including retention periods, subprocessors, and data deletion obligations.
When you connect Claude to your tools
This is where teams get tripped up. Connecting Claude to HubSpot, Slack, your CRM, or your own internal systems via Model Context Protocol (MCP) means that data from those systems flows through Claude's context window during a session. Claude can read what it's given access to — and that data is part of the conversation that Anthropic's infrastructure processes.
The privacy posture of those connections depends on:
- Which Claude product you're using (API or Teams vs. consumer)
- What data scopes you grant to the connection
- Whether you've reviewed Anthropic's subprocessor and data flow disclosures
Best practice when connecting Claude to live business systems: scope permissions tightly. If Claude only needs to read a deal stage in HubSpot, don't give it access to your entire contact database. Least privilege applies to AI integrations exactly as it does to any other system access.
What to do before deploying Claude with sensitive data
If you're deploying Claude in a context where the data is sensitive — client records, financial data, health information, legal documents — here's the checklist:
- Use the API or Claude for Teams, not the free product. The business products have the right baseline privacy posture.
- Review Anthropic's Data Processing Addendum if your organization requires a DPA. It's available for Teams and Enterprise customers.
- For HIPAA: get a Business Associate Agreement. A BAA is required before using Claude with protected health information. This is only available through Anthropic's Enterprise program.
- For GDPR: review the DPA and subprocessor list. Anthropic's privacy documentation covers EU data handling, but your legal team should sign off based on your specific data types and user locations.
- Scope integrations tightly. Only connect the systems Claude needs and only grant access to the data it requires for the task.
- Build with the assumption that context window contents are processed. Don't put data into Claude's context that you wouldn't want processed by a third-party AI vendor under standard business terms.
The bottom line for B2B teams
Claude for Teams and the Claude API are both appropriate for business use under standard conditions. Anthropic does not train on your data when you use these products. Claude sees only what you put in front of it, and only during the active session.
The risks in Claude deployments aren't usually in the model — they're in how teams configure access, what data they pass into the context, and whether they've thought through what "connected to Claude" actually means for a given system. Those are implementation decisions, not platform decisions.
If you're evaluating Claude for a deployment that involves sensitive data, the question isn't whether Claude is safe in the abstract. It's whether your specific implementation is configured correctly. That's the part TEG helps with.
Deploying Claude with sensitive data?
We've built production Claude implementations across real estate, finance, and professional services. We can tell you what to watch for before you start.
Get your automation roadmap