Claude Pro & Max Privacy: Retention, Training Opt-Out, Deletion
Do Claude Pro and Max train on your data? Retention periods, the training opt-out toggle, the 2025 privacy update explained, and how to delete your history.
Claude Pro and Max Have Identical Privacy Terms — Here's What They Are
Claude Max costs up to ten times what Pro costs. On privacy, the two plans are the same product. Every dollar of the difference buys usage limits and earlier feature access — not one line of different data handling. If you upgraded to Max expecting stronger confidentiality, this page is the correction; if you're deciding whether to, it's the fact-check.
The direct answer: Claude Pro and Claude Max run under one set of Consumer Terms and one Privacy Policy — Anthropic's privacy center documents Free, Pro, and Max as a single group, and no Anthropic document assigns them different data handling. On both plans: model training is controlled by the “Help Improve our AI models” setting (on unless you turned it off), retention is up to 5 years in de-identified form with training on or 30 days with it off, deleted conversations are purged from back-end systems within 30 days, and there is no zero-data-retention option. Verified against Anthropic's live documentation on August 5, 2026.
| Question | Pro | Max |
|---|---|---|
| Trains on your chats by default? | Yes — unless the “Help Improve our AI models” toggle is off (claude.ai/settings/data-privacy-controls) | |
| Retention, training on | Up to 5 years, de-identified | |
| Retention, training off | 30 days | |
| Deleted conversations | Removed from history immediately; off back-end systems within 30 days | |
| Incognito chats | Kept up to 30 days; never used for training; skip history and memory | |
| Zero Data Retention | Not available on any consumer plan | |
| Governing documents | Consumer Terms (effective October 8, 2025) + Privacy Policy (effective July 8, 2026) | |
The tier line that does change data handling runs between consumer and commercial — the claude.ai plans on one side, and the API, Team, Enterprise, and cloud-provider paths on the other, where training is off by default with no toggle to remember. That split is mapped in our Claude Code safety review and the Claude API data retention guide; this page stays on the consumer side, where most individual subscribers actually live.
Key Takeaway
Claude Pro and Max have identical privacy terms — one training toggle, one retention schedule (up to 5 years de-identified with training on, 30 days with it off), one 30-day deletion window, no ZDR. Plan tier is not privacy tier: the line that changes data handling is consumer vs commercial.
The Training Toggle and the 5-Year Window
One setting decides most of what this page covers. Since Anthropic's August 28, 2025 consumer terms update, Free, Pro, and Max accounts carry a model-training choice — “Help Improve our AI models,” at Settings → Privacy, direct URL claude.ai/settings/data-privacy-controls. What each position means, per Anthropic's retention documentation:
- Toggle on: Anthropic may use your chats and coding sessions to train future models and “may retain your data in a de-identified format for up to 5 years.” The scope includes the full conversation, custom styles and preferences, and Claude Code sessions run from your account. Raw content from connectors (Google Drive, MCP) is excluded unless you paste it into the chat.
- Toggle off: new chats and coding sessions are not used for training, previously stored conversations stop being used in future training runs, and retention is 30 days.
- Not retroactive: Anthropic states plainly that “your data will still be included in model training runs that are already in progress, or in models that have been trained.” Opting out stops the future, not the past.
Two channels sit outside the toggle and are easy to miss. Rating a response with thumbs up or down stores the entire related conversation for up to 5 years, regardless of your setting. And content flagged by Anthropic's safety classifiers follows safety-retention rules — inputs and outputs up to 2 years, classification scores up to 7 years — and may still be used to improve Anthropic's internal trust-and-safety models even when you've opted out of training.
If you run Claude Code from the same account, this toggle is also your code's training control — the walkthrough, and every other Claude Code flag worth setting, is in our Claude Code privacy settings guide.
That Privacy Update Notice From Anthropic, Explained

If you half-remember agreeing to something in a Claude pop-up — or you've got an Anthropic policy-update notice sitting in your inbox and want to know what it actually changed — there have been two distinct waves, and they did different things.
Wave one: the training choice (August–October 2025). Anthropic announced updated Consumer Terms in August 2025 giving Free, Pro, and Max users “the choice to allow their data to be used to improve Claude.” The terms took effect October 8, 2025, and that version is still current as of August 5, 2026 — so whatever you selected then is the regime your account runs under now. Press coverage at the time (TechCrunch) noted the notice presented a prominent Accept button with the training toggle preset to on beneath it — the design reason many people are opted in without remembering choosing. The full announcement-to-deadline sequence, including the extension that moved the date from September 28 to October 8 and the terminal notice Claude Code shows when the acceptance is still outstanding, is documented on our Is Claude Code safe? page.
Wave two: the 2026 Privacy Policy updates. The Privacy Policy — a separate document from the Terms — was updated twice in 2026, per Anthropic's policy changelog: on January 12, 2026, adding a Consumer Health Data Privacy Policy for US state residents using health-app integrations; and on July 8, 2026 (the current version), reflecting that “Claude can increasingly carry out longer tasks and work with third-party apps and services” — the agentic era — plus new verification-data categories (age and identity checks) and a reiteration that Anthropic does not sell your data or use it for advertising.
The practical summary: the 2025 wave is the one that affects your data handling today, because it installed the training toggle and its default. If you clicked Accept without touching the toggle, your setting is on — the privacy controls page takes thirty seconds to check.
Tip
Thirty-second audit: open claude.ai/settings/data-privacy-controls, check whether "Help Improve our AI models" is on, and set it deliberately. Most of this page's consequences flow from that one state.
Incognito Chats and What Deletion Actually Removes
Claude gives consumer accounts two levers for keeping specific conversations out of the record, and they do different jobs.
Incognito chats (the ghost icon, available on every plan including Free) are the before-the-fact lever. Per Anthropic's support documentation, an incognito chat is not saved to your chat history, is not written into Claude's memory, and “incognito chats are not used for training” — even if your training toggle is on. Retention is up to 30 days. Two boundaries: incognito is unavailable inside Projects, and it governs storage and training, not processing — the conversation still goes to Anthropic's servers and safety systems like any other.
Deletion is the after-the-fact lever. A deleted conversation is “removed immediately from your conversation history and automatically deleted from our back-end within 30 days” — that's from the Privacy Policy itself. The two limits mirror the training toggle's: content already used in completed or in-progress training runs isn't clawed back, and safety-flagged content follows the longer safety windows.
Memory is the third piece, because deleting a chat doesn't delete what Claude remembered from it. Memory on claude.ai (Free, Pro, and Max) stores work-focused context — your role, projects, preferences — viewable and editable at Settings → Memory, with a per-project memory space, a pause option, and an irreversible reset-all. If your goal is “no trace of this topic,” the full checklist is: incognito for the conversation (or delete it afterward), then check Memory for any entry it left behind.
What Pro and Max Don't Get: Zero Data Retention
The strongest retention arrangement Anthropic offers does not exist on consumer plans at any price. Zero Data Retention — under which prompts and responses are not stored at rest after the response returns — is a commercial contract feature: approval-based, requested through the sales team, enabled per organization. As of August 2026 it applies to eligible Anthropic APIs, products running on a Commercial organization API key (including Claude Code via the API), and Claude Code on Enterprise plans. The Team and Enterprise chat interfaces don't get it either — the full map of what's in and out is in our Claude API data retention guide.
What consumer plans top out at is the 30-day window you get by turning training off. That's a real posture — 30 days with no training is more conservative than many consumer AI products — but it's a policy you configure, not a guarantee you hold. The practical decision rule:
- Personal use, general work: Pro or Max with the training toggle off is a reasonable, documented posture.
- Client data, regulated data, anything a contract governs: the upgrade that matters is horizontal — to commercial terms (the API, Team, or Enterprise) — not vertical to a bigger consumer plan. Paying $100 or $200 a month for Max buys capacity; it does not buy a different data agreement.
Claude Cowork Data Retention: What's Documented So Far
Claude Cowork is Anthropic's agentic app — you give Claude a goal and it works across files and tools in folders you designate (“You choose the folders and tools. Claude can't reach anything else,” per the product page). It launched January 12, 2026 as a research preview in the Claude Desktop app for macOS, initially for Max subscribers; on July 7, 2026 it expanded to web and mobile in beta, and it now spans all paid plans (Pro, Max, Team, Enterprise) with desktop apps for macOS, Windows, ChromeOS, and Linux.
Because it's new, its privacy documentation is thinner than the rest of Claude's — here is what Anthropic's support pages establish as of August 5, 2026:
- Cloud sessions run on Anthropic's servers — “your sessions and files are saved to your Claude account,” and local files opened through the desktop app in a cloud session are processed server-side.
- Deletion follows the standard windows: deleting a Cowork task removes it “from our backend storage systems within 30 days, in accordance with our data retention periods.”
- Guardrails: file and network access are limited to connected folders, cloud sessions run in an isolated environment, and Claude “always asks before permanently deleting files, in any mode.”
- Governance: for individual accounts, Cowork falls under the Consumer Terms' scope — there is no separate Cowork consumer privacy policy. On Team/Enterprise, web and mobile Cowork activity is captured in the admin-facing Compliance API. And notably, Anthropic's commercial BAA explicitly excludes Cowork.
The open question, stated as one: Anthropic has not published a Cowork-specific statement on model training. The training setting's language covers “chats and coding sessions,” and no document carves Cowork in or out by name. The conservative read for a consumer account: assume your “Help Improve our AI models” setting is the control that matters, set it accordingly, and treat folders you connect to Cowork as data you're comfortable processing under consumer terms.
Voibe: For Voice Input, Retention Isn't a Toggle
Everything on this page is toggle management — one setting deciding whether your words are kept 30 days or 5 years, deletion windows, carve-outs. That's the nature of cloud products: privacy is a configuration you maintain. Voice input is the one part of an AI workflow where you can opt out of the configuration game entirely, which is the design premise of Voibe, the dictation app we build.
If you talk to Claude — dictating prompts, drafting messages, thinking out loud into a text box — the dictation layer decides who hears the audio before Claude ever sees text. Voibe's answer: on Apple Silicon Macs, transcription runs fully on-device with Whisper, so the audio never leaves the Mac — there is no retention window because there is no server copy to retain. On Windows and Intel Macs, Voibe uses its private zero-retention cloud running open-source models only: audio is never stored, never sold, never used to train AI — as the default, for every user, not as an enterprise agreement. Dictation runs at roughly 5x typing speed, and Smart Formatting cleans up fillers locally without paraphrasing what you said.
The boundary, honestly drawn: Voibe covers the voice half. Your text still lands in Claude under whatever consumer settings this page just walked through — the toggle still matters, incognito still matters. But “what happens to my audio?” becomes a question with a structural answer instead of a settings answer. Voibe is $7.50/month, $59/year, or $149 lifetime; the voice-to-AI workflow is in our dictation for AI prompting guide.
Info
Try Voibe for Free: download at getvoibe.com — no account, no credit card. On-device mode requires an Apple Silicon Mac (M1 or newer); Windows and Intel Macs run on the private zero-retention cloud.
Claude Privacy, Page by Page
This page covers the consumer plans. The rest of the cluster:
- Is Claude safe? — the claude.ai product overall: what Anthropic collects, how it compares with ChatGPT, and what's reasonable to paste into a chat.
- Is Claude Code safe? — the developer CLI's full safety review, including the consumer-vs-commercial split this page keeps pointing at.
- The session transcript prompt — a separate consent from the training toggle on this page: shared transcripts cannot be used to train Anthropic's models, whichever way your toggle is set.
- Claude Code privacy settings — every env var and toggle for the CLI, plus session deletion.
- Claude API data retention — the commercial side: the 30-day default, ZDR, the Covered Models rule, and the Bedrock/Google/Foundry paths.
- AI Tool Privacy Tracker — the cross-tool reference, updated continuously.
Frequently Asked Questions
Does Claude Max train on your data?
Is Claude Pro's privacy different from Claude Max's?
How long does Claude keep my conversations on Pro or Max?
How do I stop Claude from training on my conversations?
Does deleting a Claude conversation remove it from Anthropic's servers?
Do Claude Pro or Max offer zero data retention?
What was the Anthropic privacy update notice about?
Are Claude incognito chats actually private?
What is Claude Cowork's data retention?
Ready to type 5x faster?
Voibe is the fastest, most private dictation app for Mac and Windows. Try it today.
- On-device or private cloud
- Free to try
- No subscription
- Mac + Windows
- 90+ languages
Prefer to go Pro? Save 20% on any plan with code VOIBE20 View pricing →
Related Articles
Claude Code Privacy Settings: Every Opt-Out & Env Var (2026)
Every Claude Code privacy setting in one place: disable non-essential traffic, feedback survey, training opt-out, and how to delete sessions. Copy-paste ready.
Is Claude Safe? Privacy, Data Retention & Security Review (2026)
Claude is safe for everyday use once one toggle is checked. What Anthropic collects, how long chats are kept, and how Claude compares with ChatGPT on privacy.
Can Anthropic Look at Your Session Transcript? What Yes Uploads
Claude Code asks after the rating prompt. Yes uploads your transcript, subagent logs, and the raw session file, kept 6 months. What's redacted, what isn't.

