What you will be able to do
- Recognise the categories of data that call for extra care before they go into a chat
- Reduce a task to the minimum data it actually needs
- Explain when a consumer-plan conversation can and cannot be used to improve Claude
- Take the right first steps after sensitive data has been shared by mistake
Key concept
Share the minimum, on a suitable plan — Before you share data with Claude, work out the least data the task needs. Then use a plan whose data protections fit how sensitive that data is. Minimising the data and choosing the plan are two separate checks, and you need both.
1.Recognising data that needs a second thought
Every privacy decision starts before anything is pasted or uploaded. Anthropic's consumer help centre explains the privacy protections it applies to chats. It still recommends being thoughtful about sharing some kinds of information. It names four: financial information such as SSNs, card numbers and bank details; health records or medical information; passwords or private login credentials; and confidential business or personal documents.
The list is a useful starting point, but it does not cover everything. A customer spreadsheet, a draft merger memo and a set of job applicants' CVs don't fit neatly under one heading. Each still carries personal or commercially confidential information. The AI Fluency course suggests a practical test: annotate the material. Mark which fields contain personally identifiable information (PII), which fields the task actually needs, and what the worst case would be if the data were exposed.
2.Minimise first, then decide
Handling sensitive data well doesn't mean avoiding AI. It means using it responsibly. The course's main technique is to work backwards from the goal. For pattern analysis you usually don't need names, contact details or other PII, so you can often remove identifying information entirely before sharing anything. When the whole task seems to need sensitive input, try splitting it. Often only one part touches the sensitive fields, and the other parts can go to Claude without them.
After minimising, pick the tool. The course notes that a free AI tool you use to brainstorm event themes is not the same as a paid account with strict data retention policies, and says to match the tool to the task. The more sensitive the data that remains after minimisation, the stronger the plan's protections need to be. For regulated data, your organisation's approved arrangements decide the plan, not your own preference.
Keep the giving amounts and dates, and any non-identifying fields the analysis needs. Remove names and contact details, because pattern analysis doesn't need them. Then check the results yourself before acting on them.
Sources2
3.When a consumer conversation can be used for training
Whether your inputs can end up in model training depends on the kind of plan. Anthropic keeps separate help articles for this. The consumer article covers Claude Free, Pro and Max, including Claude Code used with those accounts. It sends commercial users (Claude for Work and the Anthropic API) to a different page. Don't carry an answer from one page over to the other.
| Route | What triggers it |
|---|---|
| You allow it | You choose to allow your chats and coding sessions to be used to improve Claude |
| Safety review | Your conversation is flagged for safety review, and may be used to improve detection and enforcement of the Usage Policy |
| Explicit feedback | You provide materials directly, for example with the thumbs up/down feedback button |
| Explicit opt-in programme | You opt in to training in some other way, for example by joining the Trusted Tester Program |
When you do allow it, Anthropic describes several protections. Data is de-linked from your user ID before any review. Access is limited to a small number of people. Tools are used to filter or obfuscate sensitive data. Two exceptions matter. First, incognito chats are never used to improve Claude, even with Model Improvement switched on. Second, conversations flagged by safety classifiers may still be used for trust and safety work. The protections lower the risk, but they don't make it safe to paste anything. Anthropic's own guidance still recommends care with the four categories above. It also encourages users not to use its products to process personal data.
A Claude.ai Free plan user deletes a conversation from their chat history. According to Anthropic's consumer data retention policy, when is that conversation removed from Anthropic's back-end storage systems?
Correct answer: A — Within 30 days of the deletion request, per Anthropic's standard back-end purge window
- A. Correct. Deleted conversations are removed from chat history immediately, then purged from Anthropic's back-end storage systems within 30 days.
- B. Incorrect. Deletion is immediate only from the visible chat history; back-end systems still take up to 30 days to fully purge the data.
- C. Incorrect. The 5-year window applies to data retained under the optional model improvement setting, not to deleted conversations that were never opted in.
- D. Incorrect. The 2-year window applies specifically to inputs and outputs flagged for trust and safety violations, not to routine user-initiated deletions.
4.If sensitive data has already been shared
Mistakes happen. For example, someone pastes a confidential document into a personal account. The course lists what you can do: delete the conversation, request data deletion through the platform's privacy process, and follow your organisation's protocols. Following the protocol matters because the data belongs to the organisation, and the incident may need to be reported through its own channels. Deleting the chat alone doesn't do that.
The consumer Privacy Policy also sets out individual rights. These include the right to request a copy of your personal data and to object to its processing or ask for it to be deleted. Anthropic is open that these rights are limited, and that handling requests about its training dataset is complex. That is one more reason to minimise data before you share it rather than rely on removing it afterwards.
A Claude.ai Pro user's conversation is flagged by automated safety classifiers, which generate safety classification scores in addition to the conversation content. How long may Anthropic retain those safety classification scores compared to the flagged inputs and outputs?
Correct answer: A — Safety classification scores may be retained for up to 7 years, longer than the 2-year window for flagged inputs and outputs
- A. Correct. Under the consumer retention policy, flagged inputs and outputs may be retained up to 2 years, while safety classification scores may be retained for up to 7 years.
- B. Incorrect. This reverses the actual durations; safety classification scores are the ones retained longer, up to 7 years, not deleted immediately.
- C. Incorrect. The 5-year figure applies to the optional model improvement and feedback retention windows, not to trust and safety flagged content or its scores.
- D. Incorrect. The 30-day window applies to standard back-end deletion of routine deleted conversations, not to safety classification scores from flagged content.
Exam traps
Each one states something that sounds right. Open it to see what is actually true.
1.If Model Improvement is switched on, incognito chats are used for training like any other chat.Why is that wrong?
Incognito chats are excluded from model improvement whatever the setting says.
Covered in When a consumer conversation can be used for training
2.Turning off model improvement guarantees that no conversation of yours is ever used for any model work.Why is that wrong?
Conversations flagged by safety classifiers may still be used to improve Anthropic's trust and safety models and to enforce its policies.
Covered in When a consumer conversation can be used for training
Sources
Every claim above is drawn from one of these pages, quoted as it was written on the date shown.
- 1.
“we also recommend being thoughtful about sharing highly sensitive personal details such as:”
↩︎ Recognising data that needs a second thought“We automatically de-link your data from your user ID (like your email address) before any review.”
↩︎ When a consumer conversation can be used for training“Your incognito chats are not used to improve Claude, even if you have enabled Model Improvement in your privacy settings.”
↩︎ Exam trap 1“If our safety classifiers flag your conversations, they may still be used to improve our internal trust and safety models”
↩︎ Exam trap 2 - 2.https://academy.claude.com/courses/ai-fluency-for-nonprofits/understanding-privacy-and-dataOfficial docs
“What's the worst-case scenario if this data were exposed?”
↩︎ Recognising data that needs a second thought“For pattern analysis, you likely don't need names, contact details, or other PII.”
↩︎ Minimise first, then decide“Often you can get full benefit from AI without sharing sensitive information by breaking tasks into component parts”
↩︎ Minimise first, then decide“Match your tool to your task—tools with more protection allow for safer sharing of sensitive data.”
↩︎ Minimise first, then decide“Delete the conversation, request data deletion through the platform's privacy process, and follow your organization's protocols”
↩︎ If sensitive data has already been shared“Work backwards from your actual goal to determine what data is truly necessary”
↩︎ Key concept - 3.https://privacy.claude.com/en/articles/10023555-how-do-you-use-personal-data-in-model-trainingOfficial docs
“For our commercial products such as Claude for Work and the Anthropic API, see here.”
↩︎ When a consumer conversation can be used for training“we encourage our users not to use our products and services to process personal data.”
↩︎ When a consumer conversation can be used for training“please be aware that these rights are limited”
↩︎ If sensitive data has already been shared