Oversharing with AI: Why Your Chatbot Conversations May Not Be Private
 (Part 2)

Is Your AI Chat Really Confidential?

arrow
September 9, 2026
By: Savvas Daginis

Your AI chatbot conversations are not automatically confidential. Before sharing sensitive business information, check whether the terms governing your account require the provider to protect it. Turning off model training does not, by itself, create that obligation.

In Part 1 of whether AI Chatbot Conversations are Confidential, I focused on whether providers could use your conversations to train their AI models, where your data is stored, and other AI privacy risks. This follow-up addresses a separate question: has the provider agreed to keep your information confidential?

Why does confidentiality matter?

Imagine sharing an unreleased product design with a prospective service provider. You would likely want a non-disclosure agreement (NDA) limiting how the service provider can use and disclose that information, and requiring safeguards. Uploading the same design to an AI chatbot deserves similar scrutiny.

A commitment not to train on your data addresses only one use of your information. Confidentiality provisions address broader questions: who may access it, how it may otherwise be used, and when and with whom it may be shared.

What do ChatGPT, Claude, and Gemini terms say?

The following terms and guidance were reviewed on September 6, 2026:

  • ChatGPT’s consumer Terms of Use allow users to opt out of model training but do not include the express confidentiality commitments found in OpenAI’s business agreement. Paying for ChatGPT Pro does not change that distinction. 
  • Claude’s Consumer Terms likewise do not include the confidentiality section found in Anthropic’s Commercial Terms. Paying for Claude Pro does not change that distinction.
  • Google’s Gemini Apps Privacy Hub warns against entering confidential information that users would not want reviewers to see or Google to use for service improvement. It also explains that some human review can occur even with Keep Activity turned off.

These services may offer privacy controls and have legal duties. But those protections should not be assumed to provide the same contractual safeguards as an NDA. 

Sidebar: is personal information the same as confidential information? Personal and confidential information are not the same thing, although they can overlap. 

  • Personal information is information about an identifiable person, such as their name, email address, or medical history. It is not necessarily secret: your name may appear publicly on your company’s website, and personal information can still be protected by privacy laws even when it is publicly accessible.
  • Confidential information, meanwhile, can include an unreleased product design, a secret recipe, or a business strategy—even if it contains no personal information at all. Confidential information, as a general rule (with exceptions), generally is no longer confidential when made public.

Why does this matter when using AI? A chatbot provider’s promise to protect personal information does not necessarily extend to your confidential business information. Before uploading something sensitive, check whether the provider’s commitments cover the information you actually want to protect.

Do business AI plans protect confidential information?

Business agreements can provide stronger contractual protection. For example, OpenAI’s Business Services Agreement, Section 7, and Anthropic’s Commercial Terms, Section E, contain express confidentiality obligations addressing permitted use, safeguards, and disclosure.

Those obligations have limits, including exceptions for legally required disclosure. Check the agreement governing your specific product, account, and connected services. A paid subscription or “enterprise” label is not enough on its own.

How can businesses reduce AI confidentiality risks?

  • Choose appropriate tasks. Start with public or non-sensitive information. Assess the risks before allowing confidential material into an AI workflow.
  • Review the terms and controls. Check confidentiality, training permissions, human access, retention, deletion, and third-party integrations. Confirm that you are authorized to upload the information.

Before you paste, ask: would you share this information with another service provider under these terms?

Davis, Burch & Abrams is a business law firm that helps companies develop practical, compliant AI, privacy, and cybersecurity programs tailored to evolving technology laws. If you have any questions about this article—or if your business needs guidance to stay current with AI, privacy and cybersecurity laws in the United States or Canada—please reach out to the author, Savvas Daginis, at savvas.daginis@davisba.com.

This article is for informational purposes only and should not be seen as legal advice. You should consult with a lawyer before you rely on this information.

Related News

Why Pre-Sale Trademark Confusion Matters

How Trademark Confusion Can Begin Before Purchase Most trademark infringement cases involve a familiar allegation: a business uses a name,…

READ MORE >

Preventing Business Email Compromise and Payment Fraud

Business email compromise (also called payment fraud, funds transfer fraud, social engineering fraud, and misdirected invoice fraud) is one of…

READ MORE >

Before You Sign a Franchise Agreement: Mitigating Financial and Asset Risks

What you need to know before you sign. If you aspire to be an entrepreneur but are unsure what kind…

READ MORE >