Is Claude Private for Legal Work?

It depends on which Claude you mean. Consumer Claude on a personal account is the wrong place for client-confidential work today. Since an August 2025 change, Anthropic uses Free, Pro, and Max chats to train its models unless you opt out, and allowing training extends retention to five years. Claude for Work, Team, Enterprise, and the API are a different posture: they run under Commercial Terms, and Anthropic states it does not train on that content. The burden is on your firm to confirm which product, and which terms, you are actually on. This is general information, not legal advice. Policy facts here were checked July 2026; confirm the current terms before you rely on them.

The Claude for Legal plugin in Claude settings

TL;DR

  • Consumer Claude now trains on your chats by default. Since the August 2025 update, Free, Pro, and Max conversations are used to improve Claude models unless you opt out (Anthropic, checked July 2026).
  • Allowing training extends retention to five years. If you leave training on, Anthropic keeps chats for up to five years. If you opt out, it keeps the older 30-day window.
  • Opting out is not total erasure. Conversations flagged for safety review can be retained and used even after you opt out.
  • Commercial tiers are a different contract. Claude for Work, Team, Enterprise, and the API run under Commercial Terms that state Anthropic does not train on customer content, and the customer owns the outputs.
  • A toggle is not a contract. A consumer setting can flip in an update, as this one did. A signed agreement with a no-train commitment is what client work needs.
  • ABA 512 makes verification your job. You must understand the tool's data handling and, in general, get informed client consent before entering confidences.
Quick check

Since August 2025, what happens to consumer Claude (Free/Pro/Max) chats by default?

The Claudes are not the same product

People say "Claude" as if it is one thing. For confidentiality it is at least two products with different promises.

  • Consumer Claude. The Free, Pro, and Max plans you reach at claude.ai with a personal login. Governed by the Consumer Terms and the Privacy Policy.
  • Commercial Claude. Claude for Work (Team and Enterprise), the Anthropic API, and offerings like Claude for Government and Education. Governed by the Commercial Terms and a customer agreement.

A lawyer who signs up at claude.ai with a personal email is on the first one. That matters, because the August 2025 change moved consumer Claude to training on your chats by default. The commercial tiers did not change.

What changed in August 2025

On August 28, 2025, Anthropic updated its Consumer Terms and Privacy Policy. The headline shift: Free, Pro, and Max chats and coding sessions are now used to train and improve Claude models unless you opt out. Before this, Anthropic did not train on consumer chats by default and generally deleted them within about 30 days.

Two facts drive the new posture, both from Anthropic's own announcement (checked July 2026):

  • Training is on unless you opt out. New users pick during signup. Existing users had to make a choice by the deadline to keep using Claude, with the setting defaulted toward sharing.
  • Allowing training extends retention to five years. If you leave training on, Anthropic keeps that data for up to five years. If you decline, you stay on the prior 30-day retention.

Consumer Claude vs Claude for Work and API

This table is the short version. Always confirm the current terms yourself, since vendor policies move, as this one did in 2025.

QuestionConsumer Claude (Free / Pro / Max)Claude for Work / Team / Enterprise / API
Trains on your data by defaultYes, since August 2025, unless you opt outNo, Commercial Terms state Anthropic does not train on customer content
RetentionUp to 5 years if training is on; 30 days if you opt outGoverned by your agreement; zero-retention is an option for eligible commercial use, not automatic
Human review of your contentYes for safety-flagged content, which can persist after opt-outLimited to safety enforcement under the commercial agreement
Admin controls and data agreementNo, consumer terms onlyYes, customer agreement and a data processing agreement, with admin controls
Who owns outputsGoverned by consumer termsCustomer owns its outputs under the Commercial Terms
Fit for privileged workNoCloser, with the agreement and controls in place

Two traps to name. First, a personal claude.ai account is the path of least resistance, and it is now the train-by-default consumer tier. Second, opting out is a setting, not a signed no-train commitment, which is a weaker thing to point to if a client or regulator asks how the data was handled.

What Anthropic actually says about consumer Claude

The Consumer Terms and Privacy Policy now describe a product that learns from your chats. Anthropic's Privacy Policy states it may use your inputs and outputs to train and improve its models unless you opt out through account settings. That is the default a lawyer lands on at claude.ai.

The retention math follows the same split. Allow training and Anthropic keeps the data for up to five years. Opt out and you keep the older 30-day window. Even after you opt out, conversations flagged during safety review sit outside that promise and can be retained and used for enforcement. So the opt-out narrows exposure. It does not hand you a clean confidentiality guarantee.

What Anthropic says about Claude for Work and the API

The commercial side reads differently because it is a different contract. Anthropic's Commercial Terms state it does not train models on customer content from the services. The same terms assign output rights to the customer, so you own what the model produces from your inputs. That is the shape you want for client data: a no-train default backed by a written agreement, not a consumer toggle.

Retention on the commercial side is set by your agreement rather than a fixed consumer window. Anthropic offers a zero-data-retention arrangement for eligible commercial use, where it does not store inputs or outputs except where needed to comply with law or stop misuse. That is not automatic. You have to qualify for it and configure it, and Anthropic still keeps safety classifier results to enforce its usage policy.

The catch is conditional. These protections attach to the paid commercial products under their terms, not to a personal login. Read your own agreement, confirm whether zero retention applies to you, and check the admin controls your team has set. For a broader look at what Claude can and cannot do on legal tasks, see our guide to Claude for legal work.

Safe and unsafe lawyer uses, tied to confidentiality

The duty of confidentiality under Model Rule 1.6 does not pause for a new tool. ABA Formal Opinion 512 applies it to generative AI directly. You must understand how the tool handles your input, and you should generally get the client's informed consent before entering confidences into a tool that could expose them. Boilerplate consent in an engagement letter is not enough.

Map that to consumer Claude, where chats now train the model by default and can persist for years:

Reasonable on consumer Claude (no client confidences):

  • Drafting a plain-English explainer of a public legal concept.
  • Rewriting or shortening text that carries no client or matter detail.
  • Brainstorming a deposition outline using hypothetical, anonymized facts.
  • Summarizing a published statute or a public court opinion.

Not safe on consumer Claude:

  • Pasting a client contract, term sheet, or settlement figure.
  • Entering names, parties, or any detail that identifies a matter.
  • Uploading privileged communications or attorney work product.
  • Running anything you would not want retained for five years or seen in a safety review.

The dividing line is simple. If keeping or reviewing it would breach a confidence, it does not belong in consumer Claude. On Claude for Work or the API with a no-train agreement in place, the calculus changes, but you still verify the terms and match the tool to the sensitivity of the matter.

The verdict

Consumer Claude on a personal account is not private enough for client-confidential work now. Since August 2025 it trains on your chats by default, and allowing that extends retention to five years. Opting out helps, but it is a toggle that already changed once, and safety-flagged content can outlive it. Claude for Work, Team, Enterprise, and the API are built on different terms. They state no training on customer content, they assign output ownership to you, and they can be configured for zero retention. That is a real difference, but it is conditional. The protection lives in the commercial agreement and the admin settings, not in the word "Claude." Confirm which product you are on, read the current terms, and handle client consent under ABA 512.

The same plan-versus-terms split shows up with other tools. See our guides on whether ChatGPT is confidential for legal work, whether Copilot is private for legal work, and whether Gemini is private for legal work. For task selection across tools, our best legal AI tools for in-house counsel covers where each fits. The full duty set is in our ABA Formal Opinion 512 guide.

Vaquill AI is a legal AI suite for in-house counsel built on the assumption that your matter data is privileged, with a no-train stance and source-linked answers over real US statutes and opinions, an approach we stress-tested in an open accuracy benchmark. A legal tool is not magic. What changes is that the confidentiality terms are written for client data instead of a general consumer audience, which is the gap a personal Claude account leaves open.

Sources: Updates to Consumer Terms and Privacy Policy (Anthropic, August 2025), Anthropic Privacy Policy, Anthropic Commercial Terms of Service, Is my data used for model training? (Anthropic Privacy Center). ABA Formal Opinion 512 (American Bar Association, July 2024).

FAQ

Is Claude private for legal work? Not on a personal account. Since August 2025, consumer Claude (Free, Pro, Max) trains on your chats unless you opt out, and allowing training extends retention to five years. Claude for Work and the API are a different posture, with terms that state no training on customer content.

Does Claude train on what I type? On consumer Claude, yes, unless you opt out. Anthropic's Privacy Policy states it may use your inputs and outputs to train and improve its models unless you turn that off in settings. Confirm the current terms, since these changed in 2025.

What changed with Claude in August 2025? Anthropic updated its Consumer Terms so Free, Pro, and Max chats are used for model training by default unless you opt out. Before that, Anthropic did not train on consumer chats and generally deleted them within about 30 days.

How long does Claude keep my conversations? If you allow training, Anthropic keeps consumer chats for up to five years. If you opt out, you stay on the older 30-day retention window. Commercial retention is set by your agreement, and zero retention is an option for eligible commercial use.

If I opt out of training, is my Claude data safe? Opting out helps but is not total erasure. It stops future chats from feeding training and keeps the shorter retention window. Conversations flagged during safety review can still be retained and used for enforcement.

Is Claude for Work or Enterprise safe for client data? It is built on different terms. Anthropic's Commercial Terms state it does not train on customer content, and the customer owns the outputs. You still confirm your agreement, whether zero retention applies, and the admin controls your team has set.

Does the Anthropic API train on my data? No. API use falls under the Commercial Terms, which state Anthropic does not train on customer content. Read your agreement to confirm retention and whether you qualify for a zero-data-retention arrangement.

Can I use Claude and stay compliant with ABA 512? With care. You must understand how the tool handles your data, match it to the sensitivity of the matter, and generally get the client's informed consent before entering confidences. A consumer account that trains on your chats is the wrong fit for privileged material.

Last updated: July 2026.

Legal AI that reads your documents and knows the law.
Ask a legal question, review a contract, or search thousands of your files. Every answer shows where it came from. 7-day free trial, no card.
12 min read

New legal AI guides, weekly.

Arshita Anand

Arshita Anand

Co-Founder & CEO · Attorney

Arshita leads product and strategy at Vaquill, building the legal AI suite that solo, small-firm, and in-house US lawyers use to run a matter end to end.