Guide

Client Asks 'Will You Train On My Data?' — How a Freelancer Answers in 2026

At a glance

As of August 2026, the honest answer splits three ways: the vendor’s training default, what you actually paste, and what your contract promises. Copy-ready replies included.

As of August 2026, “Will you train on my data?” shows up on discovery calls the way “Who owns the files?” used to. Clients have read leak headlines and vendor pop-ups about model improvement. They want to know whether their deck or unpublished prices will become someone else’s training set.

Do not answer with a slogan you have not opened this month. Split the reply: what the tool does by default, what you refuse to paste, and what the contract commits you to. Mixing those promises is how you inherit a policy you never read.

Have I Been Trained and Spawning once offered a Do-Not-Train registry for published work under EU text-and-data-mining opt-outs. As of August 23, 2026, both pages are under maintenance and unusable; any effect depends on training providers honoring it. It never governed a private Google Doc.

Three layers, in that order

Layer 1 — The tool. Consumer and business/API offerings have different data terms; a paid consumer plan is not a business tier. Confirm each live page before you quote it:

  • OpenAI consumer Data Controls: ChatGPT can train on chats unless you turn off “Improve the model for everyone.” Temporary Chat is the short-retention path (OpenAI describes deletion after 30 days — confirm).
  • OpenAI business / API: Business, Enterprise, Edu, and the API are not used to train by default. Abuse logs are often kept up to 30 days unless zero-data-retention applies (platform data controls — confirm).
  • Anthropic commercial: Claude for Work and the API are not used for training by default. Feedback can retain the related thread (Anthropic has described up to five years — confirm).
  • Anthropic consumer: Free / Pro / Max follow the user’s model-improvement setting. Incognito is excluded even if that setting is on.
  • Gemini Apps Privacy Hub: Keep Activity on can feed improvement, including human review. Temporary chats are not used to train. Activity off still leaves a short hold (Google has described 72 hours — confirm).
  • Gemini API terms: unpaid / AI Studio content may improve products; paid quota is described as not. Free access in the EEA, Switzerland, and the UK follows Paid Services data rules. Check region and service status before client use.

Retention is not training, and training is not “a human read it.” Ask which one they mean.

Layer 2 — Your handling. This is the only layer you fully control: strip names before paste; use a business/API tier, not a personal Plus login; keep anything you would not email to a stranger off consumer apps. If you cannot keep that rule, do not take the job.

Layer 3 — The contract. The vendor page is not your promise. The SOW should name the tools and tier, the training status, how long you keep files, and that you will not train on the client’s materials or reuse them in other jobs. If you cannot name the tool, do not sign.

A comparison you can show (confirm current)

Use this as a conversation card, not a statute. Recheck the official pages on the day you send the proposal.

Surface (as of August 2026) Training default What you must still do
ChatGPT consumer Can train unless you opt out in Data Controls Keep confidential files out; opt out and save dated evidence for non-sensitive material
ChatGPT Business / API No training by default; optional share Confirm the workspace, not your personal login
Claude Free / Pro / Max Depends on model-improvement setting Check the toggle; prefer Incognito for one-off pastes
Claude for Work / API No training by default Watch feedback buttons and any partner program
Gemini app Keep Activity can feed improvement Temporary chat or activity off; still a short hold
Gemini API unpaid May improve products; EEA, Switzerland, and UK access follows paid-data rules Check region and terms before confidential work
Gemini API paid Described as not used to improve Confirm you are on paid quota

If the client needs a signed DPA, zero-data-retention, or a BAA, verify and price that compliance scope separately. Say that early.

Three replies you can paste

1. Consumer-tool honesty (most freelancers). “I draft in [tool], on a login where model training is turned off (screenshot attached, dated). I do not paste your customer lists, credentials, or unpublished prices. I edit locally. I do not use your materials to train anything of mine or to prompt other clients. If you need a no-training business workspace, we can move this job to [Business/API tier] with verified pass-through costs, whether seat- or usage-based.”

2. Business-tier / API. “This work runs on [ChatGPT Business / Claude for Work / paid Gemini API]. Those products state they do not train on business inputs by default ([link], checked [date]). I will not click feedback on your threads. Retention for abuse monitoring may still apply; it is not the same as training. I delete project files from my machine within [N] days of final invoice unless you ask me to keep a copy.”

3. Refuse the paste. “I cannot put that file into a general-purpose model. I can work from a redacted excerpt, from a local search over files that stay on your drive, or I can decline this part of the job. I would rather lose the task than promise a control the vendor does not offer on this tier.”

Put it in the quote, not in Slack

Add a six-line block to every proposal:

  1. Tools and tier (names, not “AI”).
  2. Training status you verified, with URL and date.
  3. What you will never upload.
  4. Where files live (your disk, their drive, the vendor).
  5. How long you keep them after delivery.
  6. What happens if the vendor changes the policy mid-job (you notify; client can pause).

That block is the product. The spoken reassurance is not. Pair it with the disclosure habit in The Watermark That Follows Your AI Text when the same client asks both “will this be marked?” and “will this be trained on?”

If you cannot fill the six lines, you are not ready to take confidential work. Use a redacted sample, charge a small process audit, or stay on public-source tasks until the workspace matches the promise. Clients are not asking you to recite a privacy policy. They are asking whether you know which product you opened this morning.