AI Writing Tools That Don't Train on Your Data: A 2026 Procurement Guide

🔒 Vendor policy review by TopAIWritingTools.com · Published 15 September 2026 · Every claim links to the vendor's own page; where a page blocked automated retrieval, we say so
The short version: Almost every major vendor does have a no-training commitment — but usually only on the business or API tier. On consumer tiers the defaults are frequently the opposite. So the decisive question is not "does this company train on data" but "which tier am I on, and what does the contract for that tier say." Policies change — verify on the vendor's own page before you buy.

Why This Question Moved From Nice-to-Have to Procurement Blocker

Two years ago this was a question for legal teams at large companies. In 2026 it is asked by anyone who puts client work, unreleased copy or internal strategy into a text box. And there is an asymmetry that catches buyers out: the tool someone signs up for at 11pm is almost always a consumer tier, where training defaults are most likely on, while the contract the company signs is a business tier, where they are usually off. Exposure comes from the gap between the two.

The Three-Tier Model: Consumer, Business, API

The same company can give three different answers depending on the tier, so name the tier first.

Consumer tier (free and individual paid plans). Data is typically used to improve the service by default, and the training switch — if there is one — lives in your personal account settings. Assume the permissive default until you have checked.

Business tier (Team, Business, Enterprise). The default usually reverses: the vendor contractually commits not to train on your content, enforceable through a Data Processing Addendum rather than a settings toggle. The catch is that this commitment attaches to a sales conversation, not the checkout page.

API tier (developer access). Usually the strongest protections — no training by default, a DPA, often a zero-data-retention option — but the tier least resembling an AI writing tool. For how this fits the wider purchase, see our buyer's checklist.

What Each Vendor's Policy Actually Says

Everything below comes from the vendor's own published page, linked inline.

OpenAI (ChatGPT): opposite defaults on consumer and business

For business products — the API, ChatGPT Business, Enterprise, Team and Edu — inputs and outputs are not used to train models by default. For consumer products — Free, Plus and Pro — conversations may be used to improve models by default, with an opt-out under Settings → Data Controls ("Improve the model for everyone").

Two details matter. "Not trained on" is not "not stored": API data is typically retained around 30 days for abuse monitoring, and Zero Data Retention exists for qualifying endpoints but is not self-serve. Sources: OpenAI Enterprise Privacy, training data control.

Anthropic (Claude): commercial and consumer are opposite defaults

Anthropic's Commercial Terms contain one of the clearest sentences in the category: "Anthropic may not train models on Customer Content from Services." The same terms define Customer Content as Inputs and Outputs and confirm the customer retains rights to Inputs and owns Outputs. The Privacy Center is blunter: "By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models."

The consumer side is the opposite default, and that is the trap. Anthropic's privacy policy says it "may use your Inputs and Outputs to train and improve Anthropic AI models, unless you opt out through your account settings" — with two carve-outs that survive the opt-out: conversations flagged for safety review, and material you report through feedback. The toggle sits at Settings → Privacy ("Help Improve our AI models"). On retention, API inputs and outputs are deleted within about 30 days, and Zero Data Retention is available per organisation by arrangement; it does not cover stateful features like the Files API. Sources: Commercial Terms, privacy policy, training FAQ.

Google Gemini: the billing account is the switch

Google's split runs through billing, not product names. On unpaid services — the free consumer Gemini app, and API or AI Studio use without a linked Cloud Billing account — data is used to improve Google's products and human reviewers may process inputs and outputs. Unpaid-tier content is disconnected from your account and API key before review, which also means it cannot be located and deleted on request.

Once a Cloud Billing account is linked, Gemini API and AI Studio count as a Paid Service for data-use purposes even on free quota, and Google states it does not use prompts or responses to improve its products. Gemini in Workspace carries the same commitment, with no human review. The trap: a Workspace login does not by itself extend those protections to a separately used AI Studio session. Source: Gemini API Additional Terms.

Grammarly, now operating as Superhuman

First, a structural change: grammarly.com/privacy-policy now redirects to superhuman.com/legal/privacy-policy, following the parent company's rebrand to Superhuman. The current policy, effective 6 July 2026, states that the company uses information it collects to train its AI models, and that users can decide whether their content is used for training via the training control in account settings.

The tier detail is specific: individual users can toggle it themselves; on multi-user accounts bought through the website it starts on, with an admin able to opt out for the organisation; and on Business, Education, Pro and Enterprise accounts bought through sales it is off by default. A small team that bought seats on the website is in the middle case — on until an admin changes it. Sources: Superhuman privacy policy, training control article.

Jasper: strongest language, in the documents buyers skip

Jasper's Ethics page states plainly: "Data and intellectual property entered into Jasper is NOT used to train underlying LLMs." Its Data Processing Agreement goes further: Jasper "will not collect, retain, use, sell, disclose or otherwise process any Controller Data, for any purpose other than providing the Services." That processing-limitation clause is broader than a no-training promise because it restricts secondary use generally — but a DPA is a contract, so it applies where the contract applies. Note the qualifier "underlying": the commitment is that Jasper's resold foundation models are not trained, and it lives on marketing pages — Jasper's legal privacy policy contains no training clause at all. Sources: Jasper Ethics, Jasper DPA.

Copy.ai: a clear claim, not a clause

Copy.ai's security page says: "We don't train on your data. Your prompts and ideas fuel your success, not our AI models." That is clear, and it is on the vendor's own site — but it is a marketing claim on a security page, not a contractual clause: neither Copy.ai's privacy notice nor its terms of service contains a training clause at all. If this decides your purchase, get the same commitment into the contract. Source: Copy.ai security page.

QuillBot: a real opt-out, and a default that moved the wrong way

QuillBot's November 2025 privacy update is unusually candid: browser-extension users' text inputs are now stored by default, replacing the previous consent-based approach, with an opt-out available. Two controls replaced the single old consent — one for storing inputs (all users, on by default) and one for using them to train models (account-holders only) — under Extension Settings → View All Settings → Data and Privacy. Team Plan inputs continue to be excluded from training by default. Sources: privacy update notice, how QuillBot uses your data.

Where we could not verify a policy

We could not verify a published training policy for Rytr as of September 2026. Rytr's privacy policy and terms of use contain no clause stating whether submitted content is used to train models, and its help centre does not address it. We will not infer a position from an absent clause in either direction.

We could not verify a published training policy for Hypotenuse as of September 2026. No reachable official page states its position on training from customer content. If either vendor matters, ask support for a written answer and a DPA — and treat a refusal to put it in writing as the answer. Our Hypotenuse pricing notes cover what we could verify about the product itself.

How to Read a Terms of Service: The Five Sentences That Decide It

1. The training clause. Look for "train," "improve," and "develop." The distinguishing verb is may versus will not. "We may use your content to improve our services" is permissive; "we will not train models on Customer Content" is a prohibition. Both are honest; only one is what you want.

2. The processing-limitation clause. Often in a DPA rather than the public terms, and often stronger: "we will process Customer Data only to provide the Services" restricts secondary use wholesale, covering uses nobody has thought of yet.

3. The retention sentence. Look for a specific number — 30 days is the common default — and whether a zero-retention option exists and who can request it. If it takes a sales call, it is enterprise-only.

4. The definition of "Customer Content." Check that Inputs, Outputs and uploaded files are all inside it. A clause covering prompts but not uploaded documents is narrower than it reads — and brand guidelines are exactly what teams paste in.

5. The tier scope. Usually a structural fact rather than a sentence: the terms define who "Customer" is, and if your plan doesn't make you one, the protections do not apply.

The Procurement Checklist

1. Identify the plan, not the product. Consumer, team, or enterprise changes the answer more than the vendor does.

2. Get the training position in writing. Email is fine; a help-centre article is better. A verbal answer on a sales call is not a record.

3. Request the DPA before you need it. If there isn't one, that changes what you can promise your own clients.

4. Check the default. Grammarly's website-purchased multi-user accounts and QuillBot's extension storage both start on; both can be changed.

5. Ask about retention separately. Get a number of days. If the answer is "as long as necessary," treat it as unlimited.

6. Find out who can change the setting. Admin-only controls are a single point of failure if the setting dies with one person's account.

7. Inventory what your team actually pastes in. Client deliverables, unpublished pricing, roadmap notes. If the material is client-owned, your client's policy may bind you independently.

8. Set a review date. Several policies cited here changed materially within eighteen months. A commitment verified in January is not verified in September.

When the Vendor Won't Commit in Writing

Sometimes the answer is a marketing page and nothing else. That is not automatically disqualifying — it depends what you put through the tool. For client-owned material, an unenforceable claim is not a control.

The pattern worth internalising: the strongest protections here are almost never on the pricing page. They are in DPAs, commercial terms and platform documentation — the three documents buyers open last. The two vendors we could not verify failed for the same reason: there was no document to read.

If data handling is one of several criteria you are weighing, our buyer's checklist puts it alongside price and editing time, and our refund comparison covers the other contract term worth checking. For product comparisons, see ChatGPT vs Claude and our client-work guide for agencies.

Want the prompts we tested with?

The E-Commerce Copy Pack — 50+ tested prompts for product pages, ads & emails.

Get the Pack →

FAQ

Which AI writing tools do not train on your data?

On business or API tiers, OpenAI, Anthropic, Google, Jasper and QuillBot all publish no-training commitments, and Copy.ai states on its security page that it does not train on your data. On consumer tiers the defaults are often the opposite. We could not verify a published training policy for Rytr or Hypotenuse as of September 2026.

Does ChatGPT train on my conversations?

It depends on the tier. ChatGPT Free, Plus and Pro may use conversations to improve models by default, and you can opt out under Settings, Data Controls. On the API, ChatGPT Business, Enterprise, Team and Edu, inputs and outputs are not used for training by default.

Is "not used for training" the same as "not stored"?

No. Even where training is off, data is usually retained for a period — around 30 days is common — for abuse monitoring and legal compliance. Ask for the retention window separately from the training position.

What should I ask a vendor before signing?

Ask which plan the no-training commitment attaches to, request the Data Processing Addendum, ask for a retention period in days, and confirm whether the account-level default is on or off.

Get the Best AI Tool Deals in Your Inbox

One email per month — new tools, price drops, and honest comparisons.