Two conversations this month, same worry.
A consultant runs transformation projects for corporate clients. They hand her their laptops, locked down, nothing installable. She wants to run AI on her own machine instead. Her question: "Am I allowed to? And how do I tell my clients?"
A therapist friend wants to work with AI too. His clients are high profile. His question: "The data goes to an American company. I can't do that, right?"
I hear a version of this every week, so I did the homework. Every claim below links straight to its source: official policies, legal texts, independent benchmarks. And a quick heads-up: I'm not a lawyer and this isn't legal advice. It's what I found, and what I do myself.
The short version
- Does Claude train on my data? On business plans: never. On personal plans: yes, unless you turn one switch off. Takes ten seconds.
- How secure is it? Encrypted everywhere, with the same audited security certifications your bank's software carries.
- Could Anthropic get hacked? Same risk category as Google or Microsoft getting hacked. Banks and pharma companies run on Claude, and their security teams checked harder than you ever could.
- Is it allowed in Europe? Yes, with a proper setup: a business plan, a data-processing contract, and honesty with your clients. You can even keep the processing inside the EU.
- Health data and other sensitive categories? Higher bar. Still doable, with extra care.
- And if that's still not enough for my work? Run an open AI model on your own hardware. As of this summer, they're genuinely good.
Now the same answers, from your seat.
"I'm a freelancer and I use Claude every day. Is it training on my chats?"
Depends which Claude you're on.
On the personal plans (Free, Pro, Max), yes: since late 2025 Anthropic uses chats for training by default. Turning it off takes ten seconds: Settings, Privacy, "Help Improve Claude", off. Once it's off, deleted chats are wiped from their systems within 30 days.
On the business side (Team, Enterprise, the API), the default flips. Your data is never used for training, it's deleted from their servers within 30 days, and API customers can go further and have nothing stored at all.
So "everything you type trains the AI" is only true for a personal account with default settings. One switch, or one business seat, and it's simply not the case anymore.
"What if Anthropic gets hacked and my client files leak?"
Nothing is zero risk. But here's the context.
Anthropic makes about 80% of its money from businesses, over 300,000 of them, and passed a $30 billion yearly revenue pace this spring. Commonwealth Bank runs fraud detection on Claude. The insurer AIG underwrites with it. Novo Nordisk writes clinical reports with it. These companies send security teams in before they sign. A breach would end Anthropic's business overnight, and they spend on security accordingly: everything encrypted, independently audited, certified to the same standards as the software your bank runs (SOC 2, ISO 27001, and the new AI-specific ISO 42001).
The realistic risk isn't their datacenter. It's us: wrong plan, wrong settings, or pasting things somewhere a contract says they shouldn't go. All three are fixable in an afternoon, which is what the rest of this article is about.
"My data goes to America. Is that even allowed here?"
You've probably already answered this question once. If you run your business on Gmail and Google Drive, you already trust an American cloud company with everything you have, under a data-processing contract, with a promise not to train on your content. Business Claude is the same legal structure: the same kind of data-processing contract, the standard EU clauses covering the transfer, no training, audited security. Same category of decision.
And if data leaving Europe is the dealbreaker: Claude also runs inside EU datacenters, in Frankfurt, Paris, Ireland and more, through AWS and Google Cloud. The processing stays in Europe. That's how European enterprises with strict rules use it today.
"My client gave me their laptop and an NDA. Can I still use my AI setup?"
This was the consultant's question, and here the law isn't the point. The contract is.
Their laptop, their rules: what you install and where their data travels is their policy, and no privacy setting overrides an NDA. You can be perfectly legal and still in breach of contract.
So don't sneak. Ask. In writing:
"I use AI assistants under a business agreement: no training on your data, deletion within 30 days, EU processing available. Here's my one-page setup. OK for our project?"
I've never seen that conversation go badly. While everyone else quietly pastes things into free chatbots, you show up with a data sheet. Most companies are busy writing rules about which AI tools are allowed; you're handing them the paperwork. And if you work fully under your client's instructions, EU law requires their written sign-off on your tools anyway, so you're just doing it properly.
"I'm a therapist in Europe. Can I use an American AI at all?"
Yes, and it's worth seeing where the real line sits. Three layers:
Most of your work has no patient data in it. Marketing, scheduling, invoicing, research, your website, writing. That's most of the time AI saves you, at no special risk.
Anonymous case material is outside privacy law entirely. If a description can't reasonably be traced back to a person, data-protection law doesn't apply. One trap: changing the name to initials isn't anonymous. Strip the identifying details too: places, dates, professions, anything traceable.
Actual patient data has a higher bar, and it was designed to be met. Germany changed its professional-secrecy law in 2017 specifically so doctors and therapists can use IT providers, under conditions. France requires certified health-data hosting. Regulators' advice for the most sensitive material: prefer AI that runs locally. Which brings us to the last question.
"What if the answer for my work is still no?"
Then run the AI yourself. This stopped being a compromise very recently.
Four days ago, Moonshot AI released Kimi K3 with open weights, meaning you can download the model and run it on your own hardware. On the independent Artificial Analysis index it scores 57 against 61 for Claude Opus 5: the strongest open model ever, months behind the frontier instead of years.
The honest fine print: the full K3 needs datacenter hardware. The realistic setup is its smaller sibling, Kimi K2.6, which runs on a single Mac Studio with 512GB of memory, about €12k, entirely offline. Client data never leaves the room. And in between there's a middle path: European providers like Scaleway serve open models from Paris datacenters, under French jurisdiction, with no-training commitments.
So the ladder: business Claude for most work. Claude in EU datacenters if residency matters. Open models on European servers if the vendor matters. Your own machine if everything matters. I'm setting up that last rung myself in the coming weeks, and it will become part of what I teach.
"Okay. What should I actually do?"
- Business plan or API access, not a personal free account.
- Ten seconds in settings: training off on any personal account you keep.
- Accept the data-processing agreement, file it.
- One written paragraph to each client: the tools, the protections, the ask.
- Keep personal data out of prompts unless it needs to be there. Anonymize by default.
- Genuinely sensitive data: EU datacenters or your own machine.
One afternoon of admin, for a question that has blocked people for two years.
The bigger point
The professionals who win the next few years won't be the ones who avoided AI the longest. They'll be the ones who can look a client in the eye and explain exactly where the data goes, because they did the homework. Fear is free. Clarity takes an afternoon, and it's a competitive advantage.
P.S. This is what we do at Timeback. In the bootcamp we set up your AI system on the right plan with the right settings, on your real work. And for those who need the strictest setup, the own-server track is coming: an open model on hardware you control. Details at the bootcamp.
Every link above goes to a primary source: official policies, legal texts, or independent benchmarks. All checked July 30, 2026.