AI tools like Claude can transform how all businesses operate — but businesses handling confidential client information need to understand how their data is treated across different plans and tools. This guide maps each combination of Claude plan and tool to its data-handling posture, so you can adopt AI with confidence.
| Tool | Free | Pro / Max | Team |
|---|---|---|---|
| Chat |
Not for client data Consumer terms: trains on your data by default with up to 5-year retention. Can opt out (30-day retention), but no contractual guarantee (no DPA). No admin oversight. |
Use with caution Identical privacy rules to Free — paying buys more usage and features, not better data protection. Trains by default unless each user individually toggles "Help improve Claude" off. No DPA. |
Recommended Commercial terms: no training on your data by default, backed by a Data Processing Addendum (DPA). Admin controls, SSO, and role-based permissions. The right home for confidential client work. |
| Skills |
Not for client data A Skill is your firm's process written down for Claude to follow — it adds no data risk of its own, but inherits Free's consumer terms and exposure. |
Use with caution Inherits Pro/Max consumer terms. Skills themselves are safe (just methodology), but the data you feed into them is subject to the same training/retention rules. |
Recommended Inherits Team's protected posture. Admins can provision one vetted Skill across the entire firm, ensuring consistent process and data handling. |
| Cowork | Not available on Free |
Avoid for client data Consumer terms plus agentic risk: Cowork takes screenshots, browses the web, and runs multi-step tasks — prompt-injection risk is non-zero. No centralised audit logging. |
Lower-sensitivity work only Protected on training (commercial terms), but Cowork still lacks centralised audit logging and is excluded from compliance/BAA coverage. Use for general productivity; keep most-confidential financials in Chat. |
| Code |
Not for client data Consumer terms (trains by default unless opted out). Also caches session transcripts locally in plaintext for ~30 days. |
Use with caution Same consumer terms plus local plaintext cache. Relevant only if the firm has developers writing code — not typical for most professional services firms. |
Protected No training by default under commercial terms. Zero Data Retention (ZDR) available on Enterprise. Local plaintext cache still applies — device security matters. |
All three consumer tiers run under identical data rules. Pro and Max buy more usage, not better data protection. The meaningful upgrade is to Team, where no-training is the default and it's contractual.
At claude.ai/settings/data-privacy-controls, individual users can turn off "Help improve Claude." This reverts to 30-day retention with no training — but it's per-person, not centrally enforced, and not backed by a contract. It helps an individual; it's not a firm-level answer.
Upgrading the plan doesn't close Cowork's compliance gap. Until centralised audit logging is added, the most confidential regulated work should stay in standard Chat — even on Team.
Claude Code stores session transcripts locally in plaintext for ~30 days regardless of plan. This is a device-security concern, not a plan concern — and largely moot unless the firm has developers involved.
Adopt Claude Team. Use Chat and Skills for confidential client work. Use Cowork for general productivity. Apply data minimisation (strip client identifiers where AI doesn't need them) and maintain a human approval layer on every AI output before it reaches an end client. This is general technical advice, and the best solution may differ for individual business use cases.