Somebody on your team is going to paste a client contract into a chatbot this week. Probably today. They won’t do it maliciously. They’ll do it because the deadline is Thursday and the tool summarises things well, and because nobody ever told them which tools were cleared and which weren’t. The gap that lets this happen is rarely about training or policy documents. It’s that “is this tool safe for work data” takes about forty minutes to answer properly, and nobody has forty minutes. A good AI tools directory will narrow forty candidates down to four for you. The last step is on you, because the answer lives in a vendor’s terms. And those change more often than their feature page.
Here’s the version of that forty minutes that’s worth doing, in the order that catches the most problems fastest.
Start with the plan tier, not the vendor
Almost every argument about AI vendor privacy is confused because people compare companies when the meaningful differences are between plans at the same company.
OpenAI’s business offerings state that data from the API, ChatGPT Enterprise and ChatGPT Team is not used to train its models by default. Consumer tiers run on different defaults and different controls. The Data Processing Addendum you need for GDPR is offered for Team, Enterprise and API customers, not for personal accounts. So “we use ChatGPT, it’s fine, they don’t train on our data” can be simultaneously true for the CTO on an Enterprise seat and false for the intern on a free account, inside the same company, on the same afternoon.
The first question is therefore never “is this vendor trustworthy.” It’s “which exact plan is each person on, and what does the contract for that plan say.”
The retention story is more interesting than the training story
Most teams ask whether their inputs will be used for training. Fewer ask how long the data sits there, and who else can compel access to it. That second question produced the most instructive episode of the last two years.
In May 2025, a court in the New York Times copyright litigation ordered OpenAI to preserve output log data. Data that would otherwise have been deleted, overriding normal deletion schedules and users’ own delete actions. The order covered consumer ChatGPT tiers and API customers without a zero-retention agreement. ChatGPT Enterprise, Edu, and API customers with a ZDR agreement were excluded. OpenAI called the order a privacy nightmare, fought it, and its obligation to retain going-forward content ended on 26 September 2025. In early 2026, a court ordered production of a sample of de-identified consumer logs in discovery.
Nobody was hacked. No policy was violated. A third party’s lawsuit simply reached into a retention schedule and changed it, and the users affected mostly found out from the news.
The takeaway isn’t that one vendor behaved badly, it’s that deletion on a SaaS product is a promise about ordinary conditions. Standard practice at the major providers is removal within about 30 days, with carve-outs for abuse monitoring and legal obligations. If your compliance position requires that something genuinely cannot be retained, the answer is a contractual zero-retention arrangement or a deployment where the sensitive values never leave your side, not a toggle in a settings menu.
Three documents, in this order
Skip the marketing site. The pages that answer the question are:
The DPA. Does one exist for the plan you’re buying? Is it self-serve or does it require sales? Who are the sub-processors, and does the list include anyone in a jurisdiction that creates a problem for you? A vendor with no DPA for your tier is telling you it doesn’t intend to be a processor for business data.
The retention and training terms for that tier. Written defaults, not the FAQ’s summary. Note whether training is opt-in or opt-out, whether opting out changes retention, and whether human review is ever part of the loop.
The security page and whatever it links to. SOC 2 Type II or ISO 27001 with a current report available under NDA is the ordinary bar. A trust page with badges and no report is decoration.
Everything else — data residency, export format, SSO, admin visibility into who’s using what — you can settle in one email.
What is Aitoprating?
Aitoprating is a leading AI tools directory which helps teams shortlist products by what they do and how they charge, so the two or three you end up reading contracts for are the ones actually worth the reading time. It won’t replace that reading, and any directory claiming otherwise is selling something.
The email to send before the trial starts
Vendors answer these faster than you’d expect, and the speed of the reply tells you almost as much as its content:
- Is a DPA available on the plan we’re evaluating, and can we see it before signing?
- Are our inputs and outputs used for training on this plan by default, and can that be disabled at the workspace level rather than per user?
- What is the retention period for prompts, outputs and logs, and what triggers an exception to it?
- Where is data stored and processed, and who are your sub-processors?
- If we leave, what can we export and in what format?
A vendor that can’t answer the retention question in a sentence hasn’t decided the answer yet.
Make the safe path the easy path
Bans don’t work here. People will use their phones. What works is having a short list of approved tools with the right plans already provisioned, so the cleared option is also the fastest option, plus one obvious rule about what never gets pasted anywhere: customer personal data, credentials, unreleased financials, anything under NDA.
Then set a review date. Terms get rewritten, vendors get acquired, plans get restructured, and the tier you cleared in March may not be the tier your team is on in November. Half a day, twice a year, against the same three documents. It’s dull work and it is considerably less dull than the alternative conversation with a client whose contract went somewhere it shouldn’t have.






