Guide6 min read

Claude (Anthropic) and Your Data: Should You Anonymize First?

Per Anthropic, its commercial products (API, enterprise) don't train Claude on your data by default. Anonymizing first is still a control you keep.

By Pierre de ONYRI
Worried about your data? Anonymize it before AI

Should you anonymize your data before sending it to Claude? Direct answer. Anthropic's default is rather privacy-friendly. Per Anthropic, its commercial products — the API, Claude for Work, Claude for Government — don't use your inputs and outputs to train the models by default. That's a genuine plus, and worth crediting honestly. But Claude is still a third party that processes your prompt. And a policy can change. So anonymizing before you send is a defense in depth that you control. ONYRI Sanitize does it in your browser.

What Anthropic says about your data

Let's start with the attributed fact. Per Anthropic (privacy center), its commercial products don't train the models on your data by default. The exact wording is: « By default, we will not use your inputs or outputs from our commercial products to train our models. » In other words, the Anthropic API, Claude for Work and Claude for Government follow this no-train default.

There are exceptions, which Anthropic acknowledges. Explicit feedback on your part (thumbs up or thumbs down) can allow the exchange to be used. Explicit consent can too. In that case, per Anthropic, the conversation tied to that feedback may be kept for up to five years. The no-train default remains the rule, but it isn't absolute.

  • Per Anthropic, the API, Claude for Work, Claude for Government and Claude for Education follow the no-train default.
  • Per Anthropic, this default also applies to API use via third parties like Amazon Bedrock or Google Cloud Vertex AI.
  • Exception cited by Anthropic: explicit feedback or consent can allow training, with retention up to five years.

The consumer nuance: Free, Pro and Max

Here, a tier distinction changes everything. The no-train default above targets the API and enterprise offerings. It doesn't automatically cover the consumer plans. Per Anthropic, its consumer terms were updated on 28 August 2025. For Free, Pro and Max, conversations and coding sessions now serve to improve Claude, unless the user opts out. So it's an opt-out model, with a decision to make before 8 October 2025.

Retention changes too. Per Anthropic, if you accept model improvement, the duration rises to five years. If you decline, it stays at thirty days. Also per Anthropic, deleted conversations aren't used for training. Remember this above all. An employee's personal account, pasting a work document into Claude, follows these consumer rules, not the enterprise terms.

Why anonymizing first is still worth it

A good default doesn't remove the need for care. Here's why anonymizing first keeps its value, even with Claude.

  1. 1Claude is still a third party that receives and processes your prompt: the fewer real values it sees, the better.
  2. 2A policy can change, as the August 2025 consumer shift showed: defense in depth doesn't depend on the vendor's goodwill.
  3. 3You don't always control the tier in use: an employee on a personal account lacks the enterprise guarantees.
  4. 4Anonymizing before sending is a measure you control end to end, whatever the vendor's setting.

The table below recaps the rules by plan, as Anthropic describes them, and what ONYRI adds on top.

Claude planTraining by default, per AnthropicWhat ONYRI changes
API, Claude for Work, for Government, for EducationNo training by default (unless explicit feedback or consent)The prompt leaves already pseudonymized
Consumer: Free, Pro, MaxSince 28 August 2025: training unless you opt outYour real values stay on your device
An employee's personal accountConsumer rules, not the enterprise termsReduces exposure whatever the setting
Rules by plan after Anthropic's privacy center. Pseudonymization / anonymization framing after the CNIL.

How ONYRI does it

The ONYRI extension grafts directly onto the Claude site. It acts in your browser, before you send. The flow takes four steps.

  1. 1You write your prompt on Claude as usual.
  2. 2In the browser, the extension detects sensitive data and replaces it with reversible tokens.
  3. 3The already-pseudonymized prompt goes to Claude; the token ↔ value mapping stays in the tab, on your device.
  4. 4The answer comes back, and your real values are restored on screen, in the browser.

Key point on the boundary. The real values and the token ↔ value mapping never leave your browser. Claude only receives already-pseudonymized text, whatever its training policy. Detection stays heuristic: it strongly reduces exposure, without promising zero risk. A Free tier serves as an entry point; advanced features belong to the paid plans.

Diagram: a prompt bar sends text to an AI card marked with a shield-and-check glyph, a friendlier default. Yet the identifier rows still turn from amber to cobalt token chips before reaching it. This is defense in depth.
Claude's default is friendlier, but the identifiers are still pseudonymized before sending (defense in depth). CNIL framing: pseudonymization vs anonymization.

In short, Anthropic's commercial default works in your favor, and that deserves credit. But it doesn't cover every tier, and a policy can evolve. Anonymizing before you send stays a measure you keep under control. ONYRI detects, replaces with reversible tokens, then restores the answer in your browser. This approach reduces your data's exposure. It doesn't make it « anonymous under the GDPR »: reversible tokens are still pseudonymization.

Frequently asked questions

Should you anonymize your data before sending it to Claude?
Anthropic's default helps: per Anthropic, its commercial products (API, enterprise) don't train the models on your data by default. But Claude is still a third party, and the consumer tier follows other rules. Anonymizing before sending is a defense in depth that you control, useful whatever the vendor's setting.
Does Claude (Anthropic) train its models on my conversations?
It depends on the plan, per Anthropic. On the API and enterprise offerings, no training by default, save explicit feedback or consent. On the consumer plans (Free, Pro, Max), since 28 August 2025, exchanges serve to improve Claude unless you opt out. Always check the policy in force.
Does anonymizing with ONYRI make me GDPR-compliant?
No, not on its own. Per the CNIL, reversible tokens are pseudonymization: your data stays personal under the GDPR. The benefit is concrete: your real values don't leave your browser, which strongly reduces exposure and serves the minimization principle.

Sources & references

Keep your sensitive data in your browser

ONYRI Sanitize detects and masks your sensitive data before it reaches the AI, then restores the answer — from names to API keys.

Read next