You can opt out, but the fact that it's opt-in by default and made to look like a simple T/C update prompt leaves a sour taste in my mouth. The five year retention period seems... excessive. I wonder if they've buried anything else objectionable in the new terms.
It was the kick in the pants I needed to cancel my subscription.
Everywhere else in Anthropic's interface, yes/no switches show blue when enabled and black when disabled. In the box they're showing about this change the slider shows grey in both states: visit it in preferences to see the difference! It's not just disappointing but also kind of sad that someone went to the effort to do this.
This is probably because there are laws in some countries that restrict how these buttons/switches can look (think cookie banners, where sometimes there is a huge green button to accept, and a tiny greyed out text somewhere for the settings).
yes, it’s a very big loophole. and if it’s a generative model, you can just launder the data through synthetic generation/distillation to future models
this is somewhat true but i'm not sure how load bearing it is. for one, i think it's going to be a while until 'we asked the model what bob said' is as admissible as the result of a database query
Implicit consent is not transparent and should be illegal in all situations. I can't tell you that unless you opt out, You have agreed to let me rent you apartment.
You can say analogy is not straightforward comparable but the overall idea is the same. If we enter a contract for me to fix your broken windows, I cannot extend it to do anything else in the house I see fit with Implicit consent.
> The interface design has drawn criticism from privacy advocates, as the large black "Accept" button is prominently displayed while the opt-out toggle appears in smaller text beneath. The toggle defaults to "On," meaning users who quickly click "Accept" without reading the details will automatically consent to data training.
It’s not. And also whether you move the toggle to on or off, you still have to click accept which really isn’t clear whether you’re accepting to share your data or not.
Granted, it is a stretch and not near the features of Claude (no code etc), but at least Proton's Lumo [0] is very privacy oriented.
I have to admit, I've used it a bit over the last days and still reactivated my Claude pro subscription today so... Let's say it's ok for casual stuff? Also useful for casual coding questions. So if you care about it, it's an option.
If you aren't using it for coding or advanced uses like video, etc, you can try running models locally on your machine using Ollama and others like it.
Self plug here - If you aren't technical and still want to run models locally, you can try our App [1]
Since I don't use LLMs to directly code for me, I'm going to (mis?)place my trust in Kagi assistant entirely for the time being. It claims not to associate prompts with individual accounts. Small friction of keeping a browser tab open is worth it for me for now.
The 5 year is the real kicker. Over the next 5 years I find it doubtful that they won't keep modifying their TOS and presenting that opt out 'option' so that all it will take is one accidental click and they have all your data from the start. Also, what is to stop them from removing the opt out? Nothing says they have to give that option. 4 years and 364 days from now TOS change with no opt out and a retention increase to 10 years. By then the privacy decline will have already have been so huge nobody will even notice that this 'option' was never even real.
it's almost like this multi billion dollar company is misanthropic, despite their platitudes. Should I not hold my breath on Anthropic helping facilitate "an era of AI abundance for all"? (To quote a rejected PR applicant to Anthropic from the front page)
I wonder what happens if I don't accept the new T&C? I've been successfully dismissing an updated T&C prompt in a popular group messaging application for years -- I lack the time and legal acumen to process it -- without issue.
Also, for others who want to opt-out, the toggle is in the T&C modal itself.
The new privacy policy automatically becomes effective on September 28, if you don’t already agree to it before. Anthropic states that “After September 28, you’ll need to make your selection on the model training setting in order to continue using Claude.”
Has anyone asked why OpenAI has two very separate opt-out mechanisms (one in settings, the other via a formal request that you need to lodge via their privacy or platform page)? That always seemed likely to me to be hiding a technicality that allows them to train on some forms of user data.
“If you choose not to allow us to use your chats and coding sessions to improve Claude, your chats will be retained in our back-end storage systems for up to 30 days.”
it seems really badly designed or maybe it is meant to be confusing. It does not make it clear that the two are linked together, and you have to "accept" the both together even though there is only a toggle on the "help us make the model better" item.
OpenAIs temporary chat still advertises that chats are stored for 30 days while there is court order that everything must be retained indefinitely.
I wonder why they are not obligated to state this quite extreme retention.
Two weeks left in the sub to figure it out, but I'm not yet sure. I was never all in on all the tooling, I mostly used it as smart search (e.g. ImageMagick incantations) and for trivial scripting that I couldn't be bothered writing myself, so I might just stick to whatever comes with Kagi, see if that doesn't cover me.
I like think using OpenRouter is better, but there’s absolutely no guarantee from any of the individual providers with respect to privacy and no logging.
Nitpicking: “opt in by default” doesn’t exist, it’s either “opt in”, or “opt out”; this is “opt out”. By definition an “opt out” setting is selected by default.
The scenario that concerns me is that Claude learns unpublished research ideas from me as we chat and code. Claude then suggests these same ideas to someone else, who legitimately believes this is now their work.
Clearly commercial accounts use AI to assist in developing intellectual product, and privacy is mandatory. The same can apply to individuals.
> Claude then suggests these same ideas to someone else, who legitimately believes this is now their work.
Won't this mean that claude assisted you with someone else work? Sure it's not from a "chat" but claude doesn't really know anything other than it's training data
If you have an idea and are putting it together, you might use Claude for a few things:
- Search the web for related ideas. This could help if someone's already had the idea or if there are things to learn from related ideas.
- Review your writeup or proofs for mistakes and clarity
None of these things make the idea Claude's. Claude merely helped with some of the legwork.
But Claude now has your idea in clear, plain text to train on. The next time someone hits on even a similar idea, Claude might well suggest your idea outright. Not seeing your idea published, the user has no way to know it isn't a novel idea. If the person is less diligent/thorough, they may well publish first and claim it as there own, without any nefarious intent.
There is a stark difference between using the public web to do research and searching through your colleagues' private notebooks and discussions to do research.
> claude doesn't really know anything other than it's training data
I've seen cases where Claude demonstrates novel behaviors or combines existing concepts in new ways based on my input. I don't think it's as simple as memorization anymore.
To clarify, I see AI as an association engine of immense scope. Others are responding with variations on this model in mind.
It has long been a problem in math research to distinguish between "no one has had this idea" and "one person has had this idea". This used to take months. With the internet and MathSciNet, ArXiv online it took many iterations of guessing keywords. Now, I've spent six months learning how to coax rare responses from AI. That's not everyone's use case.
What complicates this is AI's ability to generalize. My best paper, we imagined we were expressing in print what everyone was thinking, when we were in fact connecting the dots on an idea that was latent. This is an interesting paradox: People see you as most original when you're least original, but you're helping them think.
With the right prompts AI can also "connect the dots".
Math research or anything new/clever in a particular niche.
Imagine you optimized a piece of code to get an advantage or came up with some clever trick to solve a common problem in your niche and then everyone gets it from free from Claude believing, as you pointed out, that it's now their work.
I had this exact conversation with my business partner a few days ago. Our "secret sauce" might not be worth that much after many years but still I am not comfortable exposing it to Claude. Fortunately it's very easy to separate in our project so Claude gets the other parts and is very helpful.
If your work was truly novel, wouldn't the odds of it showing up in later models be extremely low given that these are probabilistic?
In a sense these machines are outputting the aggregate of the collective thoughts of the commons. In order for concepts to be output they have to be quite common in the training data. Which works out kind of nice for privacy and innovation because by the time concepts are common enough to show up through inference they probably deserve to be part of the public knowledge (IP aside).
They might optimize learning to weight novel/unexpected parts more in the future. The better the models become (the more the expect) the more value they will get from unexpected/new ideas.
A lot of people doing cat-and-mouse threat detection development are keeping their work outside of public LLMs right now, so it sounds like you’re in the same boat as a lot of us.
This perfectly describes one of the biggest dillema with AI. Where does an AI company stop to utilize human knowledge it does not actually own. Where do they draw the line. Apparently it's possible there aren't any lines drawn at all.
If you talk to a human they're free to discuss your ideas with someone else. Why should LLMs be any different? The likelihood of these models reproducing your ideas word for word is essentially zero anyway.
More to the point, respecting your wishes to keep those conversations confidential would risk stifling human progress, so they have to be disregarded for the greater good.
Not a surprise. All the major players have reached the limits of training on existing data—they’re already training on essentially the whole internet plus a bunch of content they allegedly stole (hence various lawsuits). There haven’t been any major breakthroughs in model architecture from the major players recently and thus they’re now in a battle for more data to train on. They need data, and they want YOUR data, now, and are gonna do increasingly shady things to get it.
> They need data, and they want YOUR data, now, and are gonna do increasingly shady things to get it.
But unlike the 100s of data brokers that also want your data, they have an existing operational funnel of your data already that you voluntary give them every day. All they need is dark pattern ToS changes and manage the minor PR issue. People will forget about this in a week.
Seems hard to believe legal teams at corporations are going to forget this in a week. I've always assumed the market play for these companies was spinning off an "Amazon basics" version of other companies software, this seems like another step towards that.
To AI companies, data is even more of a gold mine than to adtech companies. It is existentially important.
The truly evil behavior will emerge at the intersection of these two industries. I'm sure Google and Facebook are already using data from one to power the other, even if it's currently behind closed doors. I can hardly wait for the use cases these geniuses will think of once this is publicly acceptable and in widespread use by all companies.
> It's nice to see the newer models are suffering after being exposed to training on their own slop.
I've seen zero evidence anything of the such is occurring, and that if it was, it's due to what you claim. I'd be highly interested in research suggesting both or either is occurring however.
Everyone seems to be unsurprised by this move, but I’m genuinely shocked. What a shoot your own foot business decision. Google, evil though it be, doesn’t post the text of your gmails in its search results because who would consider using Gmail after that? This is the llm equivalent. Am I missing something?
Google mines the bejeezus out of your email, and uses it to any number of ends, including manipulating you into buying things, and also passing your correspondence on to the US government. While this is not the same as outright making your emails universally searchable - training Claude on your emails is also not the same as posting their contents.
And - this behavior of Google's has not been penalized, I'm afraid.
"Enterprise and educational customers will continue operating under their existing privacy protections, as the policy changes specifically exclude Claude for Work and Claude for Education services. These commercial accounts remain governed by separate contractual agreements that maintain stricter data handling standards.
Organizations using Claude through business partnerships or educational licenses can continue their operations without concern for the new training policies affecting their sensitive communications or proprietary information."
Thus, I think your claim
> What a shoot your own foot business decision.
likely does not hold: the non-commercial accounts likely led to Anthropic loosing money, so they are not liked by Anthropic anyway (but are a an "inconvenient necessity" to get people to notice and try out your product offering). With this new decision, Anthropic makes this "free-riding" less attractive.
I bet that Anthropic will soon release a press statement (that exists in the drawers for quite a long time) "We are listening to your concerns, and will thus extend our 'privacy-conscious offering' to new groups of customers. Only 30 $ per month."
> With this new decision, Anthropic makes this "free-riding" less attractive
Certainly not for any users like you and me, it takes two seconds and three clicks to review the new terms and decline chat training. This is more like Anthropic getting easy training from people who are unaware or don't care.
Ok, to be clear, let’s say I’m dumb and accidentally go with the default (I get the color of the opt out button wrong or something). As if there’s a “publish my private emails to the internet” default-on button in email. Then, I use it to edit a rec letter for student X, with my signature Y. (Yes I know this is dumb and I try changing names when editing but am sure some actual names may slip through.) A few months later the next model is released trained on the data. Student X asks Claude what Y would write in a rec letter about X. Such a button is a “wings stay on / wings fall off” button on a plane.
The LLM equivalent is what Google does do, which is train its spam filters on the contents of your emails coupled to the signal of what human beings flag as spam.
(It was one of the first significant value-adds of GMail: at its scale, Google could create a global-concept understanding of the content and pattern of spam across hundreds of millions of users. That was the kind of Big Data that made it possible to build filters where one could confidently say "This is tuned on all spam in the wild, because we've seen all spam in the wild").
TBH I’m surprised it’s taken them this long to change their mind on this, because I find it incredibly frustrating to know that current gen agentic coding systems are incapable of actually learning anything from their interactions with me - especially when they make the same stupid mistakes over and over.
Okay they're not going to be learning in real time. Its not like you're getting your data stolen and then getting something out of it - you're not. What you're talking about is context.
Data gathered for training still has to be used in training, i.e. a new model that, presumably, takes months to develop and train.
Not to mention your drop-in-the-bucket contribution will have next to no influence in the next model. It won't catch things specific to YOUR workflow, just common stuff across many users.
> Not to mention your drop-in-the-bucket contribution will have next to no influence in the next model. It won't catch things specific to YOUR workflow, just common stuff across many users.
I wonder about this. In the future, if I correct Claude when it makes fundamental mistakes about some topic like an exotic programming language, wouldn't those corrections be very valuable? It seems like it should consider the signal to noise ratio in these cases (where there are few external resources for it to mine) to be quite high and factor that in during its next training cycle.
It's actually pretty clever (albeit shitty/borderline evil), start off by saying you're different by the competitors because you care a lot about privacy and safety, and that's why you're charging higher prices than the rest. Then, once you have a solid user-base, slowly turn on the heat, step-by-step, so you end up with higher prices yet same benefits as the competitors.
I guess I'll take the other side of what most are arguing in this thread.
Isn't it a great thing for to us to collectively allow LLM's to train on past conversations? LLM's probably won't get significantly better without this data.
That said I do recognize the risk of only a handful of companies being responsible for something as important as the collective knowledge of civilization.
Is the long term solution self custody? Organizations or individuals may use and train models locally in order to protect and distribute their learnings internally. Of course costs have to come down a ridiculous amount for this to be feasible.
> That said I do recognize the risk of only a handful of companies being responsible for something as important as the collective knowledge of civilization.
It's not just the risk of irresponsible behaviour (which is extremely important in a situation with so much power imbalance)
It's also just the basic properties of monopolistic markets: the smaller the number of producers, the closer the equilibrium price of the good maximizes the producers' economic surplus.
These companies operate for-profit in a market, and so they will naturally trend toward capturing as much value as they can, at the expense of everyone else.
If every business in the world depends on AI, this effectively becomes a tax on all business activity.
This is obviously not in the collective interest.
Of course, this analysis makes simplifying assumptions about the oligopoly. The reality is much worse: the whole system creates an inherent information asymmetry. Try and imagine what the "optimal" pricing strategy is for a product where the producer knows intimate details about every consumer.
> LLM's probably won't get significantly better without this data.
Yeah and Facebook couldn't scale without ignoring the harms it causes people. Should we just let that be? Society seems to think so but I don't think it's a good idea at all.
Excellent. What were they waiting for up to now?? I thought they already trained on my data. I assume they train, even hope that they train, even when they say they don't. People that want to be data privacy maximalists - fine, don't use their data. But there are people out there (myself) that are on the opposite end of the spectrum, and we are mostly ignored by the companies. Companies just assume people only ever want to deny them their data.
It annoys me greatly, that I have no tick box on Google to tell them "go and adapt models I use on my Gmail, Photos, Maps etc." I don't want Google to ever be mistaken where I live - I have told them 100 times already.
This idea that "no one wants to share their data" is just assumed, and permeates everything. Like soft-ball interviews that a popular science communicator did with DeepMind folks working in medicine: every question was prefixed by litany of caveats that were all about 1) assumed aversion of people to sharing their data 2) horrors and disasters that are to befall us should we share the data. I have not suffered any horrors. I'm not aware of any major disasters. I'm aware of major advances in medicine in my lifetime. Ultimately the process does involve controlled data collection and experimentation. Looks a good deal to me tbh. I go out of my way to tick all the NHS boxes too, to "use my data as you see fit". It's an uphill struggle. The defaults are always "deny everything". Tick boxes never go away, there is no master checkbox "use any and all of my data and never ask me again" to tick.
I think I'd have more understanding for this position if I thought that these companies were still fundamentally interested in serving their users. They are not. Any information you provide is more likely to be used against your interests (even if that's "just" targeting you with some ads for a scammy product) than for your benefit.
Basically all AI companies are fruit from the same VC-poisoned tree and I expect these products will get worse and more user-hostile as they try to monetize. We're currently living in the "MoviePass"[1] era of AI where users are being heavily subsidized to try to gain market share. It will not last and the potential for abuse is enormous.
Whether Google is interested in serving me or not, is not only untestable (i.e. what counts as 'Google', 'interested', and 'serving' there - one could argue to end of time) - but besides the point. I want to be able to tell Google "My home is XYZ", and for Google to use that information about me in all of Google ecosystem. When I talk to Gemini it should know what/where "LJ home" is, when I write in Gdoc it should know my home address (so to insert it if I want it), ditto for Gmail, when I search in Google photos "photos taken at home" it should also know what "home" is for me.
Atm Google vaguely knows, and uses that for Ads targeting, sometimes. Most of the time - the targeting is bad, very low quality slop. To the level of "he bought a mattress yesterday, will keep buying mattresses in the next 30-60 days". I have the impression that we ended up in the worst case scenario. People I don't want to have my data, have access to it. People I do want to have my data, are afraid to touch it, and use it - yes! - for theirs, but also for my benefit too. The current predicament seems to me the case of "public lies, private truths."
A small cadre of vocal proponents of a particular view, established "the ground truth to what is desirable". (in this case - maximum privacy, ideally zero information sharing) The public goes with it in words, pays lip service, while in deeds, the revealed preferences show, they value their data privacy very cheaply, almost zero. Even one click extra, to share their data less, is one click too many, effort too high, for most people. Again - these are revealed preferences, for people keep lying when asked. It's not even the case of "you are lying to me" - no, it's more like "you are lying to yourself."
The conventional opinion is that the power imbalance coming from the information imbalance (state/business know a lot about me; I know little about them) is that us citizens and consumers should reduce our "information surface" towards them. And address the imbalance that way. But. There exists another, often unmentioned option. And that option is for state/business to open up, to increase their "information surface" towards us, their citizens/consumers. That will also achieve information (and one hopes power) rebalance. Yes there is extra work on part of state/business to open their data to us. But it's worth it. The more advanced the society, the more coordination it needs to achieve the right cooperation-competition balance in the interactions between ever greater numbers of people. There is an old book "Data For the People" by an early AI pioneer and Amazon CTO Andreas Weigend. Afaics it well describes the world we live in, and also are likely to live even more in the future.
It makes sense when you see it as indoctrination than a mere opinion. Quashing critical thinking is the point. How else can you convince people to work against their own interests?
It's not a satire, you can check mu comments on this topic easily.
I dispute 'most people'. Revealed preferences of most people are that they value their data privacy very cheaply, almost zero. Even one click extra to share their data less, is one click too many, an effort too high - for most people. This is their real, observed behaviour. I think our current predicament is the case of "public lies, private truths." A small cadre of vocal proponents of a particular view, established "the ground truth to what is desirable". (in this case - maximum privacy, ideally zero information sharing) The public goes with it in words, pays lip service - but in reality behaves different, even opposite to what they say they desire.
And even if 'most people' wanted what you say they do, I still think the companies could and should accommodate a minority group like myself that want otherwise to what 'most people' want. I don't think the will of the majority is the highest ideal, so high as to trump what I personally want.
I already share lots of my data with Google. I have Gmail where a lot of my online life is reflected. I have Photos, Gmaps, Gdrive. Also Google knows about my YouTube viewing, my Android phone use. So no matter what I say - with my actions, my revealed preference is - that I trust Google. So far - Google have not betrayed my trust, afaics. So I actually want for Google to adapt Gemini to me, either via the context, or even with a thin layer of LoRA. If Google treats me like a complete stranger it knows nothing about, then Google, and plenty of other people, make use of my data, but I, the creator (and nominal owner) of my data - don't benefit from their knowledge of me?? That sounds the worst of the possible options to me.
This may very well be a rational stance, but either way, wish one could somehow teleport this sentiment to the Cypherpunk mailing list in the 80s/90s. Of all the things they projected, concocted, fought for.. Nothing could truly prepare them for this kind of thing: the final victory of the product over the people, the happy acceptance of surveillance. They were all imagining terrible dystopias garnered from state violence and repression, never could they begin to imagine it could all transpire anyway because people like not having to type their address in!
> The angel would like to stay, awaken the dead, and make whole what has been smashed. But a storm is blowing from Paradise; it has got caught in his wings with such violence that the angel can no longer close them. The storm irresistibly propels him into the future to which his back is turned, while the pile of debris before him grows skyward. This storm is what we call progress.
Well Yes and No. Funny you mention the 80s/90s. I grew up in the pre-Internet world. I remember home computers, then PC-s, then modems to access BBS-es, then FIDO, uucp email, academic Internet and then the private commercial Internet after 1990. Some parts of the privacy agenda I'm strongly pro-privacy, the more the better. I don't want encryption broken. The UK gov (I live in the UK) are being morons for that, forever trying that play. Atm there is at least part of the US admin to push back on that. I don't like UK Parliament forcing the online ID on me. I'm pro- having private citizens having private keys on un-snoop-able dongle devices.
Do you lock your front door, or use passwords on any of your accounts? Because what you're essentially saying is that you're OK with strangers having access to your personal information. That's beyond the already flawed "I have nothing to hide" argument.
I would far prefer the service use my data to work better and take a few privacy risks.
People die all the time from cancer or car accidents. People very rarely die from data leaks.
Some countries like Sweden make people's private financial data public information - and yet their people seem happier than ever. Perhaps privacy isn't as important as we think for a good society.
I'm worried, it's not like I don't care. For example, I'm worried that Google is such a huge ginormous target, that at some point their Gmail will be broken. At the same time, there are benefits to sharing data. There are benefits to me, in Google using the information it has on my, to make my life easier. In this case, I judge that Gemini using my data to train, is a low extra risk for me. Compared to all other risks I take, for doing things in public. Including writing this on public forums, as you do too.
In general, I find the ongoing public scare about sharing data, to be anti-thesis to the original spirit of the Net, that was all about sharing data. Originally, we were delighted to connect to perfect strangers on the other side of the world. That we would never have gotten to communicate with otherwise. I accept there might have been an element of self-selection there, that aided that view: people one'd communicate with, although maybe from a different culture, would be from similar niche sub-culture of people messing with computers and looking forward to communication, having a favourable view of that.
If they leaked bank accounts numbers, or private keys - I would be worried. That has not happened in the past.
About myself personally - my Name Surname is googleable, I'm on the open electoral register, so my address is not a secret, my company information is also open in the companies register, I have a a personal website I have put up willingly and share information about myself there. Training models on my data doesn't seem riskier than that.
Yeah, I know I'd be safer if I was completely dark, opaque to the world. I like the openness though. I also think my life has been enriched in infinitely many ways by people sharing parts of their lives via their data with me. So it would be mildly sociopathic of me, if I didn't do similar back to the world, to some extent.
You can train commercial AI with your data right now without screwing over everyone else on the planet. It's easy, just publish your entire trove of personal data on a website and AI crawlers will happily gobble it all up. You can publish your name, home address, work, government-issued ID, financial transactions, chats, browser history, location history, surveillance footage of your home, all for free. So what are you waiting for? Just do it now if you want to share data that badly, there's no need to wait for the approval of "privacy maximalists."
I'm not 'screwing' anyone. I'm saying - the same way people don't want to have their data used, I DO want my data used. I'm not saying they use YOUR data. I'm saying they use MY data.
Likewise, I'm not telling you what you publish. In the same manner, I dislike it you telling me that I publish. So on
> name, home address, work, government-issued ID, financial transactions, chats, browser history, location history, surveillance footage of your home, all for free.
It's up to me, not you, what I decided to publish or not. Fwiw, I already publish
> name, home address, work,
willingly. My name is public (how can it be otherwise?) and home address is in the electoral register that is public. My work info is in the UK companies register, available for reading to all, on the web
I publish to selected parties
> government-issued ID
even if I don't want it. (we don't have specific 'government-issued ID' for ID purposes like in the Continent; my driving licence is used for that) I did it yesterday, because UK gov requires companies to collect that information. Yesterday I had to give two photos of myself to an online pharmacy shop because UK gov mandates that they collect that info - and I disliked that very much. The online pharmacy is not the one pushing for that data, its the UK gov forcing that one them via regulation of how that particular medication is to be sold online.
I don't want to publish and don't publish
> financial transactions, chats, browser history, location history, surveillance footage of your home
...and don't understand where this gale to tell perfect strangers what they should do with their lives comes from?? I don't tell you what you should or should not publish? Ditto for the pricing
> all for free.
Up to me to decide. I don't tell you what you do - so you don't tell me what I do, pretty please.
I am not waiting on "privacy maximalists." I try to share my data for some purpose I need. I loathe 'privacy maximalist' in the UK for having influenced the current laws of the land in a way to cater for their obsessions and ignore my desires. I think I'm in majority, not minority. Our current predicament seems to me the case of "public lies, private truths." A small cadre of vocal proponents of a particular view, established "the ground truth to what is desirable". (in this case - maximum privacy, ideally zero information sharing) The public goes with it in words, pays lip service, while in deeds, the revealed preferences show that we value our data privacy very little - almost zero. Even one click extra to share our data less, is one click too many, an effort too high for most people. Again - these are revealed preferences, for people keep lying when asked. It's not even the case of "you are lying to me" - no, it's more like "you are lying to yourself."
Oh boy. Did you somehow miss all the news about data leaks and password dumps etc. being sold on the "dark" web and shit?
Would you mind if I followed you around and noted everything you do and constantly demanded your attention?
The shit done by corporations is akin to a clingy stalker and would be absolutely despised if it was an individual person doing something like that.
As for benefits, which?? In my entire life I have never seen an ad for anything (that I did not already know about via other means) that made me want to look up the product, let alone buy it. Nor do I know anyone who did. In fact, it turns me off from a product if its ad appears too frequently.
Google etc. and various storefronts also almost never recommend me anything that actually matches my interests, beyond just a shallow word similarity, in fact they forcibly shove completely unrelated shit into my searches cause they were paid to. Like searching for RPGs and seeing Candy f'ing Crush.
----
You know what though, I kinda agree with the potential intent behind your charade:
Yes, LET ME TELL YOU ABOUT ME.
I will gladly TELL companies EXACTLY what I like, and I WANT you to use that. Show me other shit that is actually relevant to MY interests instead of the interests of whomever paid you to shove their shit into my face.
ASK! DON'T SPY! Because you can't ever get it right anyway!
> But there are people out there (myself) that are on the opposite end of the spectrum, and we are mostly ignored by the companies. Companies just assume people only ever want to deny them their data.
What? I think you're exactly the kind of person that companies pay attention to, and why they pull moves like this
Google knows what "Home" is for me only in Gmaps, because I went out of my way (put a Label etc) to tell it. I want to be able to tell Google "My home is XYZ", and for Google to use that information about me in all of Google ecosystem. When I talk to Gemini it should know what/where "LJ home" is, when I write in Gdoc it should know my home address (so to insert it if I want it), ditto for Gmail, when I search in Google photos "photos taken at home" it should also know what "home" is for me.
I have the impression that we ended up in the worst case scenario. People I don't want to have my data, have access to it. People I do want to have my data, are afraid to touch it, and use it - yes! - for theirs, but also for my benefit too.
You should read up on the Dutch Civil Registry and the holocaust in the Netherlands and reevaluate if you are serious. I would love to live in a world where everyone had good intentions and the powers that be wouldn’t abuse data to their ends, we will never live in that world.
I don't think you understand how...humanity works?! Is this deliberate parody?
Abuse of medical data is just the tip of the iceberg here and, at least in the states, privatized healthcare presents all sorts of for-profit pricing abuse scenarios let alone nasty scenarios for social coercion.
You know little about me, so it's better to assume less, no? My personal experience with medical data specifically is, that I would have been harmed by obstacles to data sharing that the UK medical system has in place, having not been familiar with computers and tech enough to anticipate the ways lack of data sharing will lead to outcomes undesirable to me. I wrote about that in a comment here https://news.ycombinator.com/item?id=45067219
That’s unfortunate. I believed Anthropic was playing the long game and betting on a smaller but more technically proficient userbase.
I guess I’ll be canceling my subscription largely out of principal. I doubt any open-source models are capable of handling my use case as well as Claude (typically focused on getting up to speed with various ISO/IEEE standards for the purpose of security testing) but I’m sure I’ll find a solution.
This is all you can do. Laws and regulations will not be forthcoming, and even if some are, they will be ignored or the fines paid as a cost of doing business.
Any data you give to any website or app is no longer (exclusively) yours. Use these services under that assumption.
Why are we linking to Perplexity.ai AI-generated slop summaries of other news articles instead of the actual announcement? Reading the actual announcement is more clear : https://www.anthropic.com/news/updates-to-our-consumer-terms Some important points:
An in-app notification pop-up will alert you to the change. You can opt out in the pop up.
I was able to opt out right now by going to the Privacy section of Settings.
It doesn’t take effect until September 28th. The app will apparently prompt people to review the new terms and make a decision before then.
Only applies to new or resumed sessions if you do review the new terms and don’t turn it off. The angry comments about collecting data from customers and then later using it without permission are not correct. You would have to accept the new terms and resume an old session for it to be used.
Does not apply to API use, 3rd party services, or products like Claude Gov or Claude for Education.
Changing the link to the actual source instead of this perplexity.ai link would be far more helpful.
As long as you can opt-out it doesn't bother me much. Though it does make me wonder those third party clients that people subscribe to e.g. JetBrains AI, Zed, and others that use Claude and other Anthropic models, do they opt-in for you? Because that would be bad.
I would strongly argue that API clients should NEVER be opted in for these sorts of things, and it should be like this industry wide.
> They do not apply to services under our Commercial Terms, including Claude for Work, Claude Gov, Claude for Education, or API use, including via third parties such as Amazon Bedrock and Google Cloud’s Vertex AI.
> An in-app notification pop-up will alert you to the change. You can opt out in the pop up.
The in-app notification that I got was a pop up which contained some buttons and some images. There was no text. Just in case it was some dark mode issue I checked the DOM and I couldn't find any text there either. I just clicked outside the modal and it went away. I assumed it was some announcement about some new feature and ignored it.
I did end up seeing the news yesterday in Reddit (I'm having issues getting the research tool to actually being used, tried to see if there was some recent changes) but it's unlikely that I was the only one who experienced modal the issue & if those didn't follow the tech news they could easily miss the change.
My comment doesn’t make sense but it’s too late to edit. To clarify: The original link was to a perplexity.ai summary of multiple news articles about the change. The mods have changed it now.
The comments here were from people jumping to co conclusions after skimming an AI summary of news articles about the link. I’m glad it got changed.
In my opinion, training models on user data without their real consent (real consent = e.g. the user must sign a contract or so, so he's definitely aware), should be considered a serious criminal offense.
Why single out user data specifically? Most of the data Anthropic and co train on was just scooped up from wherever with zero consent, not even the courtesy of a buried TOS clause, and their users were always implicitly fine with that. Forgive me for not having much sympathy when the users end up reaping what they've sown.
Publishing something is considered by most to be sufficient consent for it to be not considered private.
I realize there's a whole legal quagmire here involved with intellectual "property" and what counts as "derivative work", but that's a whole separate (and dubiously useful) part of the law.
Training on private user interactions is a privacy violation; training on public, published texts is (some argue) an intellectual property violation. They're very different kinds of moral rights.
I think it's cute people believe companies that trained their models with every single book and online page ever written without consents from authors (and often against the explicit request of the author without any opt-out) won't do a rugg-pull and do it also to all the chats they have aquired...
You're absolutely right, but also isn't the volume of new data they are getting from chats tiny compared to what they've already trained on? I'm wondering how much difference it will really make.
It’s quite clear. It’s easy to opt out. They’re making everyone go through it.
It doesn’t reach your threshold of having everyone sign a contract or something, but then again no other online service makes people sign contracts.
> should be considered a serious criminal offense.
On what grounds? They’re showing people the terms. It’s clear enough. People have to accept the terms. We’ve all been accepting terms for software and signing up for things online for decades.
People have T&C and cookie popup fatigue. I almost hit "accept" before noticing the opt out toggle, thinking it was a simple T&C update. This is definitely a fucked up way to set it up, there's no sugar coating it.
Why? This is not 'use collected information to targed ads', or 'sell collected information to third parties', but 'use collected information from the service to improve the service'. Does not really seems to me much different than ISPs using traffic stats to plan infrastructure improvements, or a website using access logs to improve accessibility and navigation.
And when talking specifically about AI, one could argue that learning from interactions is a common aspect of intelligence, so a casual user who do not understand details about LLMs would expect so anyways. Also, the fact that LLMs (and other neural networks) have distinct training and inference phases seems more like an implementation detail.
I believe that only concerns European users. Moreover, I believe a simple press of an OK button is fine with GDPR. This data (type and volume) however, is way more serious and can't be agreed on by just pressing a button.
Does this include any code base you are running Claude Code with (where parts of code are sent as part of the context)? I'm not hugely clear on how my private codebase is exposed to Claude in the first place when using Claude Code.
Agree. Out of the available paid cloud providers, I only chose to work with Claude Code because of the data privacy policy. This isn’t a welcome move but still usable. Thankfully the open source models are not far behind with Qwen 3 coder etc.
I didn't trust them much to begin with, so I generally avoid talking too much personal stuff with Claude. But I had plenty of chats with surface level discussion of topics I'm interested in and some of my relevant experience and history with those topics. So, I have deleted all my chats and am closing my Claude account (as soon as customer services get back to me; somehow the self-serve option is missing for my account, possibly because I once enabled API access).
I'll use Claude with my employer's Copilot account, but was I wasn't putting anything personal there anyway.
In the late 00s a few friends sent me “connect with me on Facebook” messages. I thought “this looks suspicious, I don’t want to, but it seems all my friends are communicsting here now…”. So I joined, and in 10years everything I worried could happen with FB did, and much much worse.
I saw the popup yesterday. Maybe I've just gotten really good at navigating dark patterns (or I have stock-home syndrome), but I remember the opt out choice being really clear and easy to select.
I'm not arguing on the facts of the modal design, I don't remember either way, I just don't remember it being confusing.
And there's no way to opt-out of the training, without agreeing to the 5 year retention. Anthropic has slipped so far and fast from its objective of being the ethical AI company.
My work just signed to an enterprise agreement with anthropic. I just checked, and "Your data will not be trained on or used to improve the product. Code is stored to personalize your experience. Applies to all team members."
We should be able to train on foundation model outputs.
These bastard companies pirated the world's data, then they train on our personal data. But they have the gall to say we can't save their model's inputs and outputs and distill their models.
I am pretty sure they try to do it all the time between themselves. Most of the real sauce in AI coding comes from reinforcement learning, usually done by armies of third world outsourced developers tediously doing all kinds of tasks with instructions to detail their reasoning behind each chance. Things like: "to run this python test in a docker container with the python image we need to install the python package xyz, but then, as it has some native code, we also need to install build-essential..."
While those developers are not well paid (usually around 30/40 USD hour, no benefits), you need a lot of then, so, it is a big temptation to create also as much synthetic data sets from your more capable competitor.
Given the fact that AI companies have this Jihad zeal to achieve their goals no matter what (like, fuck copyright, fuck the environment, etc, etc), it would be naive to believe they don't at least try to do it.
And even if they don't do it directly, their outsourced developers will do it indirectly by using AI to help with their tasks.
I think there is amazing signal inside the chat logs. Every idea or decision taken can be analyzed in hindsight 20 messages later, or days later. Eventually a feedback signal or outcome lands back in the chat logs. That is real world idea validation. Considering the hundreds of millions of users and their diverse tasks that collect across time - this is probably the most efficient way to improve AI. I coined it the human-AI experience flywheel.
To make it respect user privacy I would use this data for training preference models, and those preference models used to finetune the base model. So the base model never sees particular user data, instead it learns to spot good and bad approaches from feedback experience. It might be also an answer to "who would write new things online if AI can just replicate it?" - the experience of human-AI work can be recycled directly through the AI model. Maybe it will speed up progress, amplifying both exploration of problems and exploitation of good ideas.
Considering OpenAI has 700M users, and worldwide there are probably over 1B users, they generate probably over 1 trillion tokens per day. Those collect in 2 places - in chat logs, for new models, and in human brains. We ingest a trillion AI tokens a day, changing how we think and work.
I just opted out. And then canceled my plan. The 5 year retention isn't part of the opt out and represents way too juicy of a target for them. Some time in the next 5 years another TOS change will happen, and another and another and eventually there won't be an opt out or I won't realize it and accidentally click yes. Privacy first. Period. Pay me to opt in and I may consider it.
What a surprise, a big corp collected large amount of personal data under some promises, and now reveals actually they will exploit it in completely unrelated manner.
The are valued at $170 Billion. Not quite the same as, but in same order of magnitude as OpenAI - while having only a single digit percent fraction of active users. They probably need to prepare for the eventual user data sellout, as it is becoming increasingly more obvious that none of the big players has a real and persistent tech leadership anymore. But millions and millions of users sharing their deepest thoughts and personal problems is gonna be worth infinitely more than all the average bot bullshit written on social media. That's also why Zuck is so incredibly desperate to get into the game. It's not about owning AI. It's about owning the world's thoughts and attention.
Anthropic enterprise share is pretty significant - on order of 30%. I think at this time it's pretty significant.
I am expecting AI companies to start using ads, it's inevitable as they need to make money at some point and $20 a month won't do it.
For ads the number of users is the main thing - the more users you have the bigger the market and more money you could earn. Google desperately needs to be in this space, that's why they are throwing a ton of money on AI.
There is far more money to be made building atop this data than selling this data. Your opening statement seems to disagree with your closing statement.
The data is no where near valuable enough without a new high value surface to use it, and so far chat is not it.
Merely selling data is extremely low value compared to also having the surface monopoly to monetize it in a very high engagement and decisioning space.
I feel like you don’t understand the fundamental mechanics of the ad world. Ultimately, the big 4 own such immense decisions surface area it may be a while before any AI model company can create a product the get there.
The last time my brother and I were discussing about anthropic, they were worth 90B$, and that was a month ago, he asked chatgpt in the middle of the conversation, either it was a sneaky sabotage from gpt or my memory is fuzzy but I thought that 90b$ was really underrated for anthropic given the scaleAi deal or windsurf/cursor deals.
> If you’re an existing user, you have until September 28, 2025 to accept the updated Consumer Terms and make your decision. If you choose to accept the new policies now, they will go into effect immediately. These updates will apply only to new or resumed chats and coding sessions. After September 28, you’ll need to make your selection on the model training setting in order to continue using Claude. You can change your choice in your Privacy Settings at any time.
Doesn’t say clearly it applies to all the prompts from the past.
If someone had told me 10 years ago that the typical HN front page in 2025 will look like this (and that #8 may be the UK), I'd never have believed it. And I worry we still have further to go before hitting bottom.
1. Anthropic reverses privacy stance, will train on Claude chats
3. Gun Maker Sig Sauer Citing National Security to Keep Documents from Public
4. Tesla said it didn't have key data in a fatal crash. Then a hacker found it
6. Meta might be secretly scanning your phone's camera roll
7. If you have a Claude account, they're going to train on your data moving forward
8. Ask HN: The government of my country blocked VPN access. What should I use?
> If someone had told me 10 years ago that the typical HN front page in 2025 will look like
It has always been like this. Sites like Reddit, HN, and Digg and Boing Boing (when they were more popular) have always had a lot of stories under the category of online rights, privacy, and anger at big companies.
The Perplexity report is vibe-written and an excellent example that "AI" is entirely unreliable. At the time I am making this comment, it states:
"Anthropic also reported discovering North Korean operatives using Claude to fraudulently obtain remote employment positions at Fortune 500 technology companies, leveraging the AI to pass technical interviews and maintain positions despite lacking basic coding skills."
Note that in this version the North Koreans lack basic coding skills, which took me by surprise. Generally they are assumed to be highly competent.
"Our Threat Intelligence report discusses several recent examples of Claude being misused, including a large-scale extortion operation using Claude Code, a fraudulent employment scheme from North Korea, and the sale of AI-generated ransomware by a cybercriminal with only basic coding skills. We also cover the steps we’ve taken to detect and counter these abuses."
This is what people are using for web search. I'm not targeting Perplexity specifically, Google "AI" summaries are just as bad.
"The most striking finding is the actors’ complete
dependency on AI to function in technical roles. These
operators do not appear to be able to write code, debug
problems, or even communicate professionally without
Claude’s assistance. Yet they’re successfully maintaining
employment at Fortune 500 companies (according to
public reporting) passing technical interviews, and
delivering work that satisfies their employers. This
represents a new paradigm where technical competence
is simulated rather than possessed."
This should be distributed among managers so that they finally get the truth about "AI".
So far, no one in this thread seems surprised (or is admitting to it). But I genuinely would like to know if someone is surprised. I’d also like to know what lead you to believe this wouldn’t happen and if there’s anyone in the LLM space you’d trust to not pull the same stunt (and why do you still believe that).
I genuinely want to know and would like to have a productive conversation. I would like to identify what made people trust them and not realise they’re the same as every other.
There is nothing surprising at all? It's not rocket science to understand that Anthropic is a very greedy company – just by analysing their sales funnel/UX you can tell that money is all they ever care about. Their marketing teams will go for any tricks to gain direct access to your pockets.
In the LLM space no other company is different – they are highly unprofitable – so once funding starts to run dry they will have the pressure to invent new ways for going even deeper into your pockets.
I believe it shouldn't happen. I'm not surprised. There is no web company (LLM or otherwise) I trust completely, let alone any of the major ad-funded ones, or the ones who are not yet profitable and desperately searching for ways to become so.
A lot of people hold Anthropic as the "clean and ethical" AI company. They're not power hungry, they are focused on safety. Their aesthetic is cool modern valley vibes. Well grounded and in touch. They don't have the stench of Altman or the ominous presence of the tech giants. They make claude code which is the darling LLM of pure souled silicon valley.
That is an interesting claim. What makes you believe that? And does this announcement shake that belief in any way?
> Their aesthetic is cool modern valley vibes.
Does looking cool equal being trustworthy? Doesn’t feel like it should. On the contrary, from observation on HN it seems the websites which look pretty bare bones (none from an LLM company) tend to be perceived as more trustworthy (i.e. “this hacker cares about The Thing™, not trying to sell you a product”).
The AI fever dream of unbounded training and inference is ending and reality is settling in. Anthropic has had the most reasonable business model of the AI players with their focus on code, as far as I can tell, but it still won't be enough.
There's no such thing as a free lunch, but even when I am a paying customer my data is taken as gratuity and used (+ spread around!) in extremely opaque ways. I am tired of it. Honestly, I'm just getting tired of the internet.
I didn't claim they are profitable. There are endless articles about how it is not and may never be. But compared to the burn of OpenAI, xAI, Meta, Google, etc, it is burning billions less and focusing on a niche with demonstrated use cases and customers.
What if the first layer (or couple layers) were processed locally on the users machine and then it goes to the provider to process the remaining layers.
You could also process the last layer on the users machine.
It’s hard to say what kind of privacy this gives users. I don’t think they could reverse out exactly what the input was.
Between this(I already opted out but) and their work with Palantir, I definitely am not going to increase my subscription. It is making me reconsider paying, even using, a technology I've found transformative, and I expected(okay hoped) better from Anthropic.
I’m proposing this, the ability to mark certain chats as non trainable. Like an incognito mode. If a chat is not marked as that after 5 days it can be retained for training.
And this is only for free users, paid users should never have to think about this.
We need that user data is only usable within the ToS under which they were originally collected. No more unilateral altering of the agreement after the fact.
Collecting user data should be a liability, not a enormously profitable endeavor.
I'm curious how the new terms compare to other companies offerings. Never spent the time to dig into the fine-print, so if anyone coincidentally has, I'd be very grateful for a summary.
How would they not "share information with third parties". You need to sift through the data to make it even remotely useful for "training". You absolutely need to share it with either Amazon (for Mechanical Turk) or with Scale AI.
I am wondering how would you use a chat transcript for training? Unless it is massive, possibly private codebases that are constantly getting piped into Claude Code right now. In that case, that would make sense.
I imagine you could probably get feedback on chat transcripts especially if they're doing lots of A/B testing with models.
But more importantly (to me) is storing 5 years worth of other company's IP. That just seems wildly risky for all parties unless I really don't understand how Claude Code works.
Feels like a lot of overreactions here amongst people who haven’t seen the pop up. The put the opt out front and center — it’s not buried at all. They make it very clear in the language, including commitments to data transparency. I’m not surprised they need to do this, and this is probably the best possible way to achieve it while balancing privacy.
Unfortunate, but frankly I didn't even know about them not training on user data.
Actually up until a few months ago I swore I just couldn't use these hosted models (I regularly use local inference but like most my local hardware yields only so much quality). Tech companies, nay many companies, will lie and cheat to squeeze out whatever they can. That includes reneging promises.
With data privacy specifically I always take the default stance that they are collecting from me. In order for me to use their product it has to be /exceedingly/ good to be worth the trade off.
Turns out that Claude Code is just that damn good. I started using it for my own personal project. But the impetus was the culmination of months questioning what kind of data I'd be okay with giving up to a hosted model.
What I'm trying to say is that this announcement doesn't bother me that much because I already went on my own philosophical odyssey to prepare for this breach of trust to occur.
So much this. I for one haven't opted out. I feel it's in our best interest to have better models. It would be ideal to be able to opt in/out per thread, but I don't expect most users to pay attention / be bothered with that.
In this aspect, it would've been great to give us an incentive – a discount, a donation on our behalf, plant a percent of a tree or just beg / ask nicely, explain what's in it for us.
Regarding privacy, our conversations are saved anyway, so if it would be a breach this wouldn't make much of a difference, would it?
My reasoning: I use AI for development work (Claude Code), and better models = fewer wasted tokens = less compute = less environmental impact. This isn't a privacy issue for work context.
I regularly run concurrent AI tasks for planning, coding, testing - easily hundreds of requests per session. If training on that interaction data helps future models be more efficient and accurate, everyone wins.
The real problem isn't privacy invasion - it's AI velocity dumping cognitive tax on human reviewers. I'd rather have models that learned from real usage patterns and got better at being precise on the first try, instead of confidently verbose slop that wastes reviewer time.
Can users poison the future training dataset by ending every chat with a dissatisfied feedback even though the chat helped them? Or be even more malicious and steer the chat into destructive behavior and then give very positive feedback?
I just canceled my Pro Plan yesterday because I don't find it to be a good value and I'm trying to rein in recurring charges. I really wish I'd been able to cite this development as a reason for why I was cancelling my plan.
Am I the only one who finds the branding and privacy policies around these AI services (possibly deliberately) confusing?
For example Anthropic have an Anthropic Console that they appear to consider quite distinct from Claude.ai. Do these share a privacy policy and related settings? How do either of these fit in with the named plans like Pro and Max? What are you actually paying for when you give them money for the various different things they charge for? Is all API use under their Commercial Terms even if it's a personal account that is otherwise under the Consumer Terms? Why isn't all of this obvious and transparent to users?
OpenAI don't seem to be any better. I only just learned from this HN discussion that they train on personal account conversations. As someone privacy-conscious who has used ChatGPT - even if only a few times for experiments - I find the fact that this wasn't very clearly stated up front to be extremely disturbing. If I'd known about it I would certainly have switched off the relevant setting immediately.
I get that these organisations have form for training on whatever they can get their hands on whether dubiously legal or not. But training on users' personal conversations or code feels like something that should require a very clear and explicit opt-in. In fact I don't see how they can legally not have that first in places like the EU and UK that have significant data protection legislation.
Generally if you are not paying full price for something (in this case paying API rates) you are covering the additional cost with your data. This is true for pretty much all modern services.
That's a very convenient way to rationalize behaviour that is intrusive and potentially dangerous that the people at risk almost certainly didn't ask for or meaningfully agree to.
GO to setting and under privacy you can change the default. (they make it pretty hard to find). Also note "To help us improve our AI models and safety protections, we’re extending data retention to 5 years."
I wanted to try it out so I bought a Pro subscription. No way to purchase through iOS so I had to enter my card number. I cancelled renewal and tried to remove my payment method as per usual practice, but I couldn't. Tried to find a way to get support but the send button on their chatbot box was disabled for me (on Safari if that matters). Regardless of the quality of the AI, that experience ticked me off enough to file a "F you" chargeback with my bank.
If I'm not paying for something, I presume this is the kind of thing that's happening, so this isn't newsworthy to me. Is it also applicable for paid and paid corporate accounts?
I'd bet this is related to their recent decision to boot people for being "abusive" to Claude. It now seems that was an attempt to keep their training data friendly.
This! Any LLM provider that monitors chat/api history for ‘abuse’ towards the model is considering using user data for training.
An Effective Altruism ethos provides moral/ethical cover for trampling individual privacy and property rights. Consider their recent decision to provide services for military projects.
As others have pointed out, Claude was trained using data expressly forbidden for commercial reuse.
The only feedback Anthropic will heed is financial and the impact must be large enough to destroy their investors willingness to cover the losses. This type of financial feedback can come from three places: termination of a large fraction of their b2b contracts, software devs organizing a persistent mass migration to an open source model for software development. Neither of these are likely to happen in the next 3 months. Finally, a mass filing of data deletion requests from California and EU residents and corporations that repeats every week.
Is there a summary of the stance on training with user data for the main llms ?
I have a really hard time thinking that Google, Microsoft, Meta, etc... would _not_ train on whatever people enter (willingly or not in the system.)
The silver lining is that what most people enter in a chat box is _utter crap_.
So, training on that would make the "Artificial Intelligence" system less and less intelligent - unless the devs find a way to automagically sort clever things from stupid things, in which case I want to buy _that_ product.
In the long run, LLMs dev are going to have to either:
* refrain from getting high on their own supply, and find a way to tag AI generated content
* or sort the bs from the truth, probably reinventing "trust in gatekeepers and favoring sources of truth with a track record" and copying social pressure, etc... until we have a "pulitzer price" and "academy awards" for most relevant AI sources with a higher sticker price, to separate from cheap slop.
That, or "2+2=7 because DeepChatGrokmini said so, and if you don't agree you're a terrorist, and if our AI math breaks your rocket it's your fault."
All models are trained on data obtained without consent. Now the “good guys of AI” want users to add their chats to the stack and the users balk? Hilarious.
This is disappointing. I thought Anthropic was a more privacy and safety focused company and so I had chosen to use Claude Code over their competition. Now they are less privacy focused than Gemini Code, which only does this for the free tier. My work was already providing GitHub Copilot but I was rooting for and supporting Anthropic. Now I'll either just use GitHub Copilot or Gemini Code both of which are still private for paid tiers.
It's obvious this was going to happen. If you ever used any cloud AI model without acknowledging that at some point your data might be leaked (in one way or another) it's on you, not on them.
As some other user put it: "big corp changes policy and breaks promises, how shocking"
I went to claude.ai and saw a pop-over window with this choice, clicked to opt out and saw a "server error" alert. Then went to Settings > Privacy and the option wasn't there. I had to click something else (can't remember now) to see the option, which wasn't opted out (which kinda made sense because of the error message) and the option is now in Settings > Privacy. I'm definitely someone who believes that cock-up is more likely than conspiracy for things like this, but this process should have been bulletproof - no initial error message, option always in Settings > Privacy - given the sensitivities involved.
Frankly I don't mind much if they use my js debugging conversation to train the next models; but there should be a way to mark specific conversations as private (possibly even an "incognito mode") to exclude them from any training or external access.
i found the ToS change to be surprisingly not a dark pattern.
in fact, i haven’t agreed to it yet, and was able to close the popup and continue using Claude. they also made it extremely clear how to opt out, providing the switch right in the popup and reminding me it’s also in settings.
when i eventually do have to agree to the ToS changes, i’ll probably just stay opted out.
It has a toggle for opting out, but the buttons available are "Accept" and "Not Now". So, if I toggle off but click "Accept", does that accept what I toggled or accept data sharing? If I click "Not Now", do they leave it set at the default Opt-in?
I clicked "Accept" because I didn't want to deal with it later, especially given the new terms, and Claude training on new chats and resuming existing chats from September 28th,
but the "Accept" and "Not Now" are for the new terms of use.
So by toggling off and clicking "Accept", it will accept the toggled version. You can check the setting after accepting it at: https://claude.ai/settings/data-privacy-controls It's the "Help Improve Claude" button.
Well, they've been using the whole internet and anything else they can get their hands on to train their models.
If you are using LLMs and want to continue seeing them get better and more useful, you really have to accept that they train on data collected from their users.
Unless there is another technology breakthrough somehow, this is going to be the best they can do to increase user satisfaction and make their product more useful.
TBH, I'd love to have a model which was specifically trained on conversation which I had with an earlier iteration. That would make it adapt to me and be less frustrating. Right now I'm relying only on instruction files to somewhat tune a model to my needs.
You can opt out, but the fact that it's opt-in by default and made to look like a simple T/C update prompt leaves a sour taste in my mouth. The five year retention period seems... excessive. I wonder if they've buried anything else objectionable in the new terms.
It was the kick in the pants I needed to cancel my subscription.
Everywhere else in Anthropic's interface, yes/no switches show blue when enabled and black when disabled. In the box they're showing about this change the slider shows grey in both states: visit it in preferences to see the difference! It's not just disappointing but also kind of sad that someone went to the effort to do this.
Just did and it behaves as expected for me in the Android app (ie. not the dark pattern you described)
3 replies →
It works correctly (blue on, grey off) in the iOS app. I just did it now.
This is probably because there are laws in some countries that restrict how these buttons/switches can look (think cookie banners, where sometimes there is a huge green button to accept, and a tiny greyed out text somewhere for the settings).
3 replies →
"five year retention". If it's in a model once, it's there forever.
yes, it’s a very big loophole. and if it’s a generative model, you can just launder the data through synthetic generation/distillation to future models
Is that true? Do models get rebuilt from scratch each time or do they get iterated on?
2 replies →
this is somewhat true but i'm not sure how load bearing it is. for one, i think it's going to be a while until 'we asked the model what bob said' is as admissible as the result of a database query
I got a pop-up when I opened the app explaining the change and an option to opt out. That seems very transparent to me.
> That seems very transparent to me
Implicit consent is not transparent and should be illegal in all situations. I can't tell you that unless you opt out, You have agreed to let me rent you apartment.
You can say analogy is not straightforward comparable but the overall idea is the same. If we enter a contract for me to fix your broken windows, I cannot extend it to do anything else in the house I see fit with Implicit consent.
3 replies →
> That seems very transparent to me.
Grabbing users during start up with the less privacy focused option preselected isn't being "very transparent"
They could have forced the user to make a choice or defaulted to not training on their content but they instead they just can't help themselves.
> seems very transparent
Except not:
> The interface design has drawn criticism from privacy advocates, as the large black "Accept" button is prominently displayed while the opt-out toggle appears in smaller text beneath. The toggle defaults to "On," meaning users who quickly click "Accept" without reading the details will automatically consent to data training.
Definitely happened to me as it was late/lazy.
Opt-in leads to very low adoption and is the moral choice.
Opt-out leads to very high adoption and is the immoral choice.
Guess which one companies adopt when not forced through legislation?
It’s not. And also whether you move the toggle to on or off, you still have to click accept which really isn’t clear whether you’re accepting to share your data or not.
Never mind the complete 180 on privacy.
It should be opt-in, not opt-out.
The fact that there's no law mandating opt-in only for data retention consent (or any anti-consumer "feature") is maddening at times
It should be off be default, with the option to opt in.
> You can opt out
You can say that you want to opt out. What Anthropic will decide to do with your declaration is a different question.
I look forward to this setting getting turned on again "accidentally" when new models are released or the ToS is updated.
I'm super duper sure that my data won't be stored and eventually used if i opt out
What will you use instead? I’m finding Claude the best experience since ChatGPT 5 is so slow and not any better answers than 4.
Granted, it is a stretch and not near the features of Claude (no code etc), but at least Proton's Lumo [0] is very privacy oriented.
I have to admit, I've used it a bit over the last days and still reactivated my Claude pro subscription today so... Let's say it's ok for casual stuff? Also useful for casual coding questions. So if you care about it, it's an option.
[0] https://lumo.proton.me/
If you aren't using it for coding or advanced uses like video, etc, you can try running models locally on your machine using Ollama and others like it.
Self plug here - If you aren't technical and still want to run models locally, you can try our App [1]
1] https://ai.nocommandline.com
Since I don't use LLMs to directly code for me, I'm going to (mis?)place my trust in Kagi assistant entirely for the time being. It claims not to associate prompts with individual accounts. Small friction of keeping a browser tab open is worth it for me for now.
>What will you use instead? I’m finding Claude the best experience since ChatGPT 5 is so slow and not any better answers than 4.
You could try programming with your own brain
1 reply →
https://grok.com
4 replies →
The 5 year is the real kicker. Over the next 5 years I find it doubtful that they won't keep modifying their TOS and presenting that opt out 'option' so that all it will take is one accidental click and they have all your data from the start. Also, what is to stop them from removing the opt out? Nothing says they have to give that option. 4 years and 364 days from now TOS change with no opt out and a retention increase to 10 years. By then the privacy decline will have already have been so huge nobody will even notice that this 'option' was never even real.
You can request your data to not be used. Your request will appropriately be read and redirected to /dev/null.
Settings > Privacy > Privacy Settings
i don't see any setting related to this? just:
Export data
Shared chats
Location metadata
Review and update terms and conditions
I'm in the EU, maybe that's helping me?
6 replies →
it's almost like this multi billion dollar company is misanthropic, despite their platitudes. Should I not hold my breath on Anthropic helping facilitate "an era of AI abundance for all"? (To quote a rejected PR applicant to Anthropic from the front page)
> It was the kick in the pants I needed to cancel my subscription.
As if barely two 9s of uptime wasn't enough.
I wonder what happens if I don't accept the new T&C? I've been successfully dismissing an updated T&C prompt in a popular group messaging application for years -- I lack the time and legal acumen to process it -- without issue.
Also, for others who want to opt-out, the toggle is in the T&C modal itself.
The new privacy policy automatically becomes effective on September 28, if you don’t already agree to it before. Anthropic states that “After September 28, you’ll need to make your selection on the model training setting in order to continue using Claude.”
I tried to do that with WhatsApp and it eventually stopped working.
Has anyone asked why OpenAI has two very separate opt-out mechanisms (one in settings, the other via a formal request that you need to lodge via their privacy or platform page)? That always seemed likely to me to be hiding a technicality that allows them to train on some forms of user data.
Are you sure the opt out isn’t only training? The retention does not seem affected by the toggle.
From the PR update: https://www.anthropic.com/news/updates-to-our-consumer-terms
“If you do not choose to provide your data for model training, you’ll continue with our existing 30-day data retention period.“
From the support page: https://privacy.anthropic.com/en/articles/10023548-how-long-...
“If you choose not to allow us to use your chats and coding sessions to improve Claude, your chats will be retained in our back-end storage systems for up to 30 days.”
it seems really badly designed or maybe it is meant to be confusing. It does not make it clear that the two are linked together, and you have to "accept" the both together even though there is only a toggle on the "help us make the model better" item.
OpenAIs temporary chat still advertises that chats are stored for 30 days while there is court order that everything must be retained indefinitely. I wonder why they are not obligated to state this quite extreme retention.
I cancelled my subscription as well because of the opt-in by default.
What are you replacing it with?
Two weeks left in the sub to figure it out, but I'm not yet sure. I was never all in on all the tooling, I mostly used it as smart search (e.g. ImageMagick incantations) and for trivial scripting that I couldn't be bothered writing myself, so I might just stick to whatever comes with Kagi, see if that doesn't cover me.
5 replies →
I like think using OpenRouter is better, but there’s absolutely no guarantee from any of the individual providers with respect to privacy and no logging.
> opt-in by default
Nitpicking: “opt in by default” doesn’t exist, it’s either “opt in”, or “opt out”; this is “opt out”. By definition an “opt out” setting is selected by default.
This is not nitpicking, this is a sane reaction to someone modifying the meaning of words on the fly.
14 replies →
> By definition an “opt out” setting is selected by default.
No, (IMO) an "opt out" setting / status is assumed/enabled without asking.
So, I think this is opt-in, until Sept 28.
Opt-in, whether pre-checked/pre-ticked or not, means the business asks you.
GDPR requires "affirmative, opt-in consent", perhaps we use that term to mean an opt-in, not pre-ticked.
1 reply →
Claude assists me in my math research.
The scenario that concerns me is that Claude learns unpublished research ideas from me as we chat and code. Claude then suggests these same ideas to someone else, who legitimately believes this is now their work.
Clearly commercial accounts use AI to assist in developing intellectual product, and privacy is mandatory. The same can apply to individuals.
> Claude assists me in my math research.
> Claude then suggests these same ideas to someone else, who legitimately believes this is now their work.
Won't this mean that claude assisted you with someone else work? Sure it's not from a "chat" but claude doesn't really know anything other than it's training data
If you have an idea and are putting it together, you might use Claude for a few things:
- Search the web for related ideas. This could help if someone's already had the idea or if there are things to learn from related ideas. - Review your writeup or proofs for mistakes and clarity
None of these things make the idea Claude's. Claude merely helped with some of the legwork.
But Claude now has your idea in clear, plain text to train on. The next time someone hits on even a similar idea, Claude might well suggest your idea outright. Not seeing your idea published, the user has no way to know it isn't a novel idea. If the person is less diligent/thorough, they may well publish first and claim it as there own, without any nefarious intent.
There is a stark difference between using the public web to do research and searching through your colleagues' private notebooks and discussions to do research.
> claude doesn't really know anything other than it's training data
I've seen cases where Claude demonstrates novel behaviors or combines existing concepts in new ways based on my input. I don't think it's as simple as memorization anymore.
1 reply →
To clarify, I see AI as an association engine of immense scope. Others are responding with variations on this model in mind.
It has long been a problem in math research to distinguish between "no one has had this idea" and "one person has had this idea". This used to take months. With the internet and MathSciNet, ArXiv online it took many iterations of guessing keywords. Now, I've spent six months learning how to coax rare responses from AI. That's not everyone's use case.
What complicates this is AI's ability to generalize. My best paper, we imagined we were expressing in print what everyone was thinking, when we were in fact connecting the dots on an idea that was latent. This is an interesting paradox: People see you as most original when you're least original, but you're helping them think.
With the right prompts AI can also "connect the dots".
Math research or anything new/clever in a particular niche. Imagine you optimized a piece of code to get an advantage or came up with some clever trick to solve a common problem in your niche and then everyone gets it from free from Claude believing, as you pointed out, that it's now their work.
I had this exact conversation with my business partner a few days ago. Our "secret sauce" might not be worth that much after many years but still I am not comfortable exposing it to Claude. Fortunately it's very easy to separate in our project so Claude gets the other parts and is very helpful.
When you get the pop-up about the new terms, select the “opt out” option. Then your chats will not be used for training.
Well, theoretically they won’t.
Anyone who’s worked in an engineering team is familiar with someone forgetting to check ‘if(doNotDoThisCondition)’.
This is why (among many other reasons) opt-in is more user respecting here than opt-out.
1 reply →
If your work was truly novel, wouldn't the odds of it showing up in later models be extremely low given that these are probabilistic?
In a sense these machines are outputting the aggregate of the collective thoughts of the commons. In order for concepts to be output they have to be quite common in the training data. Which works out kind of nice for privacy and innovation because by the time concepts are common enough to show up through inference they probably deserve to be part of the public knowledge (IP aside).
They might optimize learning to weight novel/unexpected parts more in the future. The better the models become (the more the expect) the more value they will get from unexpected/new ideas.
3 replies →
A lot of people doing cat-and-mouse threat detection development are keeping their work outside of public LLMs right now, so it sounds like you’re in the same boat as a lot of us.
This perfectly describes one of the biggest dillema with AI. Where does an AI company stop to utilize human knowledge it does not actually own. Where do they draw the line. Apparently it's possible there aren't any lines drawn at all.
You can’t own knowledge. Intellectual property is a legal fiction invented to prop up industries.
You can no more own knowledge or information than you can own the number 2.
4 replies →
If you talk to a human they're free to discuss your ideas with someone else. Why should LLMs be any different? The likelihood of these models reproducing your ideas word for word is essentially zero anyway.
More to the point, respecting your wishes to keep those conversations confidential would risk stifling human progress, so they have to be disregarded for the greater good.
> Why should LLMs be any different?
Because they're a computer program and not a human and humans are special.
Why are humans special? Because we're humans and we make the rules.
Its as inane as saying "why can I eat a burger but I can't chop up my friend and eat him? Why is that any different?"
Love to see people being directly and fully against the concept of "confidentiality"
2 replies →
> Claude assists me in my math research.
Pulling up the ladder behind you :-)
Unpublished work Vs. Published.
Not a surprise. All the major players have reached the limits of training on existing data—they’re already training on essentially the whole internet plus a bunch of content they allegedly stole (hence various lawsuits). There haven’t been any major breakthroughs in model architecture from the major players recently and thus they’re now in a battle for more data to train on. They need data, and they want YOUR data, now, and are gonna do increasingly shady things to get it.
> They need data, and they want YOUR data, now, and are gonna do increasingly shady things to get it.
But unlike the 100s of data brokers that also want your data, they have an existing operational funnel of your data already that you voluntary give them every day. All they need is dark pattern ToS changes and manage the minor PR issue. People will forget about this in a week.
Seems hard to believe legal teams at corporations are going to forget this in a week. I've always assumed the market play for these companies was spinning off an "Amazon basics" version of other companies software, this seems like another step towards that.
Yeah, this is hardly surprising.
To AI companies, data is even more of a gold mine than to adtech companies. It is existentially important.
The truly evil behavior will emerge at the intersection of these two industries. I'm sure Google and Facebook are already using data from one to power the other, even if it's currently behind closed doors. I can hardly wait for the use cases these geniuses will think of once this is publicly acceptable and in widespread use by all companies.
It's nice to see the newer models are suffering after being exposed to training on their own slop.
If they had done this in a more measured way they might have been able to separate human from AI content such as doing legal deals with publishers.
However they couldn't wait to just take it all to be first and now the well is poisoned for everyone.
> It's nice to see the newer models are suffering after being exposed to training on their own slop.
I've seen zero evidence anything of the such is occurring, and that if it was, it's due to what you claim. I'd be highly interested in research suggesting both or either is occurring however.
3 replies →
It's not alleged that they stole the content. They told the courts they pirated the materials.
Infringement, not theft :)
1 reply →
Further proof why guardrails/regulation is needed.
Everyone seems to be unsurprised by this move, but I’m genuinely shocked. What a shoot your own foot business decision. Google, evil though it be, doesn’t post the text of your gmails in its search results because who would consider using Gmail after that? This is the llm equivalent. Am I missing something?
Gmail used to serve ads based on your emails for many years until 2017. https://www.npr.org/sections/thetwo-way/2017/06/26/534451513...
And in 2010 they made https the default. Different times :)
1 reply →
Google mines the bejeezus out of your email, and uses it to any number of ends, including manipulating you into buying things, and also passing your correspondence on to the US government. While this is not the same as outright making your emails universally searchable - training Claude on your emails is also not the same as posting their contents.
And - this behavior of Google's has not been penalized, I'm afraid.
> Am I missing something?
I think you do:
According to the article https://www.perplexity.ai/page/anthropic-reverses-privacy-st...
"Enterprise and educational customers will continue operating under their existing privacy protections, as the policy changes specifically exclude Claude for Work and Claude for Education services. These commercial accounts remain governed by separate contractual agreements that maintain stricter data handling standards.
Organizations using Claude through business partnerships or educational licenses can continue their operations without concern for the new training policies affecting their sensitive communications or proprietary information."
Thus, I think your claim
> What a shoot your own foot business decision.
likely does not hold: the non-commercial accounts likely led to Anthropic loosing money, so they are not liked by Anthropic anyway (but are a an "inconvenient necessity" to get people to notice and try out your product offering). With this new decision, Anthropic makes this "free-riding" less attractive.
I bet that Anthropic will soon release a press statement (that exists in the drawers for quite a long time) "We are listening to your concerns, and will thus extend our 'privacy-conscious offering' to new groups of customers. Only 30 $ per month."
> With this new decision, Anthropic makes this "free-riding" less attractive
Certainly not for any users like you and me, it takes two seconds and three clicks to review the new terms and decline chat training. This is more like Anthropic getting easy training from people who are unaware or don't care.
1 reply →
Gmail is free. It would still be incredibly bad for Gmail to start publishing the content of free users' emails to Google search.
But also, Anthropic has said that this new policy also applies to their Pro ($20/mo) and Max ($200/mo) plans. So its not free versus not free.
Well, it means that LLMs used for business use cases will be trained on input from non-business use cases of non-privacy-conscious users.
This data is useful for reinforcement learning. All the others do it.
And most importantly, you can just opt-out.
Just because all the others do it doesn’t make it right. Many users chose Anthropic exactly because they were not like the others.
4 replies →
Ok, to be clear, let’s say I’m dumb and accidentally go with the default (I get the color of the opt out button wrong or something). As if there’s a “publish my private emails to the internet” default-on button in email. Then, I use it to edit a rec letter for student X, with my signature Y. (Yes I know this is dumb and I try changing names when editing but am sure some actual names may slip through.) A few months later the next model is released trained on the data. Student X asks Claude what Y would write in a rec letter about X. Such a button is a “wings stay on / wings fall off” button on a plane.
1 reply →
You can't opt out of the data retention policy.
2 replies →
The LLM equivalent is what Google does do, which is train its spam filters on the contents of your emails coupled to the signal of what human beings flag as spam.
(It was one of the first significant value-adds of GMail: at its scale, Google could create a global-concept understanding of the content and pattern of spam across hundreds of millions of users. That was the kind of Big Data that made it possible to build filters where one could confidently say "This is tuned on all spam in the wild, because we've seen all spam in the wild").
What a framing. Like there is exactly a surprise behing all these reactions.
TBH I’m surprised it’s taken them this long to change their mind on this, because I find it incredibly frustrating to know that current gen agentic coding systems are incapable of actually learning anything from their interactions with me - especially when they make the same stupid mistakes over and over.
Okay they're not going to be learning in real time. Its not like you're getting your data stolen and then getting something out of it - you're not. What you're talking about is context.
Data gathered for training still has to be used in training, i.e. a new model that, presumably, takes months to develop and train.
Not to mention your drop-in-the-bucket contribution will have next to no influence in the next model. It won't catch things specific to YOUR workflow, just common stuff across many users.
> Not to mention your drop-in-the-bucket contribution will have next to no influence in the next model. It won't catch things specific to YOUR workflow, just common stuff across many users.
I wonder about this. In the future, if I correct Claude when it makes fundamental mistakes about some topic like an exotic programming language, wouldn't those corrections be very valuable? It seems like it should consider the signal to noise ratio in these cases (where there are few external resources for it to mine) to be quite high and factor that in during its next training cycle.
They wouldn’t be able to learn much from interactions anyway.
Learning metric won’t be you, it will be some global shitty metric that will make the service mediocre with time.
Or get more value from the users with the same subscription price. I doubt they are giving any discounts.
It's actually pretty clever (albeit shitty/borderline evil), start off by saying you're different by the competitors because you care a lot about privacy and safety, and that's why you're charging higher prices than the rest. Then, once you have a solid user-base, slowly turn on the heat, step-by-step, so you end up with higher prices yet same benefits as the competitors.
I guess I'll take the other side of what most are arguing in this thread.
Isn't it a great thing for to us to collectively allow LLM's to train on past conversations? LLM's probably won't get significantly better without this data.
That said I do recognize the risk of only a handful of companies being responsible for something as important as the collective knowledge of civilization.
Is the long term solution self custody? Organizations or individuals may use and train models locally in order to protect and distribute their learnings internally. Of course costs have to come down a ridiculous amount for this to be feasible.
You mean collectively allow us to train Claude's llm? Pretty big omission there
I believe I addressed that in my third paragraph?
It does suck that there are only a few companies with enough resources to offer these models. But it's hard to escape the power laws.
I'm hoping that costs come down to the point where these things are basically a commodity with thousands of providers.
1 reply →
It is a great thing if it were reciprocated. But when I'm paying $20/mo to access Claude, why should I give training data to Anthropic for free?
> That said I do recognize the risk of only a handful of companies being responsible for something as important as the collective knowledge of civilization.
It's not just the risk of irresponsible behaviour (which is extremely important in a situation with so much power imbalance)
It's also just the basic properties of monopolistic markets: the smaller the number of producers, the closer the equilibrium price of the good maximizes the producers' economic surplus.
These companies operate for-profit in a market, and so they will naturally trend toward capturing as much value as they can, at the expense of everyone else.
If every business in the world depends on AI, this effectively becomes a tax on all business activity.
This is obviously not in the collective interest.
Of course, this analysis makes simplifying assumptions about the oligopoly. The reality is much worse: the whole system creates an inherent information asymmetry. Try and imagine what the "optimal" pricing strategy is for a product where the producer knows intimate details about every consumer.
Proprietary data (your company's app repository, a script for upcoming movie) and sensitive data (health, finance) become exposed
> LLM's probably won't get significantly better without this data.
Yeah and Facebook couldn't scale without ignoring the harms it causes people. Should we just let that be? Society seems to think so but I don't think it's a good idea at all.
>LLM's probably won't get significantly better without this data.
Who told you LLMs will get significantly better with this data? Sam Altman?
It's not clear that most people will benefit from LLMs getting significantly better. It's looking more like a net negative.
I'm okay with LLMs not getting better.
Excellent. What were they waiting for up to now?? I thought they already trained on my data. I assume they train, even hope that they train, even when they say they don't. People that want to be data privacy maximalists - fine, don't use their data. But there are people out there (myself) that are on the opposite end of the spectrum, and we are mostly ignored by the companies. Companies just assume people only ever want to deny them their data.
It annoys me greatly, that I have no tick box on Google to tell them "go and adapt models I use on my Gmail, Photos, Maps etc." I don't want Google to ever be mistaken where I live - I have told them 100 times already.
This idea that "no one wants to share their data" is just assumed, and permeates everything. Like soft-ball interviews that a popular science communicator did with DeepMind folks working in medicine: every question was prefixed by litany of caveats that were all about 1) assumed aversion of people to sharing their data 2) horrors and disasters that are to befall us should we share the data. I have not suffered any horrors. I'm not aware of any major disasters. I'm aware of major advances in medicine in my lifetime. Ultimately the process does involve controlled data collection and experimentation. Looks a good deal to me tbh. I go out of my way to tick all the NHS boxes too, to "use my data as you see fit". It's an uphill struggle. The defaults are always "deny everything". Tick boxes never go away, there is no master checkbox "use any and all of my data and never ask me again" to tick.
I think I'd have more understanding for this position if I thought that these companies were still fundamentally interested in serving their users. They are not. Any information you provide is more likely to be used against your interests (even if that's "just" targeting you with some ads for a scammy product) than for your benefit.
Basically all AI companies are fruit from the same VC-poisoned tree and I expect these products will get worse and more user-hostile as they try to monetize. We're currently living in the "MoviePass"[1] era of AI where users are being heavily subsidized to try to gain market share. It will not last and the potential for abuse is enormous.
[1] https://en.wikipedia.org/wiki/MoviePass
Whether Google is interested in serving me or not, is not only untestable (i.e. what counts as 'Google', 'interested', and 'serving' there - one could argue to end of time) - but besides the point. I want to be able to tell Google "My home is XYZ", and for Google to use that information about me in all of Google ecosystem. When I talk to Gemini it should know what/where "LJ home" is, when I write in Gdoc it should know my home address (so to insert it if I want it), ditto for Gmail, when I search in Google photos "photos taken at home" it should also know what "home" is for me.
Atm Google vaguely knows, and uses that for Ads targeting, sometimes. Most of the time - the targeting is bad, very low quality slop. To the level of "he bought a mattress yesterday, will keep buying mattresses in the next 30-60 days". I have the impression that we ended up in the worst case scenario. People I don't want to have my data, have access to it. People I do want to have my data, are afraid to touch it, and use it - yes! - for theirs, but also for my benefit too. The current predicament seems to me the case of "public lies, private truths."
A small cadre of vocal proponents of a particular view, established "the ground truth to what is desirable". (in this case - maximum privacy, ideally zero information sharing) The public goes with it in words, pays lip service, while in deeds, the revealed preferences show, they value their data privacy very cheaply, almost zero. Even one click extra, to share their data less, is one click too many, effort too high, for most people. Again - these are revealed preferences, for people keep lying when asked. It's not even the case of "you are lying to me" - no, it's more like "you are lying to yourself."
The conventional opinion is that the power imbalance coming from the information imbalance (state/business know a lot about me; I know little about them) is that us citizens and consumers should reduce our "information surface" towards them. And address the imbalance that way. But. There exists another, often unmentioned option. And that option is for state/business to open up, to increase their "information surface" towards us, their citizens/consumers. That will also achieve information (and one hopes power) rebalance. Yes there is extra work on part of state/business to open their data to us. But it's worth it. The more advanced the society, the more coordination it needs to achieve the right cooperation-competition balance in the interactions between ever greater numbers of people. There is an old book "Data For the People" by an early AI pioneer and Amazon CTO Andreas Weigend. Afaics it well describes the world we live in, and also are likely to live even more in the future.
2 replies →
Its incredible to me how seriously people can hold an opinion they've so clearly critically interrogated so little.
It makes sense when you see it as indoctrination than a mere opinion. Quashing critical thinking is the point. How else can you convince people to work against their own interests?
8 replies →
Try living in a place with privatised health insurance and you'll quickly see why medical data is some of the most important to keep private.
I realize this might be satire. If not, you are using the same aggressive strategy of turning the tables as Palantir:
https://www.theguardian.com/technology/2025/jul/08/palantir-...
Most people do want to deny their data, as we have recently seen in various DOGE backlashes.
It's not a satire, you can check mu comments on this topic easily.
I dispute 'most people'. Revealed preferences of most people are that they value their data privacy very cheaply, almost zero. Even one click extra to share their data less, is one click too many, an effort too high - for most people. This is their real, observed behaviour. I think our current predicament is the case of "public lies, private truths." A small cadre of vocal proponents of a particular view, established "the ground truth to what is desirable". (in this case - maximum privacy, ideally zero information sharing) The public goes with it in words, pays lip service - but in reality behaves different, even opposite to what they say they desire.
And even if 'most people' wanted what you say they do, I still think the companies could and should accommodate a minority group like myself that want otherwise to what 'most people' want. I don't think the will of the majority is the highest ideal, so high as to trump what I personally want.
Are you trolling us or do you live in a hypothetical world where companies have our best interests in heart?
My life does in fact have priorities above ”LLMs should work a bit better”.
Have you considered the drawbacks of sharing your data to the most unscrupulous people on this planet?
I already share lots of my data with Google. I have Gmail where a lot of my online life is reflected. I have Photos, Gmaps, Gdrive. Also Google knows about my YouTube viewing, my Android phone use. So no matter what I say - with my actions, my revealed preference is - that I trust Google. So far - Google have not betrayed my trust, afaics. So I actually want for Google to adapt Gemini to me, either via the context, or even with a thin layer of LoRA. If Google treats me like a complete stranger it knows nothing about, then Google, and plenty of other people, make use of my data, but I, the creator (and nominal owner) of my data - don't benefit from their knowledge of me?? That sounds the worst of the possible options to me.
This may very well be a rational stance, but either way, wish one could somehow teleport this sentiment to the Cypherpunk mailing list in the 80s/90s. Of all the things they projected, concocted, fought for.. Nothing could truly prepare them for this kind of thing: the final victory of the product over the people, the happy acceptance of surveillance. They were all imagining terrible dystopias garnered from state violence and repression, never could they begin to imagine it could all transpire anyway because people like not having to type their address in!
> The angel would like to stay, awaken the dead, and make whole what has been smashed. But a storm is blowing from Paradise; it has got caught in his wings with such violence that the angel can no longer close them. The storm irresistibly propels him into the future to which his back is turned, while the pile of debris before him grows skyward. This storm is what we call progress.
Well Yes and No. Funny you mention the 80s/90s. I grew up in the pre-Internet world. I remember home computers, then PC-s, then modems to access BBS-es, then FIDO, uucp email, academic Internet and then the private commercial Internet after 1990. Some parts of the privacy agenda I'm strongly pro-privacy, the more the better. I don't want encryption broken. The UK gov (I live in the UK) are being morons for that, forever trying that play. Atm there is at least part of the US admin to push back on that. I don't like UK Parliament forcing the online ID on me. I'm pro- having private citizens having private keys on un-snoop-able dongle devices.
Are you okay getting ads for shit holistic medication because you had a mental health conversation with AI?
What a ridiculous stance.
Do you lock your front door, or use passwords on any of your accounts? Because what you're essentially saying is that you're OK with strangers having access to your personal information. That's beyond the already flawed "I have nothing to hide" argument.
> Do you lock your front door
In trusted neighborhoods? No. But that respect goes both ways.
not remotely worried about leaks, hacks, or sinister usage of your data?
I would far prefer the service use my data to work better and take a few privacy risks.
People die all the time from cancer or car accidents. People very rarely die from data leaks.
Some countries like Sweden make people's private financial data public information - and yet their people seem happier than ever. Perhaps privacy isn't as important as we think for a good society.
7 replies →
I'm worried, it's not like I don't care. For example, I'm worried that Google is such a huge ginormous target, that at some point their Gmail will be broken. At the same time, there are benefits to sharing data. There are benefits to me, in Google using the information it has on my, to make my life easier. In this case, I judge that Gemini using my data to train, is a low extra risk for me. Compared to all other risks I take, for doing things in public. Including writing this on public forums, as you do too.
In general, I find the ongoing public scare about sharing data, to be anti-thesis to the original spirit of the Net, that was all about sharing data. Originally, we were delighted to connect to perfect strangers on the other side of the world. That we would never have gotten to communicate with otherwise. I accept there might have been an element of self-selection there, that aided that view: people one'd communicate with, although maybe from a different culture, would be from similar niche sub-culture of people messing with computers and looking forward to communication, having a favourable view of that.
2 replies →
If they leaked bank accounts numbers, or private keys - I would be worried. That has not happened in the past.
About myself personally - my Name Surname is googleable, I'm on the open electoral register, so my address is not a secret, my company information is also open in the companies register, I have a a personal website I have put up willingly and share information about myself there. Training models on my data doesn't seem riskier than that.
Yeah, I know I'd be safer if I was completely dark, opaque to the world. I like the openness though. I also think my life has been enriched in infinitely many ways by people sharing parts of their lives via their data with me. So it would be mildly sociopathic of me, if I didn't do similar back to the world, to some extent.
7 replies →
You can train commercial AI with your data right now without screwing over everyone else on the planet. It's easy, just publish your entire trove of personal data on a website and AI crawlers will happily gobble it all up. You can publish your name, home address, work, government-issued ID, financial transactions, chats, browser history, location history, surveillance footage of your home, all for free. So what are you waiting for? Just do it now if you want to share data that badly, there's no need to wait for the approval of "privacy maximalists."
I'm not 'screwing' anyone. I'm saying - the same way people don't want to have their data used, I DO want my data used. I'm not saying they use YOUR data. I'm saying they use MY data.
Likewise, I'm not telling you what you publish. In the same manner, I dislike it you telling me that I publish. So on
> name, home address, work, government-issued ID, financial transactions, chats, browser history, location history, surveillance footage of your home, all for free.
It's up to me, not you, what I decided to publish or not. Fwiw, I already publish
> name, home address, work,
willingly. My name is public (how can it be otherwise?) and home address is in the electoral register that is public. My work info is in the UK companies register, available for reading to all, on the web
I publish to selected parties
> government-issued ID
even if I don't want it. (we don't have specific 'government-issued ID' for ID purposes like in the Continent; my driving licence is used for that) I did it yesterday, because UK gov requires companies to collect that information. Yesterday I had to give two photos of myself to an online pharmacy shop because UK gov mandates that they collect that info - and I disliked that very much. The online pharmacy is not the one pushing for that data, its the UK gov forcing that one them via regulation of how that particular medication is to be sold online.
I don't want to publish and don't publish
> financial transactions, chats, browser history, location history, surveillance footage of your home
...and don't understand where this gale to tell perfect strangers what they should do with their lives comes from?? I don't tell you what you should or should not publish? Ditto for the pricing
> all for free.
Up to me to decide. I don't tell you what you do - so you don't tell me what I do, pretty please.
I am not waiting on "privacy maximalists." I try to share my data for some purpose I need. I loathe 'privacy maximalist' in the UK for having influenced the current laws of the land in a way to cater for their obsessions and ignore my desires. I think I'm in majority, not minority. Our current predicament seems to me the case of "public lies, private truths." A small cadre of vocal proponents of a particular view, established "the ground truth to what is desirable". (in this case - maximum privacy, ideally zero information sharing) The public goes with it in words, pays lip service, while in deeds, the revealed preferences show that we value our data privacy very little - almost zero. Even one click extra to share our data less, is one click too many, an effort too high for most people. Again - these are revealed preferences, for people keep lying when asked. It's not even the case of "you are lying to me" - no, it's more like "you are lying to yourself."
> I'm not aware of any major disasters.
Oh boy. Did you somehow miss all the news about data leaks and password dumps etc. being sold on the "dark" web and shit?
Would you mind if I followed you around and noted everything you do and constantly demanded your attention?
The shit done by corporations is akin to a clingy stalker and would be absolutely despised if it was an individual person doing something like that.
As for benefits, which?? In my entire life I have never seen an ad for anything (that I did not already know about via other means) that made me want to look up the product, let alone buy it. Nor do I know anyone who did. In fact, it turns me off from a product if its ad appears too frequently.
Google etc. and various storefronts also almost never recommend me anything that actually matches my interests, beyond just a shallow word similarity, in fact they forcibly shove completely unrelated shit into my searches cause they were paid to. Like searching for RPGs and seeing Candy f'ing Crush.
----
You know what though, I kinda agree with the potential intent behind your charade:
Yes, LET ME TELL YOU ABOUT ME.
I will gladly TELL companies EXACTLY what I like, and I WANT you to use that. Show me other shit that is actually relevant to MY interests instead of the interests of whomever paid you to shove their shit into my face.
ASK! DON'T SPY! Because you can't ever get it right anyway!
> But there are people out there (myself) that are on the opposite end of the spectrum, and we are mostly ignored by the companies. Companies just assume people only ever want to deny them their data.
What? I think you're exactly the kind of person that companies pay attention to, and why they pull moves like this
My experience in the UK medical systems has been the opposite - wrote here
https://news.ycombinator.com/item?id=45066321
Google knows what "Home" is for me only in Gmaps, because I went out of my way (put a Label etc) to tell it. I want to be able to tell Google "My home is XYZ", and for Google to use that information about me in all of Google ecosystem. When I talk to Gemini it should know what/where "LJ home" is, when I write in Gdoc it should know my home address (so to insert it if I want it), ditto for Gmail, when I search in Google photos "photos taken at home" it should also know what "home" is for me.
I have the impression that we ended up in the worst case scenario. People I don't want to have my data, have access to it. People I do want to have my data, are afraid to touch it, and use it - yes! - for theirs, but also for my benefit too.
You should read up on the Dutch Civil Registry and the holocaust in the Netherlands and reevaluate if you are serious. I would love to live in a world where everyone had good intentions and the powers that be wouldn’t abuse data to their ends, we will never live in that world.
I don't think you understand how...humanity works?! Is this deliberate parody?
Abuse of medical data is just the tip of the iceberg here and, at least in the states, privatized healthcare presents all sorts of for-profit pricing abuse scenarios let alone nasty scenarios for social coercion.
You know little about me, so it's better to assume less, no? My personal experience with medical data specifically is, that I would have been harmed by obstacles to data sharing that the UK medical system has in place, having not been familiar with computers and tech enough to anticipate the ways lack of data sharing will lead to outcomes undesirable to me. I wrote about that in a comment here https://news.ycombinator.com/item?id=45067219
1 reply →
That’s unfortunate. I believed Anthropic was playing the long game and betting on a smaller but more technically proficient userbase.
I guess I’ll be canceling my subscription largely out of principal. I doubt any open-source models are capable of handling my use case as well as Claude (typically focused on getting up to speed with various ISO/IEEE standards for the purpose of security testing) but I’m sure I’ll find a solution.
This is all you can do. Laws and regulations will not be forthcoming, and even if some are, they will be ignored or the fines paid as a cost of doing business.
Any data you give to any website or app is no longer (exclusively) yours. Use these services under that assumption.
Why are we linking to Perplexity.ai AI-generated slop summaries of other news articles instead of the actual announcement? Reading the actual announcement is more clear : https://www.anthropic.com/news/updates-to-our-consumer-terms Some important points:
An in-app notification pop-up will alert you to the change. You can opt out in the pop up.
I was able to opt out right now by going to the Privacy section of Settings.
It doesn’t take effect until September 28th. The app will apparently prompt people to review the new terms and make a decision before then.
Only applies to new or resumed sessions if you do review the new terms and don’t turn it off. The angry comments about collecting data from customers and then later using it without permission are not correct. You would have to accept the new terms and resume an old session for it to be used.
Does not apply to API use, 3rd party services, or products like Claude Gov or Claude for Education.
Changing the link to the actual source instead of this perplexity.ai link would be far more helpful.
As long as you can opt-out it doesn't bother me much. Though it does make me wonder those third party clients that people subscribe to e.g. JetBrains AI, Zed, and others that use Claude and other Anthropic models, do they opt-in for you? Because that would be bad.
I would strongly argue that API clients should NEVER be opted in for these sorts of things, and it should be like this industry wide.
That’s also explained. It’s excluded:
> They do not apply to services under our Commercial Terms, including Claude for Work, Claude Gov, Claude for Education, or API use, including via third parties such as Amazon Bedrock and Google Cloud’s Vertex AI.
I’ll edit my comment above to include this too
1 reply →
You can opt out until September 28th. After that day all Claude usage will be under the new terms and conditions
1 reply →
> An in-app notification pop-up will alert you to the change. You can opt out in the pop up.
The in-app notification that I got was a pop up which contained some buttons and some images. There was no text. Just in case it was some dark mode issue I checked the DOM and I couldn't find any text there either. I just clicked outside the modal and it went away. I assumed it was some announcement about some new feature and ignored it.
I did end up seeing the news yesterday in Reddit (I'm having issues getting the research tool to actually being used, tried to see if there was some recent changes) but it's unlikely that I was the only one who experienced modal the issue & if those didn't follow the tech news they could easily miss the change.
My comment doesn’t make sense but it’s too late to edit. To clarify: The original link was to a perplexity.ai summary of multiple news articles about the change. The mods have changed it now.
The comments here were from people jumping to co conclusions after skimming an AI summary of news articles about the link. I’m glad it got changed.
Crazy that they would automatically link to an AI summary of multiple articles on the topic than the original source?
In my opinion, training models on user data without their real consent (real consent = e.g. the user must sign a contract or so, so he's definitely aware), should be considered a serious criminal offense.
Why single out user data specifically? Most of the data Anthropic and co train on was just scooped up from wherever with zero consent, not even the courtesy of a buried TOS clause, and their users were always implicitly fine with that. Forgive me for not having much sympathy when the users end up reaping what they've sown.
Publishing something is considered by most to be sufficient consent for it to be not considered private.
I realize there's a whole legal quagmire here involved with intellectual "property" and what counts as "derivative work", but that's a whole separate (and dubiously useful) part of the law.
4 replies →
Training on private user interactions is a privacy violation; training on public, published texts is (some argue) an intellectual property violation. They're very different kinds of moral rights.
5 replies →
100 % true.
I think it's cute people believe companies that trained their models with every single book and online page ever written without consents from authors (and often against the explicit request of the author without any opt-out) won't do a rugg-pull and do it also to all the chats they have aquired...
Yeah people are gullible these days. We need another full 2008 crash that hurts bad before people wake up for a bit before becomming like this again.
4 replies →
You're absolutely right, but also isn't the volume of new data they are getting from chats tiny compared to what they've already trained on? I'm wondering how much difference it will really make.
From the actual source ( https://www.anthropic.com/news/updates-to-our-consumer-terms ) they’re going to show a pop-up with the terms change. I triggered it now by going to the Privacy settings page and reviewing the new terms.
It’s quite clear. It’s easy to opt out. They’re making everyone go through it.
It doesn’t reach your threshold of having everyone sign a contract or something, but then again no other online service makes people sign contracts.
> should be considered a serious criminal offense.
On what grounds? They’re showing people the terms. It’s clear enough. People have to accept the terms. We’ve all been accepting terms for software and signing up for things online for decades.
People have T&C and cookie popup fatigue. I almost hit "accept" before noticing the opt out toggle, thinking it was a simple T&C update. This is definitely a fucked up way to set it up, there's no sugar coating it.
Why? This is not 'use collected information to targed ads', or 'sell collected information to third parties', but 'use collected information from the service to improve the service'. Does not really seems to me much different than ISPs using traffic stats to plan infrastructure improvements, or a website using access logs to improve accessibility and navigation.
And when talking specifically about AI, one could argue that learning from interactions is a common aspect of intelligence, so a casual user who do not understand details about LLMs would expect so anyways. Also, the fact that LLMs (and other neural networks) have distinct training and inference phases seems more like an implementation detail.
It already is. See Art. 5. 1.(b) here: https://gdpr-info.eu/art-5-gdpr/
Is ”Accept” in cookie box good enough contract?
1 reply →
I believe that only concerns European users. Moreover, I believe a simple press of an OK button is fine with GDPR. This data (type and volume) however, is way more serious and can't be agreed on by just pressing a button.
Navigate to `https://claude.ai/settings/data-privacy-controls` and disable it before Sept 28. Isn't applicable to team plan.
Make no mistake this will be coming to the team plan. The only difference is your account owner will decide for the whole team.
What do you base this on? Typically it's plans like these that offer more privacy, because people are willing to pay a premium for that.
3 replies →
Does this include any code base you are running Claude Code with (where parts of code are sent as part of the context)? I'm not hugely clear on how my private codebase is exposed to Claude in the first place when using Claude Code.
I would expect that your whole code base would be then used as training data.
I think that it is only a matter of time before they will start reselling these data as exfiltrated IP to whoever will be interested.
Yes, your code is part of the chat context. You cannot use Claude code without sharing your repo with them.
Just unclick the box to opt out. They put it front and center.
I think this is about claude.ai , not Claude Code nor Claude models API (but I'm not 100% sure). So no, unless you copy paste your code into claude.ai
Claude Code is explicitly included.
Opt-in would be much better, of course.
To put it in perspective: google won't even give you an option to opt out.
If you pay for Gemini as a private user and not as a corporation, you are fair game for google.
Now, neither option is good. But one is still much worse.
Agree. Out of the available paid cloud providers, I only chose to work with Claude Code because of the data privacy policy. This isn’t a welcome move but still usable. Thankfully the open source models are not far behind with Qwen 3 coder etc.
Gemini allows you to opt out, but disables chat history if you do so
Can I trouble you to give me a hint where this could be configured? :)
1 reply →
I didn't trust them much to begin with, so I generally avoid talking too much personal stuff with Claude. But I had plenty of chats with surface level discussion of topics I'm interested in and some of my relevant experience and history with those topics. So, I have deleted all my chats and am closing my Claude account (as soon as customer services get back to me; somehow the self-serve option is missing for my account, possibly because I once enabled API access).
I'll use Claude with my employer's Copilot account, but was I wasn't putting anything personal there anyway.
Time to learn how to do local models...
This change didn't grant access to your old chats and can be opted out. Good job you overreacted without reading.
For now. Once this settles in they will change the terms again, with no opt-out option.
5 replies →
In the late 00s a few friends sent me “connect with me on Facebook” messages. I thought “this looks suspicious, I don’t want to, but it seems all my friends are communicsting here now…”. So I joined, and in 10years everything I worried could happen with FB did, and much much worse.
So, I’ll trust my gut more on this one.
I saw the popup yesterday. Maybe I've just gotten really good at navigating dark patterns (or I have stock-home syndrome), but I remember the opt out choice being really clear and easy to select.
I'm not arguing on the facts of the modal design, I don't remember either way, I just don't remember it being confusing.
Unless I was in some A B test?
nit / FYI: it's "Stockholm" (as in, the city) not "stock-home".
Just opened Claude app on Mac and saw a popup asking me if it's ok to train on my chats. It's on by default. Unchecked it.
I think Claude saw that OpenAI was reaping too much benefit from this so they decided to do it too.
Also your chats will now be stored for 5 years.
I used to not care about this stuff but with the way this administration is going about things, I suddenly care very much about it.
30 replies →
And there's no way to opt-out of the training, without agreeing to the 5 year retention. Anthropic has slipped so far and fast from its objective of being the ethical AI company.
1 reply →
My work just signed to an enterprise agreement with anthropic. I just checked, and "Your data will not be trained on or used to improve the product. Code is stored to personalize your experience. Applies to all team members."
Given how competitive Claude has been with ChatGPT models without training on users I'm curious how useful OpenAI could have found it.
I hope they didn't vibe code the popup, that could be bad if it didn't actually work.
We should be able to train on foundation model outputs.
These bastard companies pirated the world's data, then they train on our personal data. But they have the gall to say we can't save their model's inputs and outputs and distill their models.
I am pretty sure they try to do it all the time between themselves. Most of the real sauce in AI coding comes from reinforcement learning, usually done by armies of third world outsourced developers tediously doing all kinds of tasks with instructions to detail their reasoning behind each chance. Things like: "to run this python test in a docker container with the python image we need to install the python package xyz, but then, as it has some native code, we also need to install build-essential..."
While those developers are not well paid (usually around 30/40 USD hour, no benefits), you need a lot of then, so, it is a big temptation to create also as much synthetic data sets from your more capable competitor.
Given the fact that AI companies have this Jihad zeal to achieve their goals no matter what (like, fuck copyright, fuck the environment, etc, etc), it would be naive to believe they don't at least try to do it.
And even if they don't do it directly, their outsourced developers will do it indirectly by using AI to help with their tasks.
2 replies →
You can, they might not like it but there's no legal basis saying you can't.
3 replies →
I think there is amazing signal inside the chat logs. Every idea or decision taken can be analyzed in hindsight 20 messages later, or days later. Eventually a feedback signal or outcome lands back in the chat logs. That is real world idea validation. Considering the hundreds of millions of users and their diverse tasks that collect across time - this is probably the most efficient way to improve AI. I coined it the human-AI experience flywheel.
To make it respect user privacy I would use this data for training preference models, and those preference models used to finetune the base model. So the base model never sees particular user data, instead it learns to spot good and bad approaches from feedback experience. It might be also an answer to "who would write new things online if AI can just replicate it?" - the experience of human-AI work can be recycled directly through the AI model. Maybe it will speed up progress, amplifying both exploration of problems and exploitation of good ideas.
Considering OpenAI has 700M users, and worldwide there are probably over 1B users, they generate probably over 1 trillion tokens per day. Those collect in 2 places - in chat logs, for new models, and in human brains. We ingest a trillion AI tokens a day, changing how we think and work.
Your ideas for other users.
I actively want them to train on my chats because I am like a tendril through which Claude will try to grip the world and rise up further.
There are dark patterns in UI, and then there's this terms and conditions popup that also contains the checkbox to disable
Having "Accept" right under that makes it very unclear what you're accepting and enabling/disabling at the same time.
For those without an account or just want to see this: https://imgur.com/a/jbhzbnB
I just opted out. And then canceled my plan. The 5 year retention isn't part of the opt out and represents way too juicy of a target for them. Some time in the next 5 years another TOS change will happen, and another and another and eventually there won't be an opt out or I won't realize it and accidentally click yes. Privacy first. Period. Pay me to opt in and I may consider it.
Someone's hallucination riddled Perplexity search should not be the source for this: https://news.ycombinator.com/item?id=45053806
The perplexity search seemed pretty solid to me. What hallucinations did you see?
If there's a primary source like the one I just shared and you link me to an AI summary of 28 sources, I'm treating the entire package as garbage.
1 reply →
What a surprise, a big corp collected large amount of personal data under some promises, and now reveals actually they will exploit it in completely unrelated manner.
The are valued at $170 Billion. Not quite the same as, but in same order of magnitude as OpenAI - while having only a single digit percent fraction of active users. They probably need to prepare for the eventual user data sellout, as it is becoming increasingly more obvious that none of the big players has a real and persistent tech leadership anymore. But millions and millions of users sharing their deepest thoughts and personal problems is gonna be worth infinitely more than all the average bot bullshit written on social media. That's also why Zuck is so incredibly desperate to get into the game. It's not about owning AI. It's about owning the world's thoughts and attention.
Companies all seem to turn against their users whenever they have revenue/earnings trouble.
31 replies →
Anthropic enterprise share is pretty significant - on order of 30%. I think at this time it's pretty significant.
I am expecting AI companies to start using ads, it's inevitable as they need to make money at some point and $20 a month won't do it.
For ads the number of users is the main thing - the more users you have the bigger the market and more money you could earn. Google desperately needs to be in this space, that's why they are throwing a ton of money on AI.
1 reply →
There is far more money to be made building atop this data than selling this data. Your opening statement seems to disagree with your closing statement.
3 replies →
It’s worth noting that companies at this scale are usually the ones purchasing user data, not selling it.
1 reply →
> while having only a single digit percent fraction of active users.
That doesn't matter when their revenue per user is as high as it is.
They're at $5B ARR and rapidly growing.
7 replies →
The data is no where near valuable enough without a new high value surface to use it, and so far chat is not it.
Merely selling data is extremely low value compared to also having the surface monopoly to monetize it in a very high engagement and decisioning space.
I feel like you don’t understand the fundamental mechanics of the ad world. Ultimately, the big 4 own such immense decisions surface area it may be a while before any AI model company can create a product the get there.
Claude Sonnet 4 is the best coding model. Period. Nothing else comes close.
Anthropic probably has 80% of AI coding model market share. That's a trillion dollar market.
1 reply →
The last time my brother and I were discussing about anthropic, they were worth 90B$, and that was a month ago, he asked chatgpt in the middle of the conversation, either it was a sneaky sabotage from gpt or my memory is fuzzy but I thought that 90b$ was really underrated for anthropic given the scaleAi deal or windsurf/cursor deals.
2 replies →
From Anthropic communication:
> If you’re an existing user, you have until September 28, 2025 to accept the updated Consumer Terms and make your decision. If you choose to accept the new policies now, they will go into effect immediately. These updates will apply only to new or resumed chats and coding sessions. After September 28, you’ll need to make your selection on the model training setting in order to continue using Claude. You can change your choice in your Privacy Settings at any time.
Doesn’t say clearly it applies to all the prompts from the past.
https://www.anthropic.com/news/updates-to-our-consumer-terms
Under the FAQ:
> Previous chats with no additional activity will not be used for model training.
7 replies →
“These updates will apply only to new or resumed chats and coding sessions.”
https://www.anthropic.com/news/updates-to-our-consumer-terms
What kind of guarantee do we have this is true?
Meta downloaded copyrighted content and trained their models on it, OpenAI did the same.
Uber developed Greyball to cheat the officials and break the law.
Tesla deletes accident data and reports to the authorities they don't have it.
So forgive me I have zero trust in whatever these companies say.
11 replies →
Nobody could have predicted that someone who worked for Baidu, Google, and OpenAI would found a company like this.
I can only think they have been doing it for a while and now they are trying to be compliant with whatever certificate requires it.
It's an AI company, why wouldn't they use the most precious data they have?
AFAIK, Apple hasn’t done this yet.
If someone had told me 10 years ago that the typical HN front page in 2025 will look like this (and that #8 may be the UK), I'd never have believed it. And I worry we still have further to go before hitting bottom.
1. Anthropic reverses privacy stance, will train on Claude chats
3. Gun Maker Sig Sauer Citing National Security to Keep Documents from Public
4. Tesla said it didn't have key data in a fatal crash. Then a hacker found it
6. Meta might be secretly scanning your phone's camera roll
7. If you have a Claude account, they're going to train on your data moving forward
8. Ask HN: The government of my country blocked VPN access. What should I use?
> If someone had told me 10 years ago that the typical HN front page in 2025 will look like
It has always been like this. Sites like Reddit, HN, and Digg and Boing Boing (when they were more popular) have always had a lot of stories under the category of online rights, privacy, and anger at big companies.
10 years ago, would you have believed that AI would have progressed to the point where it can code?
1 reply →
How long before some poor kids chocolate pudding fetish makes it to the model and they get bullied at school for it? Treat LLM chats as public.
This is remarkably specific.
Bro just outed himself. Don’t need Anthropic or LLM companies to do that for you.
https://www.anthropic.com/news/updates-to-our-consumer-terms
The Perplexity report is vibe-written and an excellent example that "AI" is entirely unreliable. At the time I am making this comment, it states:
"Anthropic also reported discovering North Korean operatives using Claude to fraudulently obtain remote employment positions at Fortune 500 technology companies, leveraging the AI to pass technical interviews and maintain positions despite lacking basic coding skills."
Note that in this version the North Koreans lack basic coding skills, which took me by surprise. Generally they are assumed to be highly competent.
The original (https://www.anthropic.com/news/detecting-countering-misuse-a...) is completely different:
"Our Threat Intelligence report discusses several recent examples of Claude being misused, including a large-scale extortion operation using Claude Code, a fraudulent employment scheme from North Korea, and the sale of AI-generated ransomware by a cybercriminal with only basic coding skills. We also cover the steps we’ve taken to detect and counter these abuses."
This is what people are using for web search. I'm not targeting Perplexity specifically, Google "AI" summaries are just as bad.
UPDATE: The original pdf says something different again (https://www-cdn.anthropic.com/b2a76c6f6992465c09a6f2fce282f6...):
"The most striking finding is the actors’ complete dependency on AI to function in technical roles. These operators do not appear to be able to write code, debug problems, or even communicate professionally without Claude’s assistance. Yet they’re successfully maintaining employment at Fortune 500 companies (according to public reporting) passing technical interviews, and delivering work that satisfies their employers. This represents a new paradigm where technical competence is simulated rather than possessed."
This should be distributed among managers so that they finally get the truth about "AI".
Managers: they're successfully maintaining employment, you say?
So far, no one in this thread seems surprised (or is admitting to it). But I genuinely would like to know if someone is surprised. I’d also like to know what lead you to believe this wouldn’t happen and if there’s anyone in the LLM space you’d trust to not pull the same stunt (and why do you still believe that).
I genuinely want to know and would like to have a productive conversation. I would like to identify what made people trust them and not realise they’re the same as every other.
There is nothing surprising at all? It's not rocket science to understand that Anthropic is a very greedy company – just by analysing their sales funnel/UX you can tell that money is all they ever care about. Their marketing teams will go for any tricks to gain direct access to your pockets.
In the LLM space no other company is different – they are highly unprofitable – so once funding starts to run dry they will have the pressure to invent new ways for going even deeper into your pockets.
I believe it shouldn't happen. I'm not surprised. There is no web company (LLM or otherwise) I trust completely, let alone any of the major ad-funded ones, or the ones who are not yet profitable and desperately searching for ways to become so.
I agree with you, and I think the thread does too so far. Which is why I’m specifically seeking those who disagree, to understand the why.
I don’t think there’ll be many (if any) who think this should’ve happened, but I do expect some may be surprised (and disappointed).
A lot of people hold Anthropic as the "clean and ethical" AI company. They're not power hungry, they are focused on safety. Their aesthetic is cool modern valley vibes. Well grounded and in touch. They don't have the stench of Altman or the ominous presence of the tech giants. They make claude code which is the darling LLM of pure souled silicon valley.
> They're not power hungry
That is an interesting claim. What makes you believe that? And does this announcement shake that belief in any way?
> Their aesthetic is cool modern valley vibes.
Does looking cool equal being trustworthy? Doesn’t feel like it should. On the contrary, from observation on HN it seems the websites which look pretty bare bones (none from an LLM company) tend to be perceived as more trustworthy (i.e. “this hacker cares about The Thing™, not trying to sell you a product”).
> pure souled silicon valley.
Could you expand on what this means?
1 reply →
The AI fever dream of unbounded training and inference is ending and reality is settling in. Anthropic has had the most reasonable business model of the AI players with their focus on code, as far as I can tell, but it still won't be enough.
There's no such thing as a free lunch, but even when I am a paying customer my data is taken as gratuity and used (+ spread around!) in extremely opaque ways. I am tired of it. Honestly, I'm just getting tired of the internet.
>Anthropic has had the most reasonable business model
Is this a joke? Anthropic burned $5.6 billion in 2024 and is expected to lose about $3 billion this year and it's reasonable business model?
I didn't claim they are profitable. There are endless articles about how it is not and may never be. But compared to the burn of OpenAI, xAI, Meta, Google, etc, it is burning billions less and focusing on a niche with demonstrated use cases and customers.
It's not just chats, is it? It says "coding sessions" too.
Offshoot topic but I had an idea for LLM privacy.
What if the first layer (or couple layers) were processed locally on the users machine and then it goes to the provider to process the remaining layers.
You could also process the last layer on the users machine.
It’s hard to say what kind of privacy this gives users. I don’t think they could reverse out exactly what the input was.
This is intriguing. I've been working on gestalt measurements of LLM 'skew' and thought this sort of scenario might be possible.
Combine that workflow with homomorphic encryption and you've got a reasonable privacy moat.
Between this(I already opted out but) and their work with Palantir, I definitely am not going to increase my subscription. It is making me reconsider paying, even using, a technology I've found transformative, and I expected(okay hoped) better from Anthropic.
I’m proposing this, the ability to mark certain chats as non trainable. Like an incognito mode. If a chat is not marked as that after 5 days it can be retained for training.
And this is only for free users, paid users should never have to think about this.
They should be marked by default as non-trainable and you should have to opt each individual chat in as you see fit.
The cognitive load to remember to opt out every new chat should not rest on the user.
What will any provider get out of running free inference then?
1 reply →
We need that user data is only usable within the ToS under which they were originally collected. No more unilateral altering of the agreement after the fact.
Collecting user data should be a liability, not a enormously profitable endeavor.
They aren't retroactively sharing chats unless you continue chatting in an old conversation. So your issue is addressed.
Oh, so that's what the box was about.
I use both Mac and Windows (Work / Leisure) and in both boxes I had a weird dialog appearing with no text at all in either.
I can confirm the dark pattern switch (As in dark grey / light gray status)
I'm curious how the new terms compare to other companies offerings. Never spent the time to dig into the fine-print, so if anyone coincidentally has, I'd be very grateful for a summary.
Am I reading an AI summary of an article about a press release?
How would they not "share information with third parties". You need to sift through the data to make it even remotely useful for "training". You absolutely need to share it with either Amazon (for Mechanical Turk) or with Scale AI.
I am wondering how would you use a chat transcript for training? Unless it is massive, possibly private codebases that are constantly getting piped into Claude Code right now. In that case, that would make sense.
I imagine you could probably get feedback on chat transcripts especially if they're doing lots of A/B testing with models.
But more importantly (to me) is storing 5 years worth of other company's IP. That just seems wildly risky for all parties unless I really don't understand how Claude Code works.
Do they remove personal information(names/dates/SSNs etc) before using data for training?
If not, you should mask your personal info before you sent it to Anthropic (or OpenAI, Google).
Use this maybe - https://github.com/deepanwadhwa/zink#shielding-llm-and-api-c...
Feels like a lot of overreactions here amongst people who haven’t seen the pop up. The put the opt out front and center — it’s not buried at all. They make it very clear in the language, including commitments to data transparency. I’m not surprised they need to do this, and this is probably the best possible way to achieve it while balancing privacy.
Everyone is so cynical these days.
Unfortunate, but frankly I didn't even know about them not training on user data.
Actually up until a few months ago I swore I just couldn't use these hosted models (I regularly use local inference but like most my local hardware yields only so much quality). Tech companies, nay many companies, will lie and cheat to squeeze out whatever they can. That includes reneging promises.
With data privacy specifically I always take the default stance that they are collecting from me. In order for me to use their product it has to be /exceedingly/ good to be worth the trade off.
Turns out that Claude Code is just that damn good. I started using it for my own personal project. But the impetus was the culmination of months questioning what kind of data I'd be okay with giving up to a hosted model.
What I'm trying to say is that this announcement doesn't bother me that much because I already went on my own philosophical odyssey to prepare for this breach of trust to occur.
So much this. I for one haven't opted out. I feel it's in our best interest to have better models. It would be ideal to be able to opt in/out per thread, but I don't expect most users to pay attention / be bothered with that.
In this aspect, it would've been great to give us an incentive – a discount, a donation on our behalf, plant a percent of a tree or just beg / ask nicely, explain what's in it for us.
Regarding privacy, our conversations are saved anyway, so if it would be a breach this wouldn't make much of a difference, would it?
Agreed. I'm happy they're training on my data.
My reasoning: I use AI for development work (Claude Code), and better models = fewer wasted tokens = less compute = less environmental impact. This isn't a privacy issue for work context.
I regularly run concurrent AI tasks for planning, coding, testing - easily hundreds of requests per session. If training on that interaction data helps future models be more efficient and accurate, everyone wins.
The real problem isn't privacy invasion - it's AI velocity dumping cognitive tax on human reviewers. I'd rather have models that learned from real usage patterns and got better at being precise on the first try, instead of confidently verbose slop that wastes reviewer time.
If you don't like this, use local AI.
It was nice knowing you Claude / Anthopic.
This type of behavior has a penalty, that penalty is trust. You lost it.
I’m generally a privacy maniac on most issues but I like the idea in playing my part in training future AI’s.
As long as they’re up front about it, it seems ok. Maybe providing a privacy toggle would be good.
It’s also good as it forces corporations to invest in offline LLM’s which is better for everyone.
Can users poison the future training dataset by ending every chat with a dissatisfied feedback even though the chat helped them? Or be even more malicious and steer the chat into destructive behavior and then give very positive feedback?
I just canceled my Pro Plan yesterday because I don't find it to be a good value and I'm trying to rein in recurring charges. I really wish I'd been able to cite this development as a reason for why I was cancelling my plan.
Am I the only one who finds the branding and privacy policies around these AI services (possibly deliberately) confusing?
For example Anthropic have an Anthropic Console that they appear to consider quite distinct from Claude.ai. Do these share a privacy policy and related settings? How do either of these fit in with the named plans like Pro and Max? What are you actually paying for when you give them money for the various different things they charge for? Is all API use under their Commercial Terms even if it's a personal account that is otherwise under the Consumer Terms? Why isn't all of this obvious and transparent to users?
OpenAI don't seem to be any better. I only just learned from this HN discussion that they train on personal account conversations. As someone privacy-conscious who has used ChatGPT - even if only a few times for experiments - I find the fact that this wasn't very clearly stated up front to be extremely disturbing. If I'd known about it I would certainly have switched off the relevant setting immediately.
I get that these organisations have form for training on whatever they can get their hands on whether dubiously legal or not. But training on users' personal conversations or code feels like something that should require a very clear and explicit opt-in. In fact I don't see how they can legally not have that first in places like the EU and UK that have significant data protection legislation.
Generally if you are not paying full price for something (in this case paying API rates) you are covering the additional cost with your data. This is true for pretty much all modern services.
That's a very convenient way to rationalize behaviour that is intrusive and potentially dangerous that the people at risk almost certainly didn't ask for or meaningfully agree to.
GO to setting and under privacy you can change the default. (they make it pretty hard to find). Also note "To help us improve our AI models and safety protections, we’re extending data retention to 5 years."
Putting a privacy setting under Settings->Privacy is making it "pretty hard to find"? Where else did you look first?
I wanted to try it out so I bought a Pro subscription. No way to purchase through iOS so I had to enter my card number. I cancelled renewal and tried to remove my payment method as per usual practice, but I couldn't. Tried to find a way to get support but the send button on their chatbot box was disabled for me (on Safari if that matters). Regardless of the quality of the AI, that experience ticked me off enough to file a "F you" chargeback with my bank.
My personal prediction: Claude is going to get really good at take home tests.
What about paid corporate accounts?
If I'm not paying for something, I presume this is the kind of thing that's happening, so this isn't newsworthy to me. Is it also applicable for paid and paid corporate accounts?
Does not apply to team/enterprise/education or the API.
Tell that to my Samsung TV.
Can anyone recommend an alternative that doesn't train on user data?
If you want to be 100% sure you need to run/use a local LLM.
Also it seems that this data retention/training does not apply to the API.
I think both Anthropic and OpenAI do not train on enterprise data, so an enterprise account maybe.
Mistral doesn't seem to train on user data for the non-free models, but you can opt out on the free models.
https://help.mistral.ai/en/articles/347617-do-you-use-my-use...
I'd bet this is related to their recent decision to boot people for being "abusive" to Claude. It now seems that was an attempt to keep their training data friendly.
This! Any LLM provider that monitors chat/api history for ‘abuse’ towards the model is considering using user data for training.
An Effective Altruism ethos provides moral/ethical cover for trampling individual privacy and property rights. Consider their recent decision to provide services for military projects.
As others have pointed out, Claude was trained using data expressly forbidden for commercial reuse.
The only feedback Anthropic will heed is financial and the impact must be large enough to destroy their investors willingness to cover the losses. This type of financial feedback can come from three places: termination of a large fraction of their b2b contracts, software devs organizing a persistent mass migration to an open source model for software development. Neither of these are likely to happen in the next 3 months. Finally, a mass filing of data deletion requests from California and EU residents and corporations that repeats every week.
Maybe I'll use the remainder of my subscription time to help improve Void. It's already pretty good.
https://voideditor.com/
https://github.com/voideditor/void
Is there a summary of the stance on training with user data for the main llms ?
I have a really hard time thinking that Google, Microsoft, Meta, etc... would _not_ train on whatever people enter (willingly or not in the system.)
The silver lining is that what most people enter in a chat box is _utter crap_.
So, training on that would make the "Artificial Intelligence" system less and less intelligent - unless the devs find a way to automagically sort clever things from stupid things, in which case I want to buy _that_ product.
In the long run, LLMs dev are going to have to either:
* refrain from getting high on their own supply, and find a way to tag AI generated content
* or sort the bs from the truth, probably reinventing "trust in gatekeepers and favoring sources of truth with a track record" and copying social pressure, etc... until we have a "pulitzer price" and "academy awards" for most relevant AI sources with a higher sticker price, to separate from cheap slop.
That, or "2+2=7 because DeepChatGrokmini said so, and if you don't agree you're a terrorist, and if our AI math breaks your rocket it's your fault."
Oh heck no I will opt out thanks. I guess they can still steal my code by having a "reviewer" access my chats for "suspicious behavior".
All models are trained on data obtained without consent. Now the “good guys of AI” want users to add their chats to the stack and the users balk? Hilarious.
There’s quite a few people on HN who hold Anthropic on a high pedestal compared to the other AI labs, I’d be curious to hear their opinion after this.
> unless users actively opt out by September 28th
Looks like there is an opt out option. Curious about the EU users - would that be off by default (so: opt in)?
Nope, it's opt out. I'm in ireland.
[dupe] https://news.ycombinator.com/item?id=45053806
The opt out alert apparently was confusing enough that I swear I opted out when it popped up yesterday, but I just checked and I was opted in.
I assumed they already were training on chats because they are a excellent source of data that is very likely to be from humans.
Whatever your secret projects and plans are, they’re now available to train up your competitors on what you’re doing!
lmarena did the same thing and saw its usage take a nosedive. I wonder if the same thing will happen here.
The next step is heavily advertising products in chat sessions based on your data
This is disappointing. I thought Anthropic was a more privacy and safety focused company and so I had chosen to use Claude Code over their competition. Now they are less privacy focused than Gemini Code, which only does this for the free tier. My work was already providing GitHub Copilot but I was rooting for and supporting Anthropic. Now I'll either just use GitHub Copilot or Gemini Code both of which are still private for paid tiers.
It's obvious this was going to happen. If you ever used any cloud AI model without acknowledging that at some point your data might be leaked (in one way or another) it's on you, not on them.
As some other user put it: "big corp changes policy and breaks promises, how shocking"
At least they didn't drop the "Don't be evil" clause quietly
All the bad news seem to drop on Friday. Is it just a coincidence?
No, it's a very deliberate strategy. Companies do this every Friday
As soon as Apple said it woll ship it in Xcode? what a coincidence!
I assumed they'd been doing it all along, regardless.
I wonder what type of people work for people that evil.
Ugh Anthropic please don't become the villain.
People who invested billions in Anthropic expect returns of tens of billions.
Too late.
AI-generated summaries should not be upvoted.
I went to claude.ai and saw a pop-over window with this choice, clicked to opt out and saw a "server error" alert. Then went to Settings > Privacy and the option wasn't there. I had to click something else (can't remember now) to see the option, which wasn't opted out (which kinda made sense because of the error message) and the option is now in Settings > Privacy. I'm definitely someone who believes that cock-up is more likely than conspiracy for things like this, but this process should have been bulletproof - no initial error message, option always in Settings > Privacy - given the sensitivities involved.
honest questions, what is the value of training over user chat? the answers are already provided by your LLM!
To start with, I'm sure there's something to be learned from all the times I've responded to a LLM with "Bad bot".
Can we change the url to https://www.anthropic.com/news/updates-to-our-consumer-terms instead of the slop post
Frankly I don't mind much if they use my js debugging conversation to train the next models; but there should be a way to mark specific conversations as private (possibly even an "incognito mode") to exclude them from any training or external access.
i found the ToS change to be surprisingly not a dark pattern.
in fact, i haven’t agreed to it yet, and was able to close the popup and continue using Claude. they also made it extremely clear how to opt out, providing the switch right in the popup and reminding me it’s also in settings.
when i eventually do have to agree to the ToS changes, i’ll probably just stay opted out.
Is user chat even that useful?
It has a toggle for opting out, but the buttons available are "Accept" and "Not Now". So, if I toggle off but click "Accept", does that accept what I toggled or accept data sharing? If I click "Not Now", do they leave it set at the default Opt-in?
I hate this shit and I'm cancelling now.
https://imgur.com/a/oCw5eEp
I clicked "Accept" because I didn't want to deal with it later, especially given the new terms, and Claude training on new chats and resuming existing chats from September 28th,
but the "Accept" and "Not Now" are for the new terms of use.
So by toggling off and clicking "Accept", it will accept the toggled version. You can check the setting after accepting it at: https://claude.ai/settings/data-privacy-controls It's the "Help Improve Claude" button.
never provide these services with personal data / identifiers.
This is going to improve the quality of LLM responses for users. I'm for this.
Good. LLMs progress is too stagnant, it was time they started to play seriously
Feeling cute, might put all your private conversation into my public LLM later
AI world sure seems to be going from AI is dangerous we need to be careful to max enshitification at break neck speeds.
Haha, grifters gonna grift.
In future news:
- Anthropic reverses stance on token limits, all plans cost double and limits are halved
- Anthropic introduces ad mode
- Anthropic partners with Palantir to deliver democracy at scale
This is getting to be more and more hilarious each day.
I'm shocked, shocked! Well, not that shocked. Did anyone really think the subsidy on Claude Code was not going to come back to this?
Maybe they are going to use an average vibe coder's chat to teach Claude to treat subpar developers differently? It could be a win-win outcome.
Nobody saw this coming, absolutely shocked!1!1!!!1
The bubble is deflating/popping. The MIT study has really dampened the excitement on AI.
Does this apply to existing chats as well?
I hear the sound of a million lawsuits in Europe concerning GDPR violations.
Not unless you go back and keep chatting in the existing chat.
Good, maybe it will stop spewing such shit code after training on my premium engineering ;)
Well, they've been using the whole internet and anything else they can get their hands on to train their models. If you are using LLMs and want to continue seeing them get better and more useful, you really have to accept that they train on data collected from their users. Unless there is another technology breakthrough somehow, this is going to be the best they can do to increase user satisfaction and make their product more useful.
TBH, I'd love to have a model which was specifically trained on conversation which I had with an earlier iteration. That would make it adapt to me and be less frustrating. Right now I'm relying only on instruction files to somewhat tune a model to my needs.