To be honest, these companies already stole terabytes of data and don't even disclose their dataset, so you have to assume they'll steal and train at anything you throw at them
"Reading stuff freely posted on the internet" is also very different from a business having machines consume large volumes of data posted on the Internet for the purpose of generating value for them without compensating the creators. I'm not making a value judgement one way or the other, but "reading stuff freely posted on the Internet" is an oversimplification.
I'm not talking about that, I'm taking about downloading gigabytes of books, and movies and who knows what data (since it's not disclosed) without paying. Those are not freely posted on the internet. Well, not legally anyways.
The reference to terabytes of stolen data refers to copyrighted material. I think you know this but chose to frame it as "stuff freely posted on the internet" in order to mislead and strawman the other comment.
Faithfully reproducing something you've previously read while passing it off as your own original work is a violation of the most basic tenets of intellectual property rights.
Forgot the 82TB of torrented books Meta has been using for training? I mean, yeah, it’s Meta. No surprise. But I won’t believe for one second that the other players didn’t do a similar thing. They just haven’t been caught yet.
"Reading stuff freely posted on the internet" that has copyrights to be used in your generative AI service is stealing, is a pretty basic interpretation of property rights.
You don't have to assume people are going to be bad, but it's reasonable and prudent to expect it from people who have already shown themselves to be so (in this context).
I trust people until they give me cause to do otherwise.
The hardest problem in computer science in 2025 is convincing people that you aren't loading every piece of their personal data into a machine learning training run.
The cynic in me wonders if part of Anthropic's decision process here was that, since nobody believes you when you say you're not using their data for training, you may as well do it anyway!
Giving people an opt-out might even increase trust, since people can now at least see an option that they control.
> The cynic in me wonders if part of Anthropic's decision process here was that, since nobody believes you when you say you're not using their data for training, you may as well do it anyway!
This is why I love-hate Anthro, the same way I love-hate Apple. The reason is simple: Great product, shitty MBA-fueled managerial decisions.
I don't understand this mindset. Why would you assume anything? It took me a couple minutes at most to check when I first started using Claude.
I check when I start using any new service. The cynical assumption that everything's being shared leads to shrugging it off and making no attempt to look for settings.
It only takes a moment to go into settings -> privacy and look.
Because they already used data without permission on a much larger scale, so it's a perfectly logical assumption that they would continue doing so with their users?
So your assumption is that the reported privacy policy of any company is completely accurate. There there is no means for the company to violate this policy and that once violated you will immediately be notified.
> It only takes a moment to go into settings -> privacy and look.
It only takes a moment to examine history and observe why this is wholly inadequate.
Because the demand for training data is insatiable and they already are using basically everything available and they need more human generated data and chats with their own LLM is a perfect source.
This. It's the same innocence of people who believe when you delete a document on Google/META/Apple/Microsoft servers, it "really" gets deleted. Google most likely has a backup of every piece of information indexed by them in the last 20 years or so. It would cause envy to the Internet Archive.
With the privacy laws out there, I do genuinely think they eventually get purged even from backups. I remember there being a really cool YouTube video shared here on HN that google no longer has publicly, it was about the process of an email and all the behind the scenes things, like physical security into a data center, to their patented hard drive shredders they use once the hard drives are to be tossed. I wish Google had kept that video public and online, it was a great watch.
I know once you delete something on Discord its poof, and that's the end of that. I've reported things that if anyone at Discord could access a copy of they would have called police. There's a lot of awful trolls on chat platforms that post awful things.
Officially, up to you if you believe they are following their policies, all of the companies have published statements on how long they keep their data after deletion (which customers broadly want to support recovery if something goes wrong).
Same, I thought the free accounts were always trained on. Which in my opinion is reasonable since you could delete the data you didn’t want to keep on the service.
But including paid accounts and doing 5 year retention however is confounding.
I mean, I am sure there are individuals, who still believe in the basic value of the word within the framework of our civilization, but, having seen those words not just twisted beyond recognition to fit a specific idea, but simply ignored when they were no longer convenient, it would be a surprise now that a cynical stance is not more common.
The question is: how does that affect their choices. How much ends up being gated what previously would have ended up in the open?
Me: I am using a local variant ( and attempting to build something I think I can control better ).
This going to turn into one of those situations where we find out they trained on everyone whether they opted-out or not down the line. I want to keep using Claude, but I also don't want all the solutions I come up with to become common knowledge.
"Healthline.com provided an opt-out mechanism, but it was misconfigured and Healthline failed to test it, resulting in data being shared with third parties even after consumers elected to opt out.”
"The company agreed to pay the US Federal Trade Commission (FTC) after it was accused of failing to delete Alexa recordings at the request of parents.”
"According to the [California Privacy Protection] agency, Todd Snyder told website visitors they could opt out of data sharing, but didn't actually allow them to do so for 40 days in late 2023 because its opt-out mechanism was improperly configured."
I think I'm fine with the whole getting better due to something helped it / co find with it. I'm not happy if it's directly 1:1 or attributed to me - chatham house rule for this would be great.
Why don't you want to share your insights? I agree doing it in a more direct way would be better than it leaking through AI training you don't control. But your phrasing seems stronger than that.
I wonder on how much they can rely on the data and what kind of "knowledge" they can extract. I never give feedback and most time (let's say 5 out of 6) the result cc produce it simply wrong. How can they know the result is valuable or not?
In general, I think any human generated content in pre-2022 is valuable because someone did some kind of validation (think about stack overflow answer with user confirming that a specific answer fixed their problem).
If they start to feed the next model with LLM generated crap, the overall performance will drop and instead of getting a useful answer 1 of 5 it will be 1 of 10(?) and probably a lot of us will cancel the subscription ... so in the end I think it matters.
Agreed. I actually want and need Claude and other LLMs to learn from my interactions with them. Exceedingly frustrating that LLMs do not yey hold a longterm memory or embedded trace of conversations per user. I have been asking Anthropic for this option as an opt-in for 6 months.
Sure, I understand the concerns many if you have.
But in my niche areas of cognitive research, genetics, and neurophilosophy I need Claude to be much smarter than it is now. I am happy to share what I know with Anthropic so that zi eventually have a better companion thinker.
Unbelievable. This is on par ethically with bad Meta decisions as far as privacy is concerned. What a dark pattern! What a mess! Look at this botched rollout... It's not ok to do this folks. This is literally what the modal looked like for me on chats that were already in progress. And NO I did not want them to train on this or ANY OF MY DATA UNDER A DIFFERENT CONTRACT.
Anthropic PR: "Ma'am, you opted IN to training on your therapy sessions and intellectual property and algorithms and salary and family history!" Don't you remember the modal???
Modern AI is built on data. Trusting that our conversations will not be used for training the model is a bit like giving a glutton their favourite food but making them promise not to eat it. Sure, why not.
I still expect that our conversations will not leave the premises (ie end up on the internet), because that would be something else, but other than that, I knew what I signed up for.
I don't know what they've been training on but I just canceled claude for the second time.
Besides the numerous UI bugs of the web interface, incessant flickerings, it has gotten weirdly super condescending and negative in a way I hadn't observed neither in the past nor with other llms.
Probably that people accused it of being sycophantic and they have tried to adjust it but they didn't do it well. It'd rather criticize and make assumptions about my behavior rather than keeping it technical. Ha!
I prefer gemini. Seems a bit stressed always assuming that I might be frustrated by its answers which is also weird to assume but it is not straight disrespectful at least.
They need adjustable dials like they do in some API interfaces for power users. Like a sycophancy dial, a safety dial or "turn off the child lock permanently" like they have for microwaves.
You're right. Was happening to me as well last week. Especially with the flash version.
I am trying the Pro version and it seems to be better. But you are absolutely correct, I've had similar experience.
What I have experienced with Claude was just another level though.
If you don't like Claude's personallity, ask him to behave differently. It's common for me to periodically say 'don't be so sycophantic' and 'be more critical' when working on technical projects.
In your case, try saying 'be nicer' or 'be more jovial'.
I had tried and it started being defensive about this too, haha.
Hence my flip-the-table reaction, deciding to just cancel my subscription.
Maybe I will come around later.
I don't think that retention part was clear at all. It was separate from the opt-out. I assume I'm now opted out but that they'll keep the data for five years anyway.
I can understand training AIs on books, and even internet forums, but I can't help but think that training an AI on lots of dumb questions with probably an excessive amount of grammar and spelling errors will somehow make it smarter.
Depends on how you’re using the data. There’s a pretty strong correctness signal in the user behavior.
Did they rephrase the question? Probably the first answer was wrong. Did the session end? Good chance the answer was acceptable. Did they ask follow-ups? What kind? Etc.
I'm used to doing the same task 4 or 5 times (different sessions, similar prompts), and most of the time the result is useless or completely wrong. Sometimes I go back and pick the first result, other time none of them, other time a mix of them. I'm wondering how can they extract value from this.
For those who do not, or cannot, read this announcement prior to September 28th (think people in the hospital, traveling, missed an email ..) is this not a total breach of contract?
Legally, I don't understand how Anthropic's lawyers would have allowed this. Maybe I am just naively optimistic about these matters? I am a Max customer and I might leave! Talk about a "rug pull" ... and I considering moving to an inferior provider! Privacy is a fundamental human right. Please do better, we have not learned our lesson in tech or society because no one is facing any consequences.
It only applies to new conversations, and they show a popup with this info in the app. Probably as a result of the legal team considering the options you listed.
I have never input anything into one of these tools that I wasn’t entirely comfortable with them using for training or any other reason. I just assumed it was happening.
I know this is probably not related, but this is right after the release of the AI safety index that praised Anthropic for not using user data… And here I was considering them because they did so much better on that test.
I kind of already assumed they were. I've got some pretty niche use-cases that I'd like to see the models get better at thinking their way through. I benefit from their training on my interactions. So I'll opt in.
But I'll also recognize that others might not feel that way, so the services should provide a way for users to opt out.
Wow, a 5 year retention. That seems so arbitrary and excessive. As someone who has been involved with privacy compliance, this is crazy. Does this apply for European users too? I don't know what the business justification for this would be but I am sure some lawyer could explain this better.
This is what I don't get. It's so much simpler to use the LLMs with other tools (aider for me) that I don't understand why people are avoiding the API creating monthly accounts to begin with. Is it cheaper? Is Claude Code really that awesome or something? By not even looking at it I guess I never have to know, but from where I sit it seems like people are just putting themselves through a lot of b.s. in order to marry a start-up.
"ccusage" is telling me I would have spent $2010.90 in the last month if I was paying via the API, rather than $200.
But also I do feel Claude Code is quite a bit better than other things I've used, when using the same model. I'm not sure why though, it's a fairly simple program with only a few prompts and only a few tools, it seems like others could catch up immediately by learning some lessons from it.
This needs to be a two way street ... one where we have programs that feed in piles of constant garbage unless they pay us for the privilege of clean data.
When things are free (in this case your input), they will get abused. Put a cost on it.
I use AI to solve problems, not to check the weather or deciding what to wear. As such it makes sense for AI to remember when it hits the nail on the head.
And if you solve a novel problem, Claude will happily take your reasoning and give it to the next user trying to solve the same novel problem. Imagine if that was a guy working for the competition :)
"If you choose not to allow us to use your chats and coding sessions to improve Claude, your chats will be retained in our back-end storage systems for up to 30 days."
You have it backwards. I'm paying $200/month and so I want the thing to reflect more what I want than what the general public wants. They'd better be mining my data, despite that being a term I haven't heard in over a decade.
Some people were upset that Google Maps would just take the data that contributors give it for free. My problem was different. I use Google Maps and I want a way to correct it. I don't want to be paid for this. I want the tool I'm using to be correctable by me. The more I pay for it, the more I want it to be editable by me. I don't want compensation. I want it to be better. And I can make it better.
It's sort of why we picked Kong at a different company. Open source core meant that we could edit stuff we didn't like. In fact, considering that we paid, we wanted them to upstream what we changed.
what are you doing with the data? What is your legacy going to be other than the data that you leave to be mined? Do you just not want something else to benefit from something that has no benefit to you? If so, why?
Rather misleading title. Missing the important “unless you ask them not to” part. Sounds like a bit of a dark pattern to push you into accepting it and that’s not cool, but you do get a choice.
You are right. To the best of my knowledge there has notbeen a way to share conversations with Anthropic, and therefore with future versions of Claudes. There was no Opt-in option as far as I know.
Straighten me out if I am wrong.
I need this opt-in to improve the foundational model that they have trained. It is good, but not good enough.
Let's say that I use LLM to develop novel software called X. Then my work is used to train the model. Then somebody uses the model to recreate a copy of the of the software X by prompt "create software that works just like X". My novel software is no longer unique. So how come I have not been deprived of anything?
Title is misleading, they're now opt-out rather than opt-in to your data being used for training. All you have to do is flip a single switch in the options to turn it off, I don't understand why everyone is treating this as being such a big deal.
Edit: I just logged in to opt out, they presented me with the switch directly. It was two clicks.
[Edit: turns out I've got it wrong, and 5-year retention only said to apply to the data they're allowed to train on. This changes things for me.]
Personally, I don't mind training, as long as I have a say on the matter - and they have a switch for this. Opt-out is not exactly cool, but I've got the popup in my face, almost a month before the changes, and that's respectful enough for me.
This said, I've just canceled my subscription because this new 5-year mandatory data retention is a deal breaker for me. I don't mind 30 or 60 days or even 90 days - I can understand the need to briefly persist the data. But for anything long-term (and 5 years is effectively permanent) I want to be respected with having a choice, and I'm provided none except for "don't use".
> any switch from opt-out-by-default to opt-in-by-default sucks
It’s the reverse. This was opt-in and is now opt-out. Opt means choose so when “the default is opt-in” it means the option is “no” by default and you have the option to make it “yes”.
i think skepticism is healthy, but they've handled this in a fairer way than any other online product i've used before.
they gave me a popup to agree to the ToS change, but I can ignore it for a month and still use the product. In the popup, they clearly explained the opt-out switch, which is available in the popup itself as well as in the settings.
I don't think it's good, but people both here and on reddit are acting like this is some Great Betrayal when it's just a single switch that they prominently present to you. If they're going to make this change, this is exactly how I'd want them to do it.
Odd that you are being down-voted for pointing out the easy opt-out option. I need this opt-in feature. I suppose the polarity of action could be a factor.
Maybe a value to users if done correctly. The way it is right now, you can't teach the model anything. When it gets something wrong, it will probably get the same thing wrong again in another chat.
Excellent. What were they waiting for up to now?? I thought they already trained on my data. I assume they train, even hope that they train, even when they say they don't. People that want to be data privacy maximalists - fine, don't use their data. But there are people out there (myself) that are on the opposite end of the spectrum, and we are mostly ignored by the companies. Companies just assume people only ever want to deny them their data.
It annoys me greatly, that I have no tick box on Google to tell them "go and adapt models I use on my Gmail, Photos, Maps etc." I don't want Google to ever be mistaken where I live - I have told them 100 times already.
This idea that "no one wants to share their data" is just assumed, and permeates everything. Like soft-ball interviews that a popular science communicator did with DeepMind folks working in medicine: every question was prefixed by litany of caveats that were all about 1) assumed aversion of people to sharing their data 2) horrors and disasters that are to befall us should we share the data. I have not suffered any horrors. I'm not aware of any major disasters. I'm aware of major advances in medicine in my lifetime. Ultimately the process does involve controlled data collection and experimentation. Looks a good deal to me tbh. I go out of my way to tick all the NHS boxes too, to "use my data as you see fit". It's an uphill struggle. The defaults are always "deny everything". Tick boxes never go away, there is no master checkbox "use any and all of my data and never ask me again" to tick.
> It annoys me greatly, that I have no tick box on Google to tell them "go and adapt models I use on my Gmail, Photos, Maps etc." I don't want Google to ever be mistaken where I live - I have told them 100 times already.
As we’ve seen LLMs be able to fully regenerate text from their sources (or at least close enough), aren’t you the least bit worried about your personal correspondence magically appearing in the wild?
I am a little bit worried, for sure. But I think that's small extra risk on my side, for small extra gain for me personally, but large extra gain for the wider group I belong to (ultimately - all of humanity) in the sense of working towards ameliorating the "tragedy of the commons".
On the personal side. Given the LLM-s have not got the ground truth, everything is controlled hallucination, then - if the LLM tells you an imperfect version of my email or chat, you can never be sure if what the LLM told you is true, or not. So maybe you don't gain that much extra knowledge about me. For example, you can reasonably guess I'm typing this on the computer, and having coffee too. So if you ask the LLM "tell me a trivial story", and LLM comes back with "one morning, LJ was typing HN replies on the computer while having his morning coffee" - did you learn that much new about me, that you didn't know or could guess before?
On the "tragedy of the commons" side. We all benefit immensely from other people sharing their data, even very personal data. Any drug discovery, testing, approval - relies on many people allowing their data to be shared. Wider context - living in a group of people, involves radiating data outwards, and using data other people emit towards myself (and others), to have a functioning society. The more advanced the society, the more coordination it needs to achieve the right cooperation-competition balance in the interactions between ever greater numbers of people.
I think it's bad for me personally, and for everyone, that the "data privacy maximalists" had their desires codified in UK laws. My personal experience in the UK medical systems has been that the laws made my life worse, not better. Wrote here https://news.ycombinator.com/item?id=45066321
If only you were just giving them your own data. In reality, you're giving them data about your friends, relatives, and coworkers without their consent. Let's stop pretending there is any way to opt out by simply not using these companies' services; it isn't true.
If you have an API key for a paid service, would you be OK with someone asking ChatGPT or VS Code Copilot for an API key for that service and getting yours, which they then use to rack up bills that you have to pay?
Maybe in the US. In the UK, I have found obstacles to data sharing codified in the UK law frustrating. I'm reasonably sure some people will have died because of this, that would not have died otherwise. "Otherwise" case being - if they could communicate with the NHS, similarly (via email, whatsapp) to how they communicate in their private and professional lives.
Within the UK NHS and UK private hospital care, these are my personal experiences.
1) Can't email my GP to pass information back-and-forth. GP withholds their email contact, I can't email them e.g. pictures of scans, or lab work reports. In theory they should have those already on their side. In practice they rarely do. The exchange of information goes sms->web link->web form->submit - for one single turn. There will be multiple turns. Most people just give up.
2) MRI scan private hospital made me jump 10 hops before sending me link, so I can download my MRI scans videos and pictures. Most people would have given up. There were several forks in the process where in retrospect could have delayed data DL even more.
3) Blood tests scheduling can't tell me back that scheduled blood test for a date failed. Apparently it's between too much to impossible for them to have my email address on record, and email me back that the test was scheduled, or the scheduling failed. And that I should re-run the process.
4) I would like to volunteer my data to benefit R&D in the NHS. I'm a user of medicinal services. I'm cognisant that all those are helping, but the process of establishing them relied on people unknown to me sharing very sensitive personal information. If it wasn't for those unknown to me people, I would be way worse off. I'd like to do the same, and be able to tell UK NHS "here are, my lab works reports, 100 GB of my DNA paid for by myself, my medical histories - take them all in, use them as you please."
In all cases vague mutterings of "data protection... GDPR..." have been relayed back as "reasons". I take it's mostly B/S. Yes there are obstacles, but the staff could work around if they wanted to. However there is a kernel of truth - it's easier for them to not try to share, it's less work and less risk, so the laws are used as a cover leaf. (in the worst case - an alibi for laziness.)
This is a problem for folks with sensitive data, and also for coorporate users who don't want their data being used for it due to all kinds of liability issues.
I am sure they will have a coorporate carve out, otherwise it makes them unusuable for some large corps.
I think the real frustrating part is that they're using your data, scanning every driver's license etc that comes onto the google play store-- and there's still scammers etc using official google products that people catch everyday on twitter now that scambaiting is becoming a popular pastime.
To be honest, these companies already stole terabytes of data and don't even disclose their dataset, so you have to assume they'll steal and train at anything you throw at them
"Reading stuff freely posted on the internet" constitutes stealing now?
Seems like an excessively draconian interpretation of property rights.
"Reading stuff freely posted on the internet" is also very different from a business having machines consume large volumes of data posted on the Internet for the purpose of generating value for them without compensating the creators. I'm not making a value judgement one way or the other, but "reading stuff freely posted on the Internet" is an oversimplification.
34 replies →
I'm not talking about that, I'm taking about downloading gigabytes of books, and movies and who knows what data (since it's not disclosed) without paying. Those are not freely posted on the internet. Well, not legally anyways.
This is a quintessential bad faith comment.
The reference to terabytes of stolen data refers to copyrighted material. I think you know this but chose to frame it as "stuff freely posted on the internet" in order to mislead and strawman the other comment.
8 replies →
Faithfully reproducing something you've previously read while passing it off as your own original work is a violation of the most basic tenets of intellectual property rights.
Forgot the 82TB of torrented books Meta has been using for training? I mean, yeah, it’s Meta. No surprise. But I won’t believe for one second that the other players didn’t do a similar thing. They just haven’t been caught yet.
so I can take a screenshot from a movie trailer on YouTube and sell posters of it now? I thought copyright still applied to the poor.
What "reading"?
4 replies →
"Reading stuff freely posted on the internet" that has copyrights to be used in your generative AI service is stealing, is a pretty basic interpretation of property rights.
As long as people are being prosecuted for piracy or having their livelihoods compromised for including a 16 second clip of a song, yes.
They stole all that data on the internet yet it’s still not enough and now they want everything on your local drive as well.
No you don't. You don't have to assume people are going to be bad! We should not normalize it either.
You don't have to assume people are going to be bad, but it's reasonable and prudent to expect it from people who have already shown themselves to be so (in this context).
I trust people until they give me cause to do otherwise.
2 replies →
You can and should safely assume people can do anything that's possible to do. Weather something is bad or good is a term of historical debate.
1 reply →
Yours is the sanest interpretation of this.
Am I the only one that assumed everything was already being used for training?
The hardest problem in computer science in 2025 is convincing people that you aren't loading every piece of their personal data into a machine learning training run.
The cynic in me wonders if part of Anthropic's decision process here was that, since nobody believes you when you say you're not using their data for training, you may as well do it anyway!
Giving people an opt-out might even increase trust, since people can now at least see an option that they control.
> The cynic in me wonders if part of Anthropic's decision process here was that, since nobody believes you when you say you're not using their data for training, you may as well do it anyway!
This is why I love-hate Anthro, the same way I love-hate Apple. The reason is simple: Great product, shitty MBA-fueled managerial decisions.
I don't understand this mindset. Why would you assume anything? It took me a couple minutes at most to check when I first started using Claude.
I check when I start using any new service. The cynical assumption that everything's being shared leads to shrugging it off and making no attempt to look for settings.
It only takes a moment to go into settings -> privacy and look.
>Why would you assume anything?
Because they already used data without permission on a much larger scale, so it's a perfectly logical assumption that they would continue doing so with their users?
5 replies →
Huh, they’re not assuming anything is “being shared”.
They’re assuming that Anthropic that is already receiving and storing your data, is also training their models on that data.
How are you supposed to disprove that as a user?
Also, the whole point is that companies cannot be trusted to follow the settings.
6 replies →
> I check when I start using any new service.
So your assumption is that the reported privacy policy of any company is completely accurate. There there is no means for the company to violate this policy and that once violated you will immediately be notified.
> It only takes a moment to go into settings -> privacy and look.
It only takes a moment to examine history and observe why this is wholly inadequate.
> It only takes a moment to go into settings -> privacy and look.
Do you have any reason to think this does anything?
2 replies →
Because the demand for training data is insatiable and they already are using basically everything available and they need more human generated data and chats with their own LLM is a perfect source.
A silicon valley startup would never say one thing and then do another!
Bro really thinks privacy settings work
This. It's the same innocence of people who believe when you delete a document on Google/META/Apple/Microsoft servers, it "really" gets deleted. Google most likely has a backup of every piece of information indexed by them in the last 20 years or so. It would cause envy to the Internet Archive.
With the privacy laws out there, I do genuinely think they eventually get purged even from backups. I remember there being a really cool YouTube video shared here on HN that google no longer has publicly, it was about the process of an email and all the behind the scenes things, like physical security into a data center, to their patented hard drive shredders they use once the hard drives are to be tossed. I wish Google had kept that video public and online, it was a great watch.
I know once you delete something on Discord its poof, and that's the end of that. I've reported things that if anyone at Discord could access a copy of they would have called police. There's a lot of awful trolls on chat platforms that post awful things.
5 replies →
Officially, up to you if you believe they are following their policies, all of the companies have published statements on how long they keep their data after deletion (which customers broadly want to support recovery if something goes wrong).
- Google: active storage for "around 2 months from the time of deletion" and in backups "for up to 6 months": https://policies.google.com/technologies/retention?hl=en-US
- Meta: 90 days: https://www.meta.com/help/quest/609965707113909/
- Apple/iCloud: 30 days: https://support.apple.com/guide/icloud/delete-files-mm3b7fcd...
- Microsoft: 30-180 days: https://learn.microsoft.com/en-us/compliance/assurance/assur...
So if it ends up that they are storing data longer there can be consequences (GDPR, CCPA, FTC).
1 reply →
Same, I thought the free accounts were always trained on. Which in my opinion is reasonable since you could delete the data you didn’t want to keep on the service.
But including paid accounts and doing 5 year retention however is confounding.
I mean, I am sure there are individuals, who still believe in the basic value of the word within the framework of our civilization, but, having seen those words not just twisted beyond recognition to fit a specific idea, but simply ignored when they were no longer convenient, it would be a surprise now that a cynical stance is not more common.
The question is: how does that affect their choices. How much ends up being gated what previously would have ended up in the open?
Me: I am using a local variant ( and attempting to build something I think I can control better ).
You are not.
You wouldn’t have needed to assume if you had read their previous policy.
... and your assumptions were wrong until now. Not sure that's much of a dunk as you think it seems
Nope. I always assumed they were and acted accordingly.
This going to turn into one of those situations where we find out they trained on everyone whether they opted-out or not down the line. I want to keep using Claude, but I also don't want all the solutions I come up with to become common knowledge.
When has a company ignored an opt-out preference before? It sounds like you have something in mind.
Not the OP but…
https://www.jdsupra.com/legalnews/healthline-media-agrees-to...
"Healthline.com provided an opt-out mechanism, but it was misconfigured and Healthline failed to test it, resulting in data being shared with third parties even after consumers elected to opt out.”
https://www.bbc.com/news/technology-65772154
"The company agreed to pay the US Federal Trade Commission (FTC) after it was accused of failing to delete Alexa recordings at the request of parents.”
https://www.mediapost.com/publications/article/405635/califo...
"According to the [California Privacy Protection] agency, Todd Snyder told website visitors they could opt out of data sharing, but didn't actually allow them to do so for 40 days in late 2023 because its opt-out mechanism was improperly configured."
I think I'm fine with the whole getting better due to something helped it / co find with it. I'm not happy if it's directly 1:1 or attributed to me - chatham house rule for this would be great.
That’s impossible. You can’t anonymize data at scale.
Why don't you want to share your insights? I agree doing it in a more direct way would be better than it leaking through AI training you don't control. But your phrasing seems stronger than that.
So, I guess they run out of data to train on ...
I wonder on how much they can rely on the data and what kind of "knowledge" they can extract. I never give feedback and most time (let's say 5 out of 6) the result cc produce it simply wrong. How can they know the result is valuable or not?
Maybe they can use same method as Google does - if user clicked a link and didn't try to search again, it can assume the link had intended result.
So your silence can be used as a warmish signal that you were satisfied. (...or not. Depends on your usage fingerprint.)
I expect that's a very weak signal. When I ask a question and get a completely wrong answer from Claude I usually drop the chat and look elsewhere.
How can they know anything they train on is valuable?
At the end of the day it doesn't matter. You got the wrong answer and didn't complain, so why would they care?
In general, I think any human generated content in pre-2022 is valuable because someone did some kind of validation (think about stack overflow answer with user confirming that a specific answer fixed their problem).
If they start to feed the next model with LLM generated crap, the overall performance will drop and instead of getting a useful answer 1 of 5 it will be 1 of 10(?) and probably a lot of us will cancel the subscription ... so in the end I think it matters.
I just logged in on the iOS app and it immediately had a popup giving me the option to opt-out.
So yeah, annoying, but they handled it well.
Agreed. I actually want and need Claude and other LLMs to learn from my interactions with them. Exceedingly frustrating that LLMs do not yey hold a longterm memory or embedded trace of conversations per user. I have been asking Anthropic for this option as an opt-in for 6 months.
Sure, I understand the concerns many if you have.
But in my niche areas of cognitive research, genetics, and neurophilosophy I need Claude to be much smarter than it is now. I am happy to share what I know with Anthropic so that zi eventually have a better companion thinker.
Unbelievable. This is on par ethically with bad Meta decisions as far as privacy is concerned. What a dark pattern! What a mess! Look at this botched rollout... It's not ok to do this folks. This is literally what the modal looked like for me on chats that were already in progress. And NO I did not want them to train on this or ANY OF MY DATA UNDER A DIFFERENT CONTRACT.
Anthropic PR: "Ma'am, you opted IN to training on your therapy sessions and intellectual property and algorithms and salary and family history!" Don't you remember the modal???
The Modal: https://imgur.com/afqMi0Z
Dupe: https://news.ycombinator.com/item?id=45062683
At least this submission has the original text Anthropic sent out to people :) But yeah, Perplexity gives a better summary for outsiders I guess.
Modern AI is built on data. Trusting that our conversations will not be used for training the model is a bit like giving a glutton their favourite food but making them promise not to eat it. Sure, why not.
I still expect that our conversations will not leave the premises (ie end up on the internet), because that would be something else, but other than that, I knew what I signed up for.
Don't normalize this. There are contractual obligations that we have to enforce in order to keep our privacy and humanity.
I don't know what they've been training on but I just canceled claude for the second time. Besides the numerous UI bugs of the web interface, incessant flickerings, it has gotten weirdly super condescending and negative in a way I hadn't observed neither in the past nor with other llms.
Probably that people accused it of being sycophantic and they have tried to adjust it but they didn't do it well. It'd rather criticize and make assumptions about my behavior rather than keeping it technical. Ha!
I prefer gemini. Seems a bit stressed always assuming that I might be frustrated by its answers which is also weird to assume but it is not straight disrespectful at least.
So I am back to testing chatgpt. I keep changing.
They need adjustable dials like they do in some API interfaces for power users. Like a sycophancy dial, a safety dial or "turn off the child lock permanently" like they have for microwaves.
I’ve found Gemini argumentative and maybe condescending too.
Mistral feels like a good balance between haughtiness and sycophantism.
You're right. Was happening to me as well last week. Especially with the flash version. I am trying the Pro version and it seems to be better. But you are absolutely correct, I've had similar experience. What I have experienced with Claude was just another level though.
If you don't like Claude's personallity, ask him to behave differently. It's common for me to periodically say 'don't be so sycophantic' and 'be more critical' when working on technical projects.
In your case, try saying 'be nicer' or 'be more jovial'.
I had tried and it started being defensive about this too, haha. Hence my flip-the-table reaction, deciding to just cancel my subscription. Maybe I will come around later.
$COMPANY reneged on their solemn pinky promise to not do the bad thing this time? Quelle surprise!
It is optional. I want the sharing option.
You can opt out. It’s written quit quite clearly
I don't think that retention part was clear at all. It was separate from the opt-out. I assume I'm now opted out but that they'll keep the data for five years anyway.
You want them to flush your conversations on your own schedule. That I can understand. If you delete a conversation it should be DELETED.
With the amount of times Claude is visiting my websites I'd say they are very desperate for data.
I can understand training AIs on books, and even internet forums, but I can't help but think that training an AI on lots of dumb questions with probably an excessive amount of grammar and spelling errors will somehow make it smarter.
Depends on how you’re using the data. There’s a pretty strong correctness signal in the user behavior.
Did they rephrase the question? Probably the first answer was wrong. Did the session end? Good chance the answer was acceptable. Did they ask follow-ups? What kind? Etc.
I'm used to doing the same task 4 or 5 times (different sessions, similar prompts), and most of the time the result is useless or completely wrong. Sometimes I go back and pick the first result, other time none of them, other time a mix of them. I'm wondering how can they extract value from this.
> Did the session end? Good chance the answer was acceptable.
Or that the user just ragequit
Doubt they feed everything in. They probably pick out a small subset of conversations for the training round.
They train AI on Reddit and Stack Overflow questions, I can't see it getting any worse.
> and even internet forums
i would consider internet forums also includes a lot of dumb questions
Agree, but people generally take a small pause before saying stuff online.
In 'private', people are less ashamed of their ignorance, and also know they can say gibberish and the AI will figure it out.
Like what?
For those who do not, or cannot, read this announcement prior to September 28th (think people in the hospital, traveling, missed an email ..) is this not a total breach of contract?
Legally, I don't understand how Anthropic's lawyers would have allowed this. Maybe I am just naively optimistic about these matters? I am a Max customer and I might leave! Talk about a "rug pull" ... and I considering moving to an inferior provider! Privacy is a fundamental human right. Please do better, we have not learned our lesson in tech or society because no one is facing any consequences.
It only applies to new conversations, and they show a popup with this info in the app. Probably as a result of the legal team considering the options you listed.
You mean this popup?
https://imgur.com/afqMi0Z
1 reply →
I have never input anything into one of these tools that I wasn’t entirely comfortable with them using for training or any other reason. I just assumed it was happening.
see other discussion https://news.ycombinator.com/item?id=45062683
I know this is probably not related, but this is right after the release of the AI safety index that praised Anthropic for not using user data… And here I was considering them because they did so much better on that test.
https://futureoflife.org/ai-safety-index-summer-2025/
I kind of already assumed they were. I've got some pretty niche use-cases that I'd like to see the models get better at thinking their way through. I benefit from their training on my interactions. So I'll opt in. But I'll also recognize that others might not feel that way, so the services should provide a way for users to opt out.
Ditto: was delighted to see this as an option. Am I missing some details? I do not understand the comments in “rug pulls”.
Wow, a 5 year retention. That seems so arbitrary and excessive. As someone who has been involved with privacy compliance, this is crazy. Does this apply for European users too? I don't know what the business justification for this would be but I am sure some lawyer could explain this better.
Criminal, evil thieves.
"If you use Claude for Work, via the API, or other services under our Commercial Terms or other Agreements, then these changes don't apply to you."
This is what I don't get. It's so much simpler to use the LLMs with other tools (aider for me) that I don't understand why people are avoiding the API creating monthly accounts to begin with. Is it cheaper? Is Claude Code really that awesome or something? By not even looking at it I guess I never have to know, but from where I sit it seems like people are just putting themselves through a lot of b.s. in order to marry a start-up.
> Is it cheaper?
"ccusage" is telling me I would have spent $2010.90 in the last month if I was paying via the API, rather than $200.
But also I do feel Claude Code is quite a bit better than other things I've used, when using the same model. I'm not sure why though, it's a fairly simple program with only a few prompts and only a few tools, it seems like others could catch up immediately by learning some lessons from it.
1 reply →
According to Claude cost I get about 5x value in token cost by having a max subscription.
I upgraded after I hit the equivalent spend in API fees in a month.
This needs to be a two way street ... one where we have programs that feed in piles of constant garbage unless they pay us for the privilege of clean data.
When things are free (in this case your input), they will get abused. Put a cost on it.
Thanks for informing me, I've opted out.
Generally I upvote chats which gives my chat to anthropic when I feel like sharing, I'll keep doing that like before with this opted out.
i logged on and they did ask right away in a popup window.
I use AI to solve problems, not to check the weather or deciding what to wear. As such it makes sense for AI to remember when it hits the nail on the head.
And if you solve a novel problem, Claude will happily take your reasoning and give it to the next user trying to solve the same novel problem. Imagine if that was a guy working for the competition :)
Agreed. Typically I would be against something like this, but in this case, have it.
How do you feel about this data being used to target advertising at you in the inevitable rush to monetize these AI products?
3 replies →
[dupe] https://news.ycombinator.com/item?id=45053806
If you're plan to keep improving LLM's is based on more training, then we have an AI hype problem.
I always assumed they were. I've been masking / scrubbing my test data this whole time.
isn't this just a change from opt-in to opt-out? will make a big difference but still gives individuals control of their data governance
i'm fine with it. happy to seed.
"If you choose not to allow us to use your chats and coding sessions to improve Claude, your chats will be retained in our back-end storage systems for up to 30 days."
"going forward" ;-)
..and there goes our authorization to use it at work
and now the LLM gets to observe itself, heh heh heh
I’m fine with that.
you are fine with paying, 20, 90 or 200 euros a month AND having your data mined? i must be getting old...
You have it backwards. I'm paying $200/month and so I want the thing to reflect more what I want than what the general public wants. They'd better be mining my data, despite that being a term I haven't heard in over a decade.
Some people were upset that Google Maps would just take the data that contributors give it for free. My problem was different. I use Google Maps and I want a way to correct it. I don't want to be paid for this. I want the tool I'm using to be correctable by me. The more I pay for it, the more I want it to be editable by me. I don't want compensation. I want it to be better. And I can make it better.
It's sort of why we picked Kong at a different company. Open source core meant that we could edit stuff we didn't like. In fact, considering that we paid, we wanted them to upstream what we changed.
1 reply →
It's a tool that dependson data mining everything. The only surprise is that they weren't already data mining what people feed into it.
what are you doing with the data? What is your legacy going to be other than the data that you leave to be mined? Do you just not want something else to benefit from something that has no benefit to you? If so, why?
10 replies →
Rather misleading title. Missing the important “unless you ask them not to” part. Sounds like a bit of a dark pattern to push you into accepting it and that’s not cool, but you do get a choice.
You are right. To the best of my knowledge there has notbeen a way to share conversations with Anthropic, and therefore with future versions of Claudes. There was no Opt-in option as far as I know.
Straighten me out if I am wrong.
I need this opt-in to improve the foundational model that they have trained. It is good, but not good enough.
"Training" is now a euphemism for stealing. Guess I can't write any production level code w/ this...
Some people would say that since the owner isn't being deprived of anything, it's not stealing.
Let's say that I use LLM to develop novel software called X. Then my work is used to train the model. Then somebody uses the model to recreate a copy of the of the software X by prompt "create software that works just like X". My novel software is no longer unique. So how come I have not been deprived of anything?
1 reply →
Title is misleading, they're now opt-out rather than opt-in to your data being used for training. All you have to do is flip a single switch in the options to turn it off, I don't understand why everyone is treating this as being such a big deal.
Edit: I just logged in to opt out, they presented me with the switch directly. It was two clicks.
[Edit: turns out I've got it wrong, and 5-year retention only said to apply to the data they're allowed to train on. This changes things for me.]
Personally, I don't mind training, as long as I have a say on the matter - and they have a switch for this. Opt-out is not exactly cool, but I've got the popup in my face, almost a month before the changes, and that's respectful enough for me.
This said, I've just canceled my subscription because this new 5-year mandatory data retention is a deal breaker for me. I don't mind 30 or 60 days or even 90 days - I can understand the need to briefly persist the data. But for anything long-term (and 5 years is effectively permanent) I want to be respected with having a choice, and I'm provided none except for "don't use".
A shame, but fortunately they're not a monopoly.
Data retention appears to be predicated on opting in to allowing training. If you don't opt in, they retain it for the same 30 days they were already retaining it for. https://www.anthropic.com/news/updates-to-our-consumer-terms
1 reply →
I think any switch from opt-out-by-default to opt-in-by-default sucks, especially when it has no clear immediate benefit to the person being opted in.
Disclaimer: not a Claude user (not even a prospective one)
> any switch from opt-out-by-default to opt-in-by-default sucks
It’s the reverse. This was opt-in and is now opt-out. Opt means choose so when “the default is opt-in” it means the option is “no” by default and you have the option to make it “yes”.
3 replies →
i think skepticism is healthy, but they've handled this in a fairer way than any other online product i've used before.
they gave me a popup to agree to the ToS change, but I can ignore it for a month and still use the product. In the popup, they clearly explained the opt-out switch, which is available in the popup itself as well as in the settings.
I don't think it's good, but people both here and on reddit are acting like this is some Great Betrayal when it's just a single switch that they prominently present to you. If they're going to make this change, this is exactly how I'd want them to do it.
2 replies →
Odd that you are being down-voted for pointing out the easy opt-out option. I need this opt-in feature. I suppose the polarity of action could be a factor.
No thats BS, lots of people wont know the default got flipped
There's a huge popup the first time you log in now
Maybe a value to users if done correctly. The way it is right now, you can't teach the model anything. When it gets something wrong, it will probably get the same thing wrong again in another chat.
That's not how LLMs work.
Im all in for the ai hate, but this kind of hysteria on HN is devaluing all the serious discussions about AI safety, skepticism and regulation.
They literally show you a full-page popup with clear text snd OPT IN toggle. It doesn’t seem really shady to me (or worth 10 separate posts on HN).
That said, if this popup doesn’t appear when you sign up after 28th, that would be a dark pattern and shady stuff. For now it’s just clickbait
Excellent. What were they waiting for up to now?? I thought they already trained on my data. I assume they train, even hope that they train, even when they say they don't. People that want to be data privacy maximalists - fine, don't use their data. But there are people out there (myself) that are on the opposite end of the spectrum, and we are mostly ignored by the companies. Companies just assume people only ever want to deny them their data.
It annoys me greatly, that I have no tick box on Google to tell them "go and adapt models I use on my Gmail, Photos, Maps etc." I don't want Google to ever be mistaken where I live - I have told them 100 times already.
This idea that "no one wants to share their data" is just assumed, and permeates everything. Like soft-ball interviews that a popular science communicator did with DeepMind folks working in medicine: every question was prefixed by litany of caveats that were all about 1) assumed aversion of people to sharing their data 2) horrors and disasters that are to befall us should we share the data. I have not suffered any horrors. I'm not aware of any major disasters. I'm aware of major advances in medicine in my lifetime. Ultimately the process does involve controlled data collection and experimentation. Looks a good deal to me tbh. I go out of my way to tick all the NHS boxes too, to "use my data as you see fit". It's an uphill struggle. The defaults are always "deny everything". Tick boxes never go away, there is no master checkbox "use any and all of my data and never ask me again" to tick.
> It annoys me greatly, that I have no tick box on Google to tell them "go and adapt models I use on my Gmail, Photos, Maps etc." I don't want Google to ever be mistaken where I live - I have told them 100 times already.
As we’ve seen LLMs be able to fully regenerate text from their sources (or at least close enough), aren’t you the least bit worried about your personal correspondence magically appearing in the wild?
I am a little bit worried, for sure. But I think that's small extra risk on my side, for small extra gain for me personally, but large extra gain for the wider group I belong to (ultimately - all of humanity) in the sense of working towards ameliorating the "tragedy of the commons".
On the personal side. Given the LLM-s have not got the ground truth, everything is controlled hallucination, then - if the LLM tells you an imperfect version of my email or chat, you can never be sure if what the LLM told you is true, or not. So maybe you don't gain that much extra knowledge about me. For example, you can reasonably guess I'm typing this on the computer, and having coffee too. So if you ask the LLM "tell me a trivial story", and LLM comes back with "one morning, LJ was typing HN replies on the computer while having his morning coffee" - did you learn that much new about me, that you didn't know or could guess before?
On the "tragedy of the commons" side. We all benefit immensely from other people sharing their data, even very personal data. Any drug discovery, testing, approval - relies on many people allowing their data to be shared. Wider context - living in a group of people, involves radiating data outwards, and using data other people emit towards myself (and others), to have a functioning society. The more advanced the society, the more coordination it needs to achieve the right cooperation-competition balance in the interactions between ever greater numbers of people.
I think it's bad for me personally, and for everyone, that the "data privacy maximalists" had their desires codified in UK laws. My personal experience in the UK medical systems has been that the laws made my life worse, not better. Wrote here https://news.ycombinator.com/item?id=45066321
If only you were just giving them your own data. In reality, you're giving them data about your friends, relatives, and coworkers without their consent. Let's stop pretending there is any way to opt out by simply not using these companies' services; it isn't true.
If you have an API key for a paid service, would you be OK with someone asking ChatGPT or VS Code Copilot for an API key for that service and getting yours, which they then use to rack up bills that you have to pay?
The fact you are not aware of abuse, or abuse has not yet happened to you, does not mean it isn't a problem for you.
> The defaults are always "deny everything".
This is definitely not true for a massive amount of things, I'm unsure how you're even arriving at this conclusion.
Maybe in the US. In the UK, I have found obstacles to data sharing codified in the UK law frustrating. I'm reasonably sure some people will have died because of this, that would not have died otherwise. "Otherwise" case being - if they could communicate with the NHS, similarly (via email, whatsapp) to how they communicate in their private and professional lives.
Within the UK NHS and UK private hospital care, these are my personal experiences.
1) Can't email my GP to pass information back-and-forth. GP withholds their email contact, I can't email them e.g. pictures of scans, or lab work reports. In theory they should have those already on their side. In practice they rarely do. The exchange of information goes sms->web link->web form->submit - for one single turn. There will be multiple turns. Most people just give up.
2) MRI scan private hospital made me jump 10 hops before sending me link, so I can download my MRI scans videos and pictures. Most people would have given up. There were several forks in the process where in retrospect could have delayed data DL even more.
3) Blood tests scheduling can't tell me back that scheduled blood test for a date failed. Apparently it's between too much to impossible for them to have my email address on record, and email me back that the test was scheduled, or the scheduling failed. And that I should re-run the process.
4) I would like to volunteer my data to benefit R&D in the NHS. I'm a user of medicinal services. I'm cognisant that all those are helping, but the process of establishing them relied on people unknown to me sharing very sensitive personal information. If it wasn't for those unknown to me people, I would be way worse off. I'd like to do the same, and be able to tell UK NHS "here are, my lab works reports, 100 GB of my DNA paid for by myself, my medical histories - take them all in, use them as you please."
In all cases vague mutterings of "data protection... GDPR..." have been relayed back as "reasons". I take it's mostly B/S. Yes there are obstacles, but the staff could work around if they wanted to. However there is a kernel of truth - it's easier for them to not try to share, it's less work and less risk, so the laws are used as a cover leaf. (in the worst case - an alibi for laziness.)
This is a problem for folks with sensitive data, and also for coorporate users who don't want their data being used for it due to all kinds of liability issues.
I am sure they will have a coorporate carve out, otherwise it makes them unusuable for some large corps.
“Claude, please write and commit this as if you were ljosifov. Yes, please use his GitHub token, thank you”
I think the real frustrating part is that they're using your data, scanning every driver's license etc that comes onto the google play store-- and there's still scammers etc using official google products that people catch everyday on twitter now that scambaiting is becoming a popular pastime.