Large Language Models

Privacy evaluation of AI chatbot services. Analysed by Data Champion® based solely on information verified and published in each provider's privacy policy. Scores reflect data security, user control, and transparency practices.

Help improve our evaluations

Observed good or bad data practices in AI services? Your insights help the community make informed decisions.

Report Data Practices

🏆 Data Champion® Awards

Gold
82
Claude AI assistant interface by Anthropic showing a clean chat windowData Champion Gold Award

Claude

Anthropic

Free – $20/moLOW RISK

Privacy Highlights

  • Conversations not used to train models by default (API)
  • Users can opt out of training data use on Claude.ai
  • Data deletion requests honoured per privacy policy
Silver
78
Microsoft Copilot AI assistant interface integrated into Microsoft 365 productivity suite

Microsoft Copilot

Microsoft Corporation

Free – $30/user/moLOW RISK

Privacy Highlights

  • Enterprise customers: prompts and responses not used to train foundation models
  • Microsoft 365 Copilot data stays within Microsoft 365 compliance boundary
  • Supports EU Data Boundary for European customers
Bronze
72
ChatGPT conversational AI interface by OpenAI showing a text-based chat session

ChatGPT

OpenAI

Free – $20/moMEDIUM RISK

Privacy Highlights

  • Chat history can be turned off to prevent training use
  • Users can request deletion of their data
  • API data not used for training by default

Category Risk Assessment

Risk CategoryLevelDescription
Conversation Training UseHIGHMost LLMs use conversations to train models unless users opt out
Data JurisdictionHIGHServer location determines which laws govern your data
Human Review of ChatsMEDIUMSome providers allow staff to review conversations for safety/quality
Third-Party Data SharingMEDIUMData shared with vendors, affiliates, and service providers
Account & Profile LinkingMEDIUMLLMs linked to broader platform accounts can aggregate data profiles
Enterprise Data IsolationLOWPaid enterprise tiers typically offer stronger data separation guarantees

Product Comparison

ProductOverallData CollectionSecurityUser ControlTransparencyData UsagePrice
Claude AI assistant interface by Anthropic showing a clean chat window
Claude
Anthropic
82
8485828080Free – $20/mo
Microsoft Copilot AI assistant interface integrated into Microsoft 365 productivity suite
Microsoft Copilot
Microsoft Corporation
78
7686807474Free – $30/user/mo
ChatGPT conversational AI interface by OpenAI showing a text-based chat session
ChatGPT
OpenAI
72
6880767066Free – $20/mo
Google Gemini AI assistant interface showing multimodal conversation capabilities
Gemini
Google LLC
65
5878686258Free – $19.99/mo
Grok AI chatbot interface by xAI integrated within the X social media platform
Grok
xAI / X Corp
48
4260484444Included with X Premium ($8–$16/mo)
DeepSeek AI chat interface showing a minimalist conversation window
DeepSeek
DeepSeek AI (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.)
32
2838323030Free (API usage-based)

Privacy Policy Details

Claude

Anthropic

82
LOW RISK

✓ Privacy Positives

  • Conversations not used to train models by default (API)
  • Users can opt out of training data use on Claude.ai
  • Data deletion requests honoured per privacy policy
  • No sale of personal data stated in privacy policy
  • SOC 2 Type II certified infrastructure

✗ Privacy Concerns

  • Claude.ai conversations may be used for training unless opted out
  • Conversation data retained for up to 90 days by default
  • Third-party service providers may process data
View Official Privacy PolicyFull Privacy Review
Microsoft Copilot

Microsoft Corporation

78
LOW RISK

✓ Privacy Positives

  • Enterprise customers: prompts and responses not used to train foundation models
  • Microsoft 365 Copilot data stays within Microsoft 365 compliance boundary
  • Supports EU Data Boundary for European customers
  • ISO 27001, SOC 1 & 2 certified
  • Data subject rights (access, deletion, portability) supported

✗ Privacy Concerns

  • Consumer Copilot (Bing) conversations may inform model improvements
  • Microsoft collects usage and diagnostic data by default
  • Data may be shared with Microsoft affiliates and partners
  • Advertising personalisation applies in consumer tier
View Official Privacy PolicyFull Privacy Review
ChatGPT

OpenAI

72
MEDIUM RISK

✓ Privacy Positives

  • Chat history can be turned off to prevent training use
  • Users can request deletion of their data
  • API data not used for training by default
  • SOC 2 Type II and ISO 27001 certified
  • Memory feature can be disabled or cleared by user

✗ Privacy Concerns

  • Free-tier conversations used for model training unless opted out
  • Broad data collection including device info, usage patterns, and location
  • Data shared with third-party vendors and service providers
  • Conversation data retained for up to 30 days even after deletion request for safety review
  • No end-to-end encryption for conversations at rest
View Official Privacy PolicyFull Privacy Review
Gemini

Google LLC

65
MEDIUM RISK

✓ Privacy Positives

  • Gemini Apps Activity can be turned off in Google Account settings
  • Users can delete Gemini conversation history
  • Workspace (enterprise) data not used to train models
  • Google security infrastructure and encryption in transit
  • Data subject rights supported under GDPR and CCPA

✗ Privacy Concerns

  • Conversations reviewed by human reviewers to improve products (stated in policy)
  • Data linked to Google Account and integrated with broader Google data profile
  • Conversations retained for up to 18 months by default
  • Used to personalise Google ads unless opted out
  • Broad data sharing within Google product ecosystem
View Official Privacy PolicyFull Privacy Review
Grok

xAI / X Corp

48
HIGH RISK

✓ Privacy Positives

  • Users can request data deletion via X privacy settings
  • Grok conversations can be deleted from history
  • xAI privacy policy published and accessible

✗ Privacy Concerns

  • Conversations used to train xAI models by default; opt-out buried in settings
  • X platform posts (public and private) used as training data per X privacy policy
  • Data shared between xAI and X Corp with limited separation
  • Limited independent security audit disclosures
  • Privacy policy less detailed than competitors on data retention periods
  • No enterprise-grade data isolation tier available at time of review
View Official Privacy PolicyFull Privacy Review
DeepSeek

DeepSeek AI (Hangzhou DeepSeek Artificial Intelligence Co., Ltd.)

32
HIGH RISK

✓ Privacy Positives

  • Privacy policy published and accessible in English
  • Users can request account deletion

✗ Privacy Concerns

  • Data stored on servers in the People's Republic of China, subject to Chinese data laws
  • Chinese National Intelligence Law may compel data disclosure to authorities
  • Broad data collection including keystroke patterns and device fingerprinting (per published policy)
  • Conversation data used to train models; no opt-out mechanism described
  • Data shared with third parties including advertising partners
  • No independent third-party security audits disclosed
  • Banned or restricted for government and sensitive use in multiple countries
  • No EU data residency or adequacy decision coverage
View Official Privacy PolicyFull Privacy Review

Scoring Criteria

Data Collection (30%)
Minimal data gathering and retention practices
Security (25%)
Encryption, certifications, and infrastructure protection
User Control (20%)
Opt-outs, deletion rights, and privacy settings
Transparency (15%)
Clear, accessible policies and accountability
Data Usage (10%)
How data is used, shared, and monetised

Methodology note: All scores are based exclusively on information verified and published in each provider's official privacy policy at the time of review. Data Champion® does not accept payment from any provider reviewed on this page.