← All tools

The Privacy Cost of Sending Your Data Out

Every other calculator here prices money. This one prices the other thing you spend when you use a hosted model: what the provider is allowed to keep, for how long, and whether you can turn it off. Read from each provider's own terms, with the baseline being the machine on your desk — which keeps nothing, because nothing leaves it.

A small aluminium padlock with a copper shackle.
Provider / tierWhat it does with your dataRetention (days)Zero-retentionSource
Running it on your own machineNothing leaves0n/ano terms to change under you
Google — Gemini app (AI Pro / Ultra)
consumer-paid
Trains on your data

Google's own privacy hub makes NO distinction between free and paid subscribers for training, human review, retention or Keep Activity behaviour.

1095 · ~3ynone offeredprovider terms
read 2026-07-06
Google — Gemini app (free)
consumer-free
Trains on your data

"Keep Activity" is ON by default; while on, Google uses conversations to develop and improve its services, including training generative AI models. A subset of chats also get human review.

1095 · ~3ynone offeredprovider terms
read 2026-07-06
Google — Gemini API (paid)
api-standard
Kept, no way out

Google does not use prompts or responses to improve its products on the paid/enterprise Gemini API tier.

unstatednone offeredprovider terms
read 2026-07-06
Meta — Llama API (first-party, sunset)
api-standard
Kept, no way out

Meta does not train its models on Llama API customer content; data is used only to provide the service, enforce the acceptable-use policy and comply with law.

unstatednone offeredprovider terms
read 2026-07-06
Anthropic — API
api-standard
Kept, but you can opt out

Default no-train for commercial products. Exception: explicit thumbs-up/down feedback may be used, de-linked from identity, retained up to 5 years; admins can disable feedback collection org-wide.

unstatedavailableprovider terms
read 2026-07-06
Llama via Together AI
api-standard-together
Kept, but you can opt out

Data sharing for training other models is opt-in and not enabled by default; Together does not store inputs or outputs by default, i.e. it supports zero data retention.

unstatedavailableprovider terms
read 2026-07-06
Mistral — API
api-standard
Kept, but you can opt out

Mistral will not use customer data or outputs to train its models by default, except for free-subscription products not opted out, explicit feedback, moderation-flagged data, or per an order form.

30availableprovider terms
read 2026-07-06
OpenAI — API
api-standard
Kept, but you can opt out

Data sent to the API is not used to train or improve models unless the customer explicitly opts in — policy in effect since March 2023.

30availableprovider terms
read 2026-07-06

Google — Gemini app (AI Pro / Ultra)The finding worth the whole table: paying for Google AI Pro or Ultra does NOT opt you out of training or human review. The same toggle governs both tiers, from the same source page. Workspace-embedded Gemini carries its own separate no-train commitment and is not this row.

Google — Gemini app (free)Human-reviewed chats are retained up to 3 years EVEN AFTER you delete your activity, disconnected from the account. With Keep Activity off, non-reviewed conversations are kept about 72 hours.

Google — Gemini API (paid)No zero-retention option is mentioned in the terms. Logs are kept "for a limited period" with no day count given, for abuse detection and legal compliance. Search grounding stores data 30 days regardless of tier.

Meta — Llama API (first-party, sunset)Meta's own first-party Llama API was sunset on 2026-07-06 — the same day these terms were read. Kept in the table as the record of what it promised; the commercially live path is the Together row below.

Anthropic — APIZero-retention eligible on the Messages and Token Counting APIs, but some stateful features (Files, Batch, code execution) are NOT eligible even under an org ZDR arrangement. Retention is left blank because it varies by feature rather than being one org-wide number.

Llama via Together AINot a Meta first-party tier — this is the commercial route to Llama actually used for pricing. Deliberately a distinct tier value so Meta's dying API and its replacement are never confused. No day count is given beyond 'does not store by default'.

Mistral — APIThe 30 days is the post-termination purge window stated in the DPA, NOT a confirmed per-request retention TTL — a distinction worth keeping. Zero data retention is available and referenced directly in the DPA.

OpenAI — APIThe 30 days is abuse-monitoring retention, deleted after unless legally required. Zero Data Retention exists but is approval-gated — you must apply and be accepted, it is not self-serve — and some abuse-monitoring metadata may still be kept.

Every row above was read from the provider's own page on 2026-07-06 and has not been swept since. These are terms, not prices: they change without announcement and the date beside each source is the honest limit of what this table knows. 8 tiers are listed — a ninth was observed and withheld, because its provider's own page did not state the default it turned on.

How to read it

Training dominates retention. A thirty-day window is a real protection; it is also irrelevant if the content has already been folded into a set of weights, because there is no retention clock on a model and no way to take it back out. Read the first column before the third.

Paying is not opting out. The single most useful line in this table is that a paid Google AI Pro or Ultra subscription does not change the training, human review or retention terms of the Gemini consumer app — the same source page governs the free tier and the paid one. Buying the product and buying out of the data arrangement are different purchases, and only one of them is on the pricing page.

An unstated retention is worse than a long one. Several providers give no day count at all. That reads as reassuring and is the opposite: a stated 1,095 days is a number you can plan around, while “a limited period” is a number you cannot. This table grades silence as exposure rather than safety, deliberately.

Zero-retention is usually a door, not a default. Where it is offered it often has to be applied for and granted, may not cover every endpoint, and may leave abuse-monitoring metadata behind. “Available” in the fourth column means obtainable, not switched on.

The local column is the whole comparison. Running the model yourself moves the cost from privacy to hardware, electricity and your own time — which is a real bill, and the reason the rest of this shelf exists to size it.