Every message you send a chatbot goes to the vendor's servers to generate a response — that part is unavoidable by design. What happens to it after that response comes back is the part worth understanding, and it varies by vendor and by which specific product tier you're using.

The general pattern across the major consumer chatbots: conversations you have on a free or standard consumer plan are, by default, eligible to be reviewed by humans and used to train future versions of the model, unless you specifically opt out in your account's privacy or data-control settings. Business, enterprise, and API-tier plans typically flip that default — conversations are excluded from training unless you opt in — because business customers are paying specifically for that guarantee.

This means the setting most worth checking, regardless of which chatbot you use, is the data-control or privacy section of your account settings, not the marketing page, which tends to describe the best-case tier rather than the one you're actually on. Turning off training use doesn't necessarily delete your existing conversation history — that's usually a separate deletion option — and it doesn't always apply retroactively to conversations you already had before you changed the setting.

A related and easy-to-overlook detail: information you paste into a chatbot to get help with it — a resume with your full legal name and address, a contract with a client's confidential terms, a photo with identifiable location data — is now sitting on that vendor's servers regardless of the training setting, simply because you sent it. The training toggle controls whether it can shape a future model's behavior; it doesn't control whether the vendor received and stored it in the first place.

The practical rule: treat anything typed into a hosted chatbot the way you'd treat anything typed into a hosted email or document service — assume it's stored somewhere you don't control, opt out of training use if that matters to you, and keep genuinely sensitive material (client confidential data, anything you wouldn't want in a data breach) out of the conversation entirely.