Resource · Security questionnaires
Which AI vendors say they will not train on your data
Every commitment not to train that we can quote from a page an AI vendor publishes, and every opt-out, with the source and the day we read it.
There is no list here of vendors that do train
Not because it would be unflattering. Because we cannot read one honestly. A sentence saying a vendor will not train is explicit and quotable. A sentence saying it will is almost never written that way; what exists instead is a broad license to “improve the Services,” and reading training into that is inference, not reporting.
So the absence of a vendor from the lists below means one thing only: nothing on the pages we read states a position we could quote. 119 vendors are in that position. Ask them directly rather than assuming either answer.
What the record holds
29 vendors state a commitment not to train on customer data. 8 publish an opt-out. 119 of the 186 vendors whose pages Xither reads state neither in words we could quote.
6 of the 29commitments carry a carve-out in the same sentence — “unless,” “except,” “subject to.” Quoting the first half of one of those to a customer is quoting half a sentence.
Vendors that say they will not train on your data
Ada
Ada does not use identifiable end-user data from Meta Platform Services to train public AI models.
https://ada.cx/privacy · read Aug 31, 2026
Adobe
Customer content is not used to train Adobe AI models or partner generative AI models, and that partner-model access is governed through Adobe enterprise controls (no separate login to the partner is required).
https://www.adobe.com/privacy/sub-processors.html · read Sep 12, 2026
AI21 Labs
Consistent with our Terms of Service, and unless otherwise agreed in writing or required to provide the Services, we do not use your inputs or outputs to train AI21’s foundational or generally available AI models.
https://ai21.com/privacy-policy · read Sep 7, 2026
AlphaSense
We do not use customer personal data, customer-provided content, or personal data processed on behalf of customers to train generally available generative artificial intelligence models or large language models, except where expressly agreed with the customer.
https://alpha-sense.com/privacy-policy · read Sep 13, 2026
Alteryx
We do not use your personal information to train artificial intelligence models, meaning we do not collect, use, or sell your personal information for the purpose of training Artificial Intelligence Large Language Models (referred to as an LLM).
https://alteryx.com/privacy · read Sep 11, 2026
Anysphere
ANYSPHERE WILL NOT USE CONTENT TO TRAIN, OR ALLOW ANY THIRD PARTY TO TRAIN, ANY AI MODELS, UNLESS YOU’VE EXPLICITLY AGREED TO THE USE OF CONTENT FOR TRAINING.
https://cursor.com/terms-of-service · read Sep 9, 2026
BigPanda
We strictly control access and adhere to OWASP security standards for AI, including committing to never using customer data to train our models.
https://www.bigpanda.io/our-product/bigpanda-security/ · read Sep 2, 2026
Camunda
No Model Training on Applicant Data: Your personal data is not used to train or improve the AI model.
https://camunda.com/privacy · read Aug 31, 2026
Chroma
Unless expressly permitted by Customer, Chroma will not use Customer Data to train the artificial intelligence or machine learning models.
https://trychroma.com/terms · read Aug 31, 2026
Cohere
The data remains within the enterprise customer’s or the third-party cloud provider’s controlled environment and is never accessible to or used by Cohere (for example, we do not train our models on it).
https://cohere.com/privacy · read Sep 13, 2026
Eightfold AI
The Eightfold platform does not use identifiable customer data to train its models.
https://eightfold.ai/security · read Sep 13, 2026
Elastic
Data collected from these marketing campaigns is not used by our third-party vendors to train their own generalized AI models.
https://elastic.co/privacy · read Sep 13, 2026
Fireflies.ai
(ii) will not use your User Content to train, retrain, fine-tune or otherwise improve any generative artificial intelligence models.
https://fireflies.ai/terms-of-service · read Aug 31, 2026
GitLab
However, we will not use your AI-inputs to train any language models without your instruction or prior consent.
https://about.gitlab.com/privacy · read Sep 11, 2026
Glean
Training Data Restrictions**: While using Glean's OpenAI/Azure OpenAI key, customer data will not be used to inform or train Azure OpenAI/OpenAI's generative AI model.
https://www.glean.com/website-terms · read Sep 2, 2026
H2O.ai
Customer-provided input data, metadata, and model data are not used to train H2O.ai AI models, unless explicitly agreed in writing.
https://h2o.ai/privacy · read Aug 31, 2026
Hebbia
We do not use Personal Data contained in Customer Data to train or improve generalized or third-party artificial intelligence or machine learning models.
https://hebbia.com/privacy · read Sep 13, 2026
Insider
Insider One shall not use any Customer Data—including prompts, inputs, AI Outputs, or other Personal Data—for the purpose of training, fine‑tuning, or otherwise developing or improving any artificial‑intellige…
https://useinsider.com/legal/dpa · read Sep 13, 2026
Landing AI
Data Usage: Customers with the ZDR Option:** Your data is never used for training or improving our models.
https://landing.ai/security-at-landingai · read Sep 9, 2026
LangChain
LangChain agrees that it will not use Customer Data to train on, develop, or otherwise improve its products, including any large language models. 4.3 Operational Metadata.
https://langchain.com/terms-of-service · read Sep 11, 2026
Lindy
Lindy and our providers do not use your data to train AI models.
https://lindy.ai/security · read Sep 2, 2026
LiveKit
We have opted out, on your behalf, of any use of Voice Samples (including any biometric data contained in them) by those inference providers for training, fine-tuning, or other improvement of their models; we likewise do not use Voice Samples to train our own models.
https://livekit.io/legal/privacy-policy · read Sep 13, 2026
Lovable
Data made available to us by a messaging or collaboration platform you connect is used only to operate the integration and generate responses; we do not use it to train AI models.
https://lovable.dev/privacy · read Sep 13, 2026
Modal
Modal will not, except with Customer's prior written consent: (i) train any AI model using Customer Data, or (ii) export Customer Data into, or cause Customer Data to be ingested by, large language models.
https://modal.com/legal/terms · read Sep 13, 2026
Notion
No customer data for AI training User data is never used to train or influence Notion AI models.
https://trust.notion.com/subprocessors · read Sep 10, 2026
Otter.ai
No Customer Data will be used to train or improve Anthropic’s artificial intelligence models.
https://otter.ai/subprocessors · read Sep 2, 2026
Rev
Customer Content will not be used for any generative AI model training.
https://rev.com/legal/terms · read Sep 13, 2026
Spellbook
Customer Data transmitted to Third Party LLMs via the Spellbook AI Platform will not be used to train, improve, or develop the AI models of those Third Party LLMs.
https://spellbook.legal/terms-of-service · read Sep 13, 2026
xAI
Google Apps Using Google OAuth**: For users who opt to connect to Google Apps via Google OAuth, SpaceXAI shall not use any Google Apps content for any of its internal AI or other training purposes (such as training its machine learning models), including developing new products or services based on su…
https://x.ai/privacy-policy · read Sep 11, 2026
Vendors that offer a switch
A switch is not a promise. These vendors say training happens unless you turn it off, which makes the default the thing that matters — and makes it matter whether anyone at your company knows the setting exists.
Anthropic
We may use Materials to provide, maintain, and improve the Services and to develop other products and services, including training our models, unless you opt out of training through your account settings.
https://anthropic.com/terms · read Sep 10, 2026
AssemblyAI
For information on how to opt-out of AssemblyAI’s use of Customer Data for purposes of training its artificial intelligence and machine learning models (to the extent applicable to Customer’s pricing plan), please visit: [https://www.assemblyai.com/docs/faq/how-to-opt-out-of-data-sharing-for-our-model-improvement-program](https://www.assemblyai.com/docs/faq/how-to-opt-out-of-data-sharing-for-our-…
https://assemblyai.com/terms · read Sep 11, 2026
Codeium
After you opt out, your data will not be used for training and Zero Data Retention will be enabled with our model providers.
https://windsurf.com/security · read Sep 2, 2026
Cohere
Opt out of model training at any time — your data stays yours.
https://cohere.com/security · read Sep 13, 2026
HubSpot
If you opt out, we will no longer collect Customer Data to train our AI models, unless you later update your settings and opt in.
https://hubspot.com/terms-of-service · read Sep 12, 2026
Lovable
You may tell us at any time that you do not want your Customer Data used for model training or the other business purposes described above, and we will honor that request for prospective use, free of charge and regardless of your plan.
https://lovable.dev/terms · read Sep 13, 2026
OpenAI
If you do not want us to use your Content to train our models, you can opt out by following the instructions in this article.
https://openai.com/terms · read Sep 12, 2026
Zapier
Does Zapier use customer data to train AI models? Enterprise customers are automatically opted out of data training, and customers on other plans can opt out of data training by filling out this form.
https://zapier.com/security-compliance · read Sep 13, 2026
What to ask for
Three things separate a commitment you can hand to a customer from one you cannot. Which data it covers — several of these name customer content and say nothing about prompts, outputs or metadata. Whether it binds the vendor’s own models, its third-party model providers, or both, because the two are drafted separately and a vendor can promise one and not the other. And whether it sits in the agreement or on a trust page: a page can be edited without anyone telling you, and a clause cannot.
Take it with you
Both lists as a Word document, with every quote, source and read date. It is generated when you download it, so it carries the record as it stands that day.
How these were read
Each statement is quoted from a page the vendor publishes, with the URL and the date we read it. Where a stored clip ran several statements together, the statement carrying the commitment is shown on its own rather than the paragraph around it. No words are changed and nothing is joined.
The extractor stores a polarity for each of these sentences, and this page ignores it. One of the plainest refusals in the record is filed in the extractor’s affirmative bucket, so the stored label is unreliable in both directions and every sentence is read on its own.
Common questions
- Which AI vendors do not train on customer data?
- The vendors publishing a commitment we could quote are listed on this page with their exact wording. A vendor absent from the list has not been found to train on customer data — it means nothing on the pages we read states a position we could quote.
- Does my AI vendor train on my data?
- Check whether it has published a commitment not to, and read what that commitment covers. Vendors that do train rarely say so in those words; what appears instead is a broad license to “improve the Services”, which is not the same sentence and should not be read as one.
- What is the difference between an opt-out and a commitment not to train?
- A commitment says training does not happen. An opt-out says it happens unless you turn it off, which makes the default the thing that matters and puts the work on you. Both are listed here, apart.
- Do these commitments cover prompts and outputs as well as content?
- Read each sentence. Several name customer content and say nothing about prompts, outputs or metadata, and the ones that cover all of them say so explicitly. The wording quoted here is the vendor's own.
- Does a no-training commitment cover third-party model providers?
- Not automatically. A vendor's own models and the model providers it routes to are drafted separately, and a vendor can commit for one and not the other. Several of the quotes below name which they mean.
Security questionnaires
Answer what a customer's security team asks about your AI stack.
- Answering “list every AI sub-processor”
What the question is asking for, where each vendor publishes the answer, and what to say about the gaps.
- Which certifications AI vendors say they hold
SOC 2, ISO 27001, ISO 42001 and more, counted off trust pages and kept apart by level — says, not holds.
- How long AI vendors keep your data
Every retention window we can quote, grouped by vendor — because a vendor states several, and they cover different data.
- Answering the AI questions in a security questionnaire
Eight questions, the answer that closes and the boundary on each — starting with the fact that “list every AI sub-processor” means about ninety companies.
- AI supply-chain question set
29 questions to put to an AI vendor — drafted by a language model, reviewed by a second, and published with all 15 edits shown.
- Where AI vendors say they keep your data
Residency commitments and transfer disclosures, quoted from vendor pages and kept apart — they look alike and mean opposite things.
This is not legal advice. The pages quoted are published documents read on the dates shown; your negotiated contract governs over anything here. The record behind this page is free to read, and corrections are free to request.