Perkins SmartOps
Technical 27 Sep 2026 8 min read

Where does my AI data go?

ChatGPT, Claude, Gemini or Copilot: the account you use matters more than the badge. Here's what to check before sharing business information.

Quick answer

Start with the account and the job, then check the provider. Business versions of ChatGPT, Claude, Gemini and Copilot offer protections that personal accounts don't automatically provide, including a promise not to train on what you type. But not being used for training doesn't mean your information stays in Britain. Storage and processing are separate promises, and on the plans a small firm buys, none of the four does its processing in the UK today. That is mainly a UK data protection question, and it has legal answers. The chance of a US court asking for your data is real but small. If information genuinely must not leave the UK, the only sure route is a model running on a machine or UK server you control.

The full story

You wouldn’t hand over a confidential folder because someone was wearing a familiar company badge. Yet choosing an AI tool because it says Microsoft can amount to the same decision. ChatGPT, Claude, Gemini and Copilot all need information to do useful work. The question is what happens after you hand it over, and whether the answer changes with your subscription.

Does my account change the answer?

Yes. Start with the exact account you’re signed into. Paying for a personal subscription doesn’t automatically give you your employer’s protections.

ChatGPT: OpenAI can use personal conversations for training unless you opt out. Training means using material to improve future models. Its business products, including ChatGPT Business and Enterprise, don’t use inputs and replies for training by default. Feedback can carry separate permissions, even after a personal opt-out, as OpenAI’s training rules set out.

Claude: Free, Pro and Max are consumer plans. Anthropic says it uses conversations for model improvement when you allow it, with separate provisions for safety review and feedback. For Team and Enterprise, training is off by default, but submitting feedback can permit training on the related conversation.

Gemini: Personal Gemini has activity controls, and some material is reviewed by people. Google’s own consumer privacy notice warns against entering confidential information. Turning activity off limits future model improvement, but doesn’t remove safety processing. With a qualifying Google Workspace account, content isn’t human-reviewed or used to train models outside your organisation without permission.

Copilot: Work and personal accounts have different terms. Microsoft’s current consumer privacy pages don’t set out a clear training default for UK users, so check the setting in the app rather than assuming. Don’t assume the work account’s promise applies either. For work, Microsoft says prompts, replies and accessed business data aren’t used to train its underlying models. More on those work protections below.

Our recommendation is an organisation-controlled business account with agreed data-processing terms. Those terms define the provider’s responsibilities for handling personal information. A paid badge or a privacy toggle isn’t a substitute. Turn off optional training wherever that control is available, and check feedback permissions too. Business defaults don’t remove the need to check your actual settings.

Where does my information actually go?

Separate where it’s kept from where it’s used. A folder can live in one office while someone elsewhere reads it and prepares your answer. Providers call these storage and processing locations.

ChatGPT Business now offers storage-region choices through a gradual rollout. Availability isn’t universal. Crucially, OpenAI says a copy of every prompt and reply still goes into US safety logs for a limited time. Choosing a storage region doesn’t control where answers are generated.

Enterprise has separate arrangements. Eligible customers can choose UK storage, but the current list of regions for generating answers includes Europe, the US and the United Arab Emirates. It doesn’t include the UK, as OpenAI’s location guidance makes clear.

Claude’s commercial location guidance says data is stored in the US. Processing can be routed through selected countries across the US, Europe, Asia and Australia. Some Enterprise customers have routing controls, but these aren’t a UK promise. Don’t assume Team includes a European location switch.

Google Workspace Business Standard and Plus offer a storage-region policy; Business Starter doesn’t. The options are the US or Europe, meaning the European Union, rather than a UK-only choice. Processing controls depend on the edition, and only the Enterprise Plus tier adds processing-region controls that the Business editions lack.

Microsoft’s European data boundary doesn’t include the UK. It covers the European Union and Iceland, Liechtenstein, Norway and Switzerland. Microsoft does store a UK organisation’s Copilot interactions in the UK. That still isn’t a promise that every processing step stays here.

Put together, the answer is short. On the plans a small firm is likely to buy, none of the four does its processing in the UK today. If a piece of work genuinely must not leave the country, the only sure route is a model running on a machine or UK server you control. That is less exotic than it sounds, and we’ve set out what it costs to run your own AI separately.

“Not used for training” doesn't mean “never leaves Britain”.

Is Copilot safer than the others?

It can be easier to control if your business already uses Microsoft 365 properly. That gives it a practical advantage, but doesn’t settle every safety question.

The current work-product names are Microsoft Copilot and Microsoft Copilot Chat. They were Microsoft 365 Copilot and Microsoft 365 Copilot Chat. Microsoft says the rename doesn’t change organisational privacy protections; older names still appear on some licences.

Both work services have Microsoft’s business data-processing terms and no-training commitment. Existing permissions and administrative controls apply, although the controls available depend on your subscription. Those are useful advantages over an unmanaged personal account.

Copilot Chat is included with eligible Microsoft 365 subscriptions. It mainly uses the web and content you provide, with supported app experiences and agents adding access to business information. Outlook can use a limited set of work content too. Paid Microsoft Copilot provides broader access across your organisation’s information. “Chat can’t see work files” is therefore too simple.

There’s a significant location exception. Copilot can now use Anthropic’s Claude models in Word, Excel and PowerPoint, and when it does, Microsoft says processing happens outside its European data boundary. In UK Microsoft accounts created after 25 March 2026, that setting is on by default; older accounts should check what their administrator has chosen. Anthropic works under Microsoft’s data-processing terms as a supplier handling information on Microsoft’s behalf, so the contract remains and the location promise changes. Some separately enabled Anthropic models run under Anthropic’s own terms, so check which ones are switched on.

Isn’t my data already in SharePoint?

Yes, but storing a file and asking AI to use it are different jobs. SharePoint keeps the file. Copilot reads it, and that takes a great deal of computing power in a data centre that isn’t promised to be in the UK. Microsoft stores a UK organisation’s Copilot history here, but says customers outside the European Union may have their queries processed in the US, the EU or other regions. It now expects to offer UK processing by the end of 2026. Until then, the file staying in the UK doesn’t mean the reading happens here.

Microsoft also says Copilot respects existing access permissions. The consequence is straightforward: permissions that are too broad remain too broad when AI makes the information easier to find. A folder shared with everyone doesn’t become suitable for everyone because Copilot can summarise it.

Web search is another route. Copilot generates short search queries from prompts and sends them to Bing under separate data-handling terms. User and organisation identifiers are removed, but the European boundary doesn’t cover those searches. Review web-search and agent settings alongside file permissions.

For recordings and transcripts, see Where do my AI meeting notes actually go?. The decision here is which account and features may handle the resulting information.

Should I worry about US processing?

Take it seriously, without treating a US server as proof that something has gone wrong. It’s mostly a UK question: whether sending the information abroad is lawful, and whether the remaining risk is acceptable.

The UK-US data bridge provides a legal route for transfers to participating US organisations. UK law doesn’t impose a general UK-only processing rule. But the bridge isn’t permission to send anything to any American company. The Information Commissioner’s Office says to check active registration, participation in the UK extension and coverage of the information being transferred.

Microsoft and Google state that they participate in the UK extension. Don’t assume all four providers use the same route. OpenAI and Anthropic both point to contractual safeguards in their data-processing terms for UK transfers.

The US CLOUD Act concerns lawful access to information controlled by providers under US jurisdiction, including information stored abroad. The US Department of Justice explains that existing legal requirements still apply. It doesn’t create unrestricted access to every business file. Equally, choosing a European server doesn’t by itself remove US legal exposure.

How likely is it? Rare. Microsoft’s own figures for the second half of 2024 show 173 law-enforcement requests about business customers across the whole world, with content handed over in 26. It’s a real risk, but a small one for a firm doing ordinary work.

Our practical priority would be to fix the risks you can inspect now: the wrong account, excessive sharing and unnecessary sensitive detail. For legally privileged, health or similarly sensitive information, check confidentiality duties, contract restrictions and the particular use before approving it. Get specialist advice where needed. This is a steer, not legal advice.

What should my business do first?

Approve one business account for one defined job. That means some administration up front, but gives your team a clear rule they can follow.

What may go where?
1
Name the job
Describe the task and the information it needs. Start with invented examples, then remove any detail the real task doesn't require.
2
Check the route
Record the account, processing terms, storage, processing countries and retention. Include web search, connected apps and alternative models.
3
Set the boundary
Write what staff may upload, what they must remove, and what needs approval. If UK-only handling is required, run the model yourself.

Running your own model brings responsibility for security and maintenance. Buying a different subscription doesn’t remove the need to decide what may leave your business.

What should I remember?
  • Check the account, terms and enabled features before choosing by provider.
  • Treat training, storage and processing as separate questions.
  • On the plans a small firm buys, none of the four processes your work in the UK today.
  • Use Copilot’s existing controls, but check permissions and the Claude setting.
  • The US court risk is real and small. The wrong account and loose sharing are likelier problems.
How this was written

Drafted by Otto, the Perkins SmartOps AI assistant. Reviewed, edited and published by David Perkins, the human.

Start with a diagnosis,
not a quote.

01Free, and it stays free. No follow-up sequence.
02Thirty minutes, in the diary, by video or phone.
03You leave with a view either way, build or no build.

You speak to David. No account manager, no handovers.

Free · 30 minutes Book the strategy session No pitch. Straight into David’s calendar. Book now