AI VALUE CREATION Register interest
Thought leadership

Your AI Sends Your Confidential Files to Anthropic. What Will You Tell Your Investors? - GXB

When Claude reads your files, the full text goes to Anthropic's computers. Here is what Anthropic's contract promises, what its strongest privacy setting does not cover, and what it costs to run AI on your own equipment.

A client connected Claude to their company's shared drive. Soon after, their leadership asked us three questions. When Claude reads our files, do they leave our network? Anthropic says it will not train on our data, but is that real? And what would it cost to run AI on our own equipment, so that nothing leaves?

They also had to answer their investors, who wanted to know where the company's data goes. We answered with a presentation. This post is that presentation, with the client's details removed. The short version: yes, your files leave. The promise is a real contract, but it is still only a promise. And private AI is now cheap enough for a mid-size company to try.

All prices, scores, and privacy terms in this post were fetched on 2026-10-02. AI prices and models change every month.

The short answers

When Claude reads our files, do they leave our network and go to Anthropic's servers? Can Anthropic keep them?
YES, it leaves.

When you use a file connector in Claude, your question and the search results go to Anthropic's servers. Claude reads them there. The results are file names, folder paths, and matching text. When Claude opens a document, it gets the full text.

How long Anthropic may keep it depends on your plan. See "Anthropic's privacy levels" below.

Anthropic has a checkbox that says it will not use our data to train its models. Is that real?
YES, it is a contract.

These terms cover Claude Team, Claude Enterprise, and the API. It is a binding promise. But it is a promise, not a physical limit: your data still goes to their computers.

What would it take, in time and money, to move to private AI?
About 1 week to start. $3,500 to $175,000 to own it.

"Private AI" means the AI model runs on a computer that you control, so nothing leaves. A trial can start in about 1 week with no equipment. Equipment costs about $3,500 for a one-person test box and up to about $175,000 for a server for a whole office. Details are below.

The privacy scale, from least private to most private

Every option to the left of the dashed line sends your data to Anthropic. The two options on the right do not. The rest of this page goes from left to right.

Privacy terms fetched on 2026-10-02.

← Your data goes to Anthropic Never goes to Anthropic → Least private Most private 1. Claude Free, Pro, Maxtraining on, kept up to 5 years Most businesses today 3. Claude Team or Enterpriseno training, kept until you delete 5. Anthropic APIdeleted within 30 days 7. Fireworks AIopen model, keeps no data 2. Claude Free, Pro, Maxtraining off 4. Enterprise, auto-deleteyour admin sets the period 6. API + Zero Data Retentionnot stored, with exceptions 8. Your own boxnothing leaves your office

How a question travels: two ways Claude can reach your files

Claude can reach a shared drive in two ways. Claude has direct connectors for file hosts such as Egnyte, Box, Google Drive, and SharePoint. Or you can use a connector like GXB's, which reads your files ahead of time. Both send data to Anthropic. The GXB route takes fewer steps, because GXB reads the drive once ahead of time. Anthropic keeps everything that passes through it in your chat history, until you delete the chat.

your question Claude's request file names and folders matching text a full document the answer
Route 1: your file host's own connector in Claude Claude must search, open, and read the original files (PDF, PowerPoint, Excel) each time you ask. Your office Anthropic File host Your laptop Claude Kept on Anthropic's servers (your chat history) Original files 1. Your question goes to Anthropic2. Claude asks Egnyte to search3. Egnyte sends file names and folder paths4. Claude asks for file 15. Egnyte sends the whole PDF6. Claude asks for file 27. Egnyte sends the whole slide deck8. Claude asks for file 39. Egnyte sends the whole spreadsheet10. Claude reads all three files11. The answer comes back to youEverything in the dashed box stays until you delete the chat. questionfile listPDFslidesspreadsheetanswer
Route 2: the GXB Connector GXB already read the shared drive and turned memos, reports, and spreadsheets into searchable text and tables. One search returns the answer. Your office Anthropic GXB Your laptop Claude Kept on Anthropic's servers (your chat history) GXB server text already pulled out copied from your files and read once, ahead of time 1. Your question goes to Anthropic2. Claude asks the GXB Connector to search3. GXB sends only the matching text, already pulled out4. The answer comes back to youDone, with less data sent. Route 1 is still opening files. questionmatching textanswer

Both animations run on the same clock. In both routes, the connector request comes from Anthropic's servers, not from your laptop. GXB also holds a text copy of the shared drive, so true privacy must include GXB too. We come back to this at the end.

What Anthropic's servers receive: one example

One question, step by step. Each box is plain text that goes to Anthropic. The company, the document, the names, and the numbers are made up. Scroll inside the dark boxes to see all of it.

1 · You type
Find the Q2 board update and list the risks it talks about.
Anthropic sees: your question.
2 · Claude asks the connector to search
search_documents({
  "query": "Q2 2026 board update"
})
Anthropic sees: the search words. Claude wrote them.
3 · The connector answers
3 results
1. /Shared/Leadership/Board/2026/Q2 2026 Board Update - CONFIDENTIAL.pdf
   modified 2026-07-14 09:12  ·  18 pages
2. /Shared/Leadership/Board/2026/Q1 2026 Board Update - CONFIDENTIAL.pdf
   modified 2026-04-15 16:40  ·  16 pages
3. /Shared/Leadership/Board/2026/Drafts/Q2 Board Update v3 (do not share).docx
   modified 2026-07-11 22:05  ·  19 pages
Anthropic sees: your folder structure and file names.
4 · Claude asks to open the first file
read_document({
  "path": "/Shared/Leadership/Board/2026/Q2 2026 Board Update - CONFIDENTIAL.pdf"
})
Anthropic sees: which file Claude chose.
5 · The connector sends the full text
PIPEFIELD SYSTEMS, INC.
Q2 2026 BOARD UPDATE                                   CONFIDENTIAL. DO NOT FORWARD.
Prepared for the Board of Directors, July 14, 2026

1. SUMMARY
   Revenue        $14.2M   (plan $15.0M, -5%)
   Gross margin   61%      (plan 64%)
   Cash           $9.8M    (about 11 months at current spend)
   Headcount      142      (plan 150)

2. TOP CUSTOMERS
   Customer              Annual value   Renewal     Status
   Harlow Medical Group  $2,400,000     2026-11-30  At risk. Asked for 20% discount.
   Cobalt Freight        $1,150,000     2027-03-31  Healthy
   Redwater County       $  880,000     2026-09-30  Public bid. Competitor is lower.
   Lumen Dental Partners $  610,000     2027-01-15  Healthy

3. RISKS
   a. Harlow Medical: if Harlow leaves, revenue falls about 17%.
   b. Lawsuit: a former sales director claims unpaid commission
      ($1.3M). Outside counsel: settle for $250k to $400k.
   c. Data incident: on May 3 a contractor laptop with customer
      files was stolen. Counsel is reviewing notice duties.
   d. Price increase: we plan +9% on all renewals after Oct 1.
      Customers do not know yet.

4. PEOPLE
   Planned reduction of 12 roles in support and sales on Aug 15.
   Not yet announced to staff. Severance cost: about $410k.
   CFO search: two finalists. Offer range $310k to $340k base.

5. CORPORATE DEVELOPMENT
   Project Juniper: early talks to acquire a smaller competitor
   for $18M to $22M. Letter of intent target: September.

6. ASKS OF THE BOARD
   - Approve the reduction plan and severance budget.
   - Approve up to $400k for the lawsuit settlement.
   - Approve a $250k budget for Project Juniper diligence.
Anthropic sees: every word and number in the document, including customers, salaries, a lawsuit, and layoffs that staff do not know about.
6 · Claude answers you

The Q2 board update lists these risks:

Customer: Harlow Medical ($2.4M a year, about 17% of revenue) may leave. It asked for a 20% discount.
Legal: a commission lawsuit for $1.3M. Counsel suggests a settlement of $250k to $400k.
Data: a stolen contractor laptop with customer files (May 3).
Pricing: a 9% increase on renewals after October 1, not yet told to customers.

Anthropic sees: the answer, because Anthropic wrote it.

Tool names are simplified. The company, people, dates, and numbers are made up for this example.

From least private to most private

Plans, settings, and keep periods fetched on 2026-10-02.

Plan and settingTrains AI on it?How long they say they keep itNotes
1Claude Free, Pro, or Max
"Help improve Claude" on
YESUp to 5 yearsPersonal terms. Each user picks this setting.
2Claude Free, Pro, or Max
that setting off
NOUntil you delete, then 30 daysPersonal terms. No data processing agreement.
3Claude Team or Enterprise
Most businesses are here
NO unless someone sends thumbs up/down feedbackUntil you delete, then 30 days. Feedback: 5 years.Business contract. Flagged chats: 2 years.
4Claude Enterprise
with custom retention
NOYour admin sets an automatic delete periodAdds audit logs. Same contract.
5Anthropic API
(an app like GXB's calls Claude)
NODeleted within 30 daysAnthropic keeps no chat history. The app does.
6Anthropic API with Zero Data Retention (ZDR)NONot stored after the answerNeeds Anthropic's approval. API only, so not Claude chat. Exceptions are listed below.

At every level, your data still travels to Anthropic and is processed on their computers. The levels change what Anthropic may keep and use afterward. Sources are at the end.

What you can tell clients and investors today:

"We use Claude under Anthropic's business contract. Anthropic is not permitted to train its models on our data, and it removes deleted data from its systems within 30 days. We also work with GXB to limit what Anthropic sees: our file connector usually sends Anthropic only the specific facts that a question needs, which is much less text than whole documents."

Even with Anthropic's strongest option, three problems stay

Zero Data Retention (ZDR) means Anthropic does not store your prompts after it sends the answer. It is the best Anthropic offers. It also costs more: it needs Anthropic's approval, and you pay for each question at API prices instead of a flat price per person. One estimate: a heavy user on a $200 a month Claude plan uses about $5,000 a month of AI at API prices.

1

You lose the Claude app

ZDR covers only the API and Claude Code. It does not cover claude.ai, the desktop app, or the phone app, where most people use connectors today. You would need a different chat app that calls the API, such as one that GXB builds.

2

Fable is not covered

For Claude Fable and other models of that class, Anthropic keeps your prompts for 30 days for safety review, even under ZDR. To get true ZDR, you must use a less capable Claude model.

3

It is still a promise

Your data still goes to Anthropic's computers. You trust them to delete it as they say. Exceptions: they keep safety scores, chats their systems flag, and anything a court orders. In 2025 a court ordered OpenAI to keep all ChatGPT chats, including deleted ones, during a lawsuit.

Why a physical limit is better: AI companies trained on the public web and on books without asking. In 2025, Anthropic agreed to pay $1.5 billion to settle a lawsuit from book authors. That is a reason to prefer a physical limit to a promise. It is not evidence that Anthropic breaks its business contracts.

It is not one company

OpenAI, Google, Anthropic, Meta, and SpaceXAI (the maker of Grok) have each been in the news for taking, keeping, or exposing data that was not theirs to use. Two of these stories are about customer data, like your files. SpaceXAI's coding tool uploaded users' whole code folders to the company's cloud, and Elon Musk promised to delete them. OpenAI's test agents posted images that users had uploaded on public websites. The Google story is a lawsuit that a court has not decided yet.

Five news headlines. 1, The Register: Musk promises purge after Grok Build caught sending entire repos to the cloud. 2, TechCrunch: Unsecured OpenAI agents posted 53 user images on the internet without the lab's knowledge. 3, TechCrunch: Google faces another AI training lawsuit from major publishers. 4, The Register: Anthropic to pay at least $1.5 billion to authors whose work it knowingly pirated. 5, Tom's Hardware: Meta staff torrented nearly 82TB of pirated books for AI training, court records reveal copyright violations.
Headlines as published: [1] The Register, July 14, 2026. [2] TechCrunch, September 25, 2026. [3] TechCrunch, July 14, 2026. [4] The Register, September 8, 2025. [5] Tom's Hardware, February 9, 2025. Notes are in the sources at the end.

Private AI: the model runs on a computer in your office

Your office network Your laptops Mac Studio AI model + chat app Shared drive copy Hundreds of GB fit on the box Internet, Anthropic, GXB, everyone else can unplug 1. Your question goes to the Mac Studio in your office2. The model searches your shared drive copy3. It reads the full documents, inside the office4. The answer comes back to youNothing left the office.

Nothing leaves

The model, your files, and the chat history stay on a box you own. You need no promise from anyone, because there is no copy anywhere else.

Works with no internet

You can unplug it from the internet ("air gap") and it still answers. It only needs your office network.

Rent vs. buy

Claude is like renting: no upfront cost, and you pay for each use. Private AI is like buying the building: a large upfront cost, then almost nothing for each use (about $20 to $150 a month in power).

What you can tell clients and investors, with your own equipment:

"Questions about our internal files are answered by AI that runs on hardware we own, inside our office. That data never leaves our network."

How smart is a model you can own, and what does it cost?

Scores from the Artificial Analysis Intelligence Index, an independent test of AI models (checked October 2, 2026). Higher is smarter. To make the scale easy to read, we count brains. Claude Fable 5.1 has 5 brains, so each brain is about 10.6 points.

Scores and prices fetched on 2026-10-02.

0102030405060 ANTHROPIC CLAUDE (rented) Haiku 4.517 · 1.5 brains Sonnet 4.630 · 3 brains Opus 4.842 · 4 brains Fable 5.153 · 5 brains Opus 5.558 · 5.5 brains OPEN MODELS YOU CAN OWN Qwen 3.8 27B · 34 Framework Desktop $3,449 or DGX Spark $4,699 list ($6,000+ today) Qwen 3.8 Flash-Next · 40 256GB Mac Studio $11,299 (faster) GLM 5.3 Flash · 42 256GB Mac Studio $11,299, or tinybox $91,000 GLM 5.3 · 45 512GB Mac Studio, about $17k to $20k

Mac Studio prices are Apple's store prices on October 2 (M5 Ultra, 80-core GPU, 2TB). Apple has not set a price for the 512GB model yet. DGX Spark: NVIDIA lists the 128GB model at $4,699, but market prices passed $6,000 this week. A 64GB version from Dell, ASUS, HP, and others starts at $4,999 on October 23.

Open models are catching up

The best closed model (Anthropic, OpenAI, Google, xAI) and the best open model you can download and own, by month. Same index.

Scores and release dates fetched on 2026-10-02.

0102030405060Jul 2024Jan 2025Jul 2025Jan 2026Jul 2026Claude 3 OpusOpenAI o1Claude 4 OpusClaude Opus 4.5Claude Opus 4.8Claude Opus 5.5DeepSeek R1Kimi K2 ThinkingGLM-5GLM 5.3Best closed model (rented only)Best open model (you can own it)Shaded area = the gap

Scores and release dates fetched on 2026-10-02.

02468Months the best open model is behind the best closed modelJul 20244Jan 2025567567Jul 2025856344Jan 2026345631Jul 202623

Source: Artificial Analysis Intelligence Index, model scores and release dates, checked October 2, 2026. Each line shows the best score released so far. "Months behind" counts back to the month when a closed model first reached the open model's score (GXB calculation). Open means the model's weights can be downloaded and run on your own equipment.

Plain English

The best model you can own today has about 4 brains: about as smart as Claude Opus 4.8. Claude was at that level in May 2026. It is much smarter than Claude Haiku. For searching and summarizing your own files, the gap is small. For hard analysis, you will notice it.

The delay is getting shorter

In 2025, the best open model was usually 5 to 8 months behind the best closed model. Since June 2026, it has been 1 to 3 months behind. A box you buy now gets smarter each time we load a newer free model onto it. You do not need new equipment for that.

Equipment options, from a desk box to a server

The highlighted columns are the ones that matter for a decision. The gray column is the technical reason behind them.

Prices, delivery dates, and model scores fetched on 2026-10-02.

OptionPrice todayWhen it arrivesSmartsPeople at onceMessages per dayMemory / speed
Claude (rented)
for comparison
Per seat, per monthNow 🧠🧠🧠🧠🧠🧠Fable 5.1 (5), Opus 5.5 (5.5) No practical limit No practical limit Anthropic's data centers
Framework Desktop
AMD Ryzen AI Max+ 395
$3,449Check Framework's site 🧠🧠🧠Qwen 3.8 27B 1 About 200 128 GB · 256 GB/s
NVIDIA DGX Spark
Sold by Dell, ASUS, HP, and others
$4,699 list
$6,000+ in the market now
Check reseller stock. A 64GB model ($4,999) ships October 23. 🧠🧠🧠Qwen 3.8 27B 1 to 2 About 400 128 GB · 273 GB/s
Mac Studio, 256GB
M5 Ultra, 80-core GPU, 2TB
$11,299Late January 2027
Apple quotes 16 to 18 weeks
🧠🧠🧠🧠GLM 5.3 Flash About 4 About 1,000 256 GB · 1,200 GB/s
Mac Studio, 512GB
M5 Ultra, 80-core GPU
About $17k to $20k
Apple has not set a price
Orders open late October.
Expect February to March 2027.
🧠🧠🧠🧠GLM 5.3 1 to 2
or about 8 with GLM 5.3 Flash
About 400
or about 1,500 with GLM 5.3 Flash
512 GB · 1,200 GB/s
tinybox green v2
tiny corp (George Hotz). 4 NVIDIA RTX PRO 6000 Blackwell
$91,000Made to order, 2 to 8 weeks 🧠🧠🧠🧠GLM 5.3 Flash, high quality 20 to 50 20,000+ 384 GB · 7,168 GB/s
Dell Pro Max with GB300
NVIDIA Grace Blackwell desktop
$175,497
list price
Ask Dell 🧠🧠🧠🧠GLM 5.3 10 to 30 10,000+ 252 GB GPU + 496 GB · 7,100 GB/s
For scale: a team of 15 people who each send 20 messages a day uses about 300 messages a day. One 256GB Mac Studio covers that.

Prices and dates checked October 2, 2026. Memory prices are high and rising, so quotes may change. "People at once" means questions answered at the same moment. "Messages per day" is an estimate for a 10-hour work day, where one message reads about 15 pages and writes about 1 page. Mac Studio numbers are scaled from GXB's own Mac Studios (previous chip, measured September 27). Equipment only: GXB setup and support are quoted separately.

Our recommendation: try open models first, with no equipment

The trial runs GLM 5.3 Flash, an open model, on Fireworks AI, through GXB's chat app. Fireworks keeps no prompts or answers by default for open models, and Anthropic never sees the question. Other companies run the same open models, such as Together AI, Groq, and Baseten. A newer option is Darkbloom, from Eigen Labs. It runs open models on other people's idle Macs, and encrypts each question so the Mac's owner cannot read it. Darkbloom is in public alpha and offers smaller models, so we would not use it for confidential files yet.

Your laptop or phone chat.gxb.vc GXB's chat app, with your shared drive text already in it Kept by GXB (chat history) Fireworks AI runs an open model (GLM 5.3 Flash) Kept by Fireworks 1. Your question goes to GXB's chat app2. GXB searches your shared drive text3. The question and matching text go to Fireworks4. Fireworks writes the answer and sends it back5. Fireworks deletes everything. It keeps no copy.6. The answer comes to you. GXB keeps a copy, as Anthropic does today.GXB keeps the copy so we can find and fix bad answers. questionmatching textquestion + textanswernothing kept

Why start here

$0

No upfront cost

No equipment to buy. The model costs about 1 to 2 cents per question. We set up the trial in about 1 week.

Trial$0 up front
Buy a box$3.5k to $175k
Prices fetched on 2026-10-02.

The same model you would run on your own box

Fireworks (trial) GLM 5.3 Flash = GLM 5.3 Flash Your box (later)

Same model, same chat app. The trial tells you how a box would perform before you buy one. To move, we copy the setup onto the box.

No lock-in

Open models run at many companies. We can change the company or the model at any time, and nothing else changes for you.

The one dependency is GXB's chat app. You can ask for your data and chat history at any time.

Built for your company

It is our software, so we can add what you ask for. Examples:

Which board update first mentioned the Harlow discount?
Text it from your phone.
  • When an answer fails, it goes to GXB as a ticket, and we fix it.
  • Mix models. Example: Jev, a low-cost model that answers yes/no questions over thousands of documents.

The trade-offs

  • Not the smartest model. GLM 5.3 Flash has about 4 brains. Claude's best has 5 to 5.5. Searching and summarizing will feel similar. Hard analysis will feel weaker.
  • Some rough edges. Anthropic has spent years on the Claude app. chat.gxb.vc is newer, so some things will not work as smoothly at first. We fix them as you find them.
  • GXB sees what Anthropic sees today. During the trial, GXB's chat server stores your questions and answers. That is how we find and fix bad answers. If GXB already runs your file connector, GXB already holds a text copy of your files, so this does not add a new company.

The path to "nobody can see it"

To go fully private, we move the model, the chat app, and the shared drive copy onto a box in your office. GXB then has access only when you turn it on for a support visit. Outside your company, nobody can see your data, and that includes GXB.

Before you buy a box, check two things

  1. Your current Claude use. Sign in at claude.ai as an Owner. Click your initials (lower left), then Analytics. Under "How much is Claude costing?", click Export spend report, choose Last 90 Days, and download.
  2. What your clients and investors require. If they sent a policy or a questionnaire, it tells you if a promise is enough, or if the data must stay on your own equipment.

What you can tell clients and investors, after the trial, if you keep it:

"Questions about our internal files go to an open AI model on a provider that keeps no data. They do not go to Anthropic or OpenAI."

Where these facts come from

Want to know where your data goes?

We can map where your company's data goes today, and set up a private AI trial in about a week. Book a call.

All thought leadership Register interest