Your AI Sends Your Confidential Files to Anthropic. What Will You Tell Your Investors? - GXB
When Claude reads your files, the full text goes to Anthropic's computers. Here is what Anthropic's contract promises, what its strongest privacy setting does not cover, and what it costs to run AI on your own equipment.
A client connected Claude to their company's shared drive. Soon after, their leadership asked us three questions. When Claude reads our files, do they leave our network? Anthropic says it will not train on our data, but is that real? And what would it cost to run AI on our own equipment, so that nothing leaves?
They also had to answer their investors, who wanted to know where the company's data goes. We answered with a presentation. This post is that presentation, with the client's details removed. The short version: yes, your files leave. The promise is a real contract, but it is still only a promise. And private AI is now cheap enough for a mid-size company to try.
All prices, scores, and privacy terms in this post were fetched on 2026-10-02. AI prices and models change every month.
The short answers
When you use a file connector in Claude, your question and the search results go to Anthropic's servers. Claude reads them there. The results are file names, folder paths, and matching text. When Claude opens a document, it gets the full text.
How long Anthropic may keep it depends on your plan. See "Anthropic's privacy levels" below.
These terms cover Claude Team, Claude Enterprise, and the API. It is a binding promise. But it is a promise, not a physical limit: your data still goes to their computers.
"Private AI" means the AI model runs on a computer that you control, so nothing leaves. A trial can start in about 1 week with no equipment. Equipment costs about $3,500 for a one-person test box and up to about $175,000 for a server for a whole office. Details are below.
The privacy scale, from least private to most private
Every option to the left of the dashed line sends your data to Anthropic. The two options on the right do not. The rest of this page goes from left to right.
Privacy terms fetched on 2026-10-02.
How a question travels: two ways Claude can reach your files
Claude can reach a shared drive in two ways. Claude has direct connectors for file hosts such as Egnyte, Box, Google Drive, and SharePoint. Or you can use a connector like GXB's, which reads your files ahead of time. Both send data to Anthropic. The GXB route takes fewer steps, because GXB reads the drive once ahead of time. Anthropic keeps everything that passes through it in your chat history, until you delete the chat.
Both animations run on the same clock. In both routes, the connector request comes from Anthropic's servers, not from your laptop. GXB also holds a text copy of the shared drive, so true privacy must include GXB too. We come back to this at the end.
What Anthropic's servers receive: one example
One question, step by step. Each box is plain text that goes to Anthropic. The company, the document, the names, and the numbers are made up. Scroll inside the dark boxes to see all of it.
search_documents({
"query": "Q2 2026 board update"
})3 results 1. /Shared/Leadership/Board/2026/Q2 2026 Board Update - CONFIDENTIAL.pdf modified 2026-07-14 09:12 · 18 pages 2. /Shared/Leadership/Board/2026/Q1 2026 Board Update - CONFIDENTIAL.pdf modified 2026-04-15 16:40 · 16 pages 3. /Shared/Leadership/Board/2026/Drafts/Q2 Board Update v3 (do not share).docx modified 2026-07-11 22:05 · 19 pages
read_document({
"path": "/Shared/Leadership/Board/2026/Q2 2026 Board Update - CONFIDENTIAL.pdf"
})PIPEFIELD SYSTEMS, INC.
Q2 2026 BOARD UPDATE CONFIDENTIAL. DO NOT FORWARD.
Prepared for the Board of Directors, July 14, 2026
1. SUMMARY
Revenue $14.2M (plan $15.0M, -5%)
Gross margin 61% (plan 64%)
Cash $9.8M (about 11 months at current spend)
Headcount 142 (plan 150)
2. TOP CUSTOMERS
Customer Annual value Renewal Status
Harlow Medical Group $2,400,000 2026-11-30 At risk. Asked for 20% discount.
Cobalt Freight $1,150,000 2027-03-31 Healthy
Redwater County $ 880,000 2026-09-30 Public bid. Competitor is lower.
Lumen Dental Partners $ 610,000 2027-01-15 Healthy
3. RISKS
a. Harlow Medical: if Harlow leaves, revenue falls about 17%.
b. Lawsuit: a former sales director claims unpaid commission
($1.3M). Outside counsel: settle for $250k to $400k.
c. Data incident: on May 3 a contractor laptop with customer
files was stolen. Counsel is reviewing notice duties.
d. Price increase: we plan +9% on all renewals after Oct 1.
Customers do not know yet.
4. PEOPLE
Planned reduction of 12 roles in support and sales on Aug 15.
Not yet announced to staff. Severance cost: about $410k.
CFO search: two finalists. Offer range $310k to $340k base.
5. CORPORATE DEVELOPMENT
Project Juniper: early talks to acquire a smaller competitor
for $18M to $22M. Letter of intent target: September.
6. ASKS OF THE BOARD
- Approve the reduction plan and severance budget.
- Approve up to $400k for the lawsuit settlement.
- Approve a $250k budget for Project Juniper diligence.The Q2 board update lists these risks:
Customer: Harlow Medical ($2.4M a year, about 17% of revenue) may leave. It asked for a 20% discount.
Legal: a commission lawsuit for $1.3M. Counsel suggests a settlement of $250k to $400k.
Data: a stolen contractor laptop with customer files (May 3).
Pricing: a 9% increase on renewals after October 1, not yet told to customers.
Tool names are simplified. The company, people, dates, and numbers are made up for this example.
From least private to most private
Plans, settings, and keep periods fetched on 2026-10-02.
"Help improve Claude" onYESUp to 5 yearsPersonal terms. Each user picks this setting.
that setting offNOUntil you delete, then 30 daysPersonal terms. No data processing agreement.
Most businesses are hereNO unless someone sends thumbs up/down feedbackUntil you delete, then 30 days. Feedback: 5 years.Business contract. Flagged chats: 2 years.
with custom retentionNOYour admin sets an automatic delete periodAdds audit logs. Same contract.
(an app like GXB's calls Claude)NODeleted within 30 daysAnthropic keeps no chat history. The app does.
At every level, your data still travels to Anthropic and is processed on their computers. The levels change what Anthropic may keep and use afterward. Sources are at the end.
What you can tell clients and investors today:
Even with Anthropic's strongest option, three problems stay
Zero Data Retention (ZDR) means Anthropic does not store your prompts after it sends the answer. It is the best Anthropic offers. It also costs more: it needs Anthropic's approval, and you pay for each question at API prices instead of a flat price per person. One estimate: a heavy user on a $200 a month Claude plan uses about $5,000 a month of AI at API prices.
You lose the Claude app
ZDR covers only the API and Claude Code. It does not cover claude.ai, the desktop app, or the phone app, where most people use connectors today. You would need a different chat app that calls the API, such as one that GXB builds.
Fable is not covered
For Claude Fable and other models of that class, Anthropic keeps your prompts for 30 days for safety review, even under ZDR. To get true ZDR, you must use a less capable Claude model.
It is still a promise
Your data still goes to Anthropic's computers. You trust them to delete it as they say. Exceptions: they keep safety scores, chats their systems flag, and anything a court orders. In 2025 a court ordered OpenAI to keep all ChatGPT chats, including deleted ones, during a lawsuit.
It is not one company
OpenAI, Google, Anthropic, Meta, and SpaceXAI (the maker of Grok) have each been in the news for taking, keeping, or exposing data that was not theirs to use. Two of these stories are about customer data, like your files. SpaceXAI's coding tool uploaded users' whole code folders to the company's cloud, and Elon Musk promised to delete them. OpenAI's test agents posted images that users had uploaded on public websites. The Google story is a lawsuit that a court has not decided yet.
Private AI: the model runs on a computer in your office
Nothing leaves
The model, your files, and the chat history stay on a box you own. You need no promise from anyone, because there is no copy anywhere else.
Works with no internet
You can unplug it from the internet ("air gap") and it still answers. It only needs your office network.
Rent vs. buy
Claude is like renting: no upfront cost, and you pay for each use. Private AI is like buying the building: a large upfront cost, then almost nothing for each use (about $20 to $150 a month in power).
What you can tell clients and investors, with your own equipment:
How smart is a model you can own, and what does it cost?
Scores from the Artificial Analysis Intelligence Index, an independent test of AI models (checked October 2, 2026). Higher is smarter. To make the scale easy to read, we count brains. Claude Fable 5.1 has 5 brains, so each brain is about 10.6 points.
Scores and prices fetched on 2026-10-02.
Mac Studio prices are Apple's store prices on October 2 (M5 Ultra, 80-core GPU, 2TB). Apple has not set a price for the 512GB model yet. DGX Spark: NVIDIA lists the 128GB model at $4,699, but market prices passed $6,000 this week. A 64GB version from Dell, ASUS, HP, and others starts at $4,999 on October 23.
Open models are catching up
The best closed model (Anthropic, OpenAI, Google, xAI) and the best open model you can download and own, by month. Same index.
Scores and release dates fetched on 2026-10-02.
Scores and release dates fetched on 2026-10-02.
Source: Artificial Analysis Intelligence Index, model scores and release dates, checked October 2, 2026. Each line shows the best score released so far. "Months behind" counts back to the month when a closed model first reached the open model's score (GXB calculation). Open means the model's weights can be downloaded and run on your own equipment.
Plain English
The best model you can own today has about 4 brains: about as smart as Claude Opus 4.8. Claude was at that level in May 2026. It is much smarter than Claude Haiku. For searching and summarizing your own files, the gap is small. For hard analysis, you will notice it.
The delay is getting shorter
In 2025, the best open model was usually 5 to 8 months behind the best closed model. Since June 2026, it has been 1 to 3 months behind. A box you buy now gets smarter each time we load a newer free model onto it. You do not need new equipment for that.
Equipment options, from a desk box to a server
The highlighted columns are the ones that matter for a decision. The gray column is the technical reason behind them.
Prices, delivery dates, and model scores fetched on 2026-10-02.
| Option | Price today | When it arrives | Smarts | People at once | Messages per day | Memory / speed |
|---|---|---|---|---|---|---|
| Claude (rented) for comparison |
Per seat, per month | Now | 🧠🧠🧠🧠🧠🧠Fable 5.1 (5), Opus 5.5 (5.5) | No practical limit | No practical limit | Anthropic's data centers |
| Framework Desktop AMD Ryzen AI Max+ 395 |
$3,449 | Check Framework's site | 🧠🧠🧠Qwen 3.8 27B | 1 | About 200 | 128 GB · 256 GB/s |
| NVIDIA DGX Spark Sold by Dell, ASUS, HP, and others |
$4,699 list $6,000+ in the market now | Check reseller stock. A 64GB model ($4,999) ships October 23. | 🧠🧠🧠Qwen 3.8 27B | 1 to 2 | About 400 | 128 GB · 273 GB/s |
| Mac Studio, 256GB M5 Ultra, 80-core GPU, 2TB |
$11,299 | Late January 2027 Apple quotes 16 to 18 weeks |
🧠🧠🧠🧠GLM 5.3 Flash | About 4 | About 1,000 | 256 GB · 1,200 GB/s |
| Mac Studio, 512GB M5 Ultra, 80-core GPU |
About $17k to $20k Apple has not set a price | Orders open late October. Expect February to March 2027. |
🧠🧠🧠🧠GLM 5.3 | 1 to 2 or about 8 with GLM 5.3 Flash |
About 400 or about 1,500 with GLM 5.3 Flash |
512 GB · 1,200 GB/s |
| tinybox green v2 tiny corp (George Hotz). 4 NVIDIA RTX PRO 6000 Blackwell |
$91,000 | Made to order, 2 to 8 weeks | 🧠🧠🧠🧠GLM 5.3 Flash, high quality | 20 to 50 | 20,000+ | 384 GB · 7,168 GB/s |
| Dell Pro Max with GB300 NVIDIA Grace Blackwell desktop |
$175,497 list price | Ask Dell | 🧠🧠🧠🧠GLM 5.3 | 10 to 30 | 10,000+ | 252 GB GPU + 496 GB · 7,100 GB/s |
Prices and dates checked October 2, 2026. Memory prices are high and rising, so quotes may change. "People at once" means questions answered at the same moment. "Messages per day" is an estimate for a 10-hour work day, where one message reads about 15 pages and writes about 1 page. Mac Studio numbers are scaled from GXB's own Mac Studios (previous chip, measured September 27). Equipment only: GXB setup and support are quoted separately.
Our recommendation: try open models first, with no equipment
The trial runs GLM 5.3 Flash, an open model, on Fireworks AI, through GXB's chat app. Fireworks keeps no prompts or answers by default for open models, and Anthropic never sees the question. Other companies run the same open models, such as Together AI, Groq, and Baseten. A newer option is Darkbloom, from Eigen Labs. It runs open models on other people's idle Macs, and encrypts each question so the Mac's owner cannot read it. Darkbloom is in public alpha and offers smaller models, so we would not use it for confidential files yet.
Why start here
No upfront cost
No equipment to buy. The model costs about 1 to 2 cents per question. We set up the trial in about 1 week.
The same model you would run on your own box
Same model, same chat app. The trial tells you how a box would perform before you buy one. To move, we copy the setup onto the box.
No lock-in
Open models run at many companies. We can change the company or the model at any time, and nothing else changes for you.
The one dependency is GXB's chat app. You can ask for your data and chat history at any time.
Built for your company
It is our software, so we can add what you ask for. Examples:
- When an answer fails, it goes to GXB as a ticket, and we fix it.
- Mix models. Example: Jev, a low-cost model that answers yes/no questions over thousands of documents.
The trade-offs
- Not the smartest model. GLM 5.3 Flash has about 4 brains. Claude's best has 5 to 5.5. Searching and summarizing will feel similar. Hard analysis will feel weaker.
- Some rough edges. Anthropic has spent years on the Claude app. chat.gxb.vc is newer, so some things will not work as smoothly at first. We fix them as you find them.
- GXB sees what Anthropic sees today. During the trial, GXB's chat server stores your questions and answers. That is how we find and fix bad answers. If GXB already runs your file connector, GXB already holds a text copy of your files, so this does not add a new company.
The path to "nobody can see it"
To go fully private, we move the model, the chat app, and the shared drive copy onto a box in your office. GXB then has access only when you turn it on for a support visit. Outside your company, nobody can see your data, and that includes GXB.
Before you buy a box, check two things
- Your current Claude use. Sign in at claude.ai as an Owner. Click your initials (lower left), then Analytics. Under "How much is Claude costing?", click Export spend report, choose Last 90 Days, and download.
- What your clients and investors require. If they sent a policy or a questionnaire, it tells you if a promise is enough, or if the data must stay on your own equipment.
What you can tell clients and investors, after the trial, if you keep it:
Where these facts come from
- Anthropic Commercial Terms of Service, Sections B and E.1 ("Anthropic may not train models on Customer Content from Services"): anthropic.com/legal/commercial-terms
- Anthropic, consumer data retention (5 years with training on, 30 days off): privacy.claude.com/en/articles/10023548
- Anthropic, business and API retention, flagged chats (2 years), feedback (5 years): privacy.claude.com/en/articles/7996866
- Anthropic, which products ZDR applies to (API and Claude Code only): privacy.claude.com/en/articles/8956058
- Anthropic, 30-day retention for Fable-class models, even under ZDR: privacy.claude.com/en/articles/15425996
- Claude plan vs. API price ($200 plan, about $5,000 of API-priced use for a heavy user): Forbes, March 5, 2026, explained by Martin Alderson: martinalderson.com
- Fireworks AI, zero data retention by default for open models: docs.fireworks.ai
- Apple Mac Studio M5 Ultra price: apple.com. Specs and the 512GB "late October" date: Macworld. Pricing detail: AppleInsider
- NVIDIA DGX Spark prices: VideoCardz, NVIDIA
- tiny corp tinybox green v2 Blackwell, $91,000, 2 to 8 weeks: tinycorp.myshopify.com, specs: tinygrad.org
- Dell Pro Max with GB300: dell.com
- Framework Desktop prices: Phoronix
- Model scores and release dates: Artificial Analysis Intelligence Index, checked October 2, 2026. Open models in the chart: models with downloadable weights from DeepSeek, Alibaba (Qwen, not Qwen Max), Z AI (GLM), Moonshot (Kimi), MiniMax, Xiaomi, Meta (Llama), and Mistral. GLM 5.3 Flash size: z.ai
- Speed and capacity estimates: GXB's own Mac Studio measurements (M3 Ultra, September 27, 2026), scaled by the M5 Ultra's memory speed.
- Darkbloom, private inference on idle Macs (public alpha), security model and prices: docs.darkbloom.dev, checked 2026-10-02.
- Headline image [1], SpaceXAI's Grok Build uploads: The Register, July 14, 2026, checked 2026-10-04. SpaceXAI says customers with Zero Data Retention were never kept; data from other users was kept by default during the early test period.
- Headline image [2], OpenAI agents posted user images: TechCrunch, September 25, 2026, checked 2026-10-04. Based on OpenAI's own statement.
- Headline image [3], publishers sue Google over Gemini training: TechCrunch, July 14, 2026, checked 2026-10-04. A lawsuit, not yet decided.
- Headline image [4], Anthropic's $1.5 billion settlement with authors: The Register, September 8, 2025, checked 2026-10-04.
- Headline image [5], Meta and pirated books: Tom's Hardware, February 9, 2025, checked 2026-10-04. A judge later ruled that Meta's training was fair use; the claim about torrenting continued.
Want to know where your data goes?
We can map where your company's data goes today, and set up a private AI trial in about a week. Book a call.