# Your AI Sends Your Confidential Files to Anthropic. What Will You Tell Your Investors?

By Christian Genco, GXB. October 2, 2026.

A client connected Claude to their company's shared drive. Soon after, their leadership asked us three questions. When Claude reads our files, do they leave our network? Anthropic says it will not train on our data, but is that real? And what would it cost to run AI on our own equipment, so that nothing leaves?

They also had to answer their investors, who wanted to know where the company's data goes. We answered with a presentation. This post is that presentation, with the client's details removed. The short version: yes, your files leave. The promise is a real contract, but it is still only a promise. And private AI is now cheap enough for a mid-size company to try.

All prices, scores, and privacy terms in this post were fetched on 2026-10-02. AI prices and models change every month.

## The short answers

**1. When Claude reads our files, do they leave our network and go to Anthropic's servers? Can Anthropic keep them?**

**Yes, they leave.** When you use a file connector in Claude, your question and the search results go to Anthropic's servers. Claude reads them there. The results are file names, folder paths, and matching text. When Claude opens a document, it gets the full text. How long Anthropic may keep it depends on your plan (see the privacy levels below).

**2. Anthropic has a checkbox that says it will not use our data to train its models. Is that real?**

**Yes, it is a contract.** From the [Anthropic Commercial Terms of Service](https://www.anthropic.com/legal/commercial-terms):

> Section B: "Anthropic may not train models on Customer Content from Services."
>
> Section B, definition: "'Inputs' means submissions to the Services by Customer or its Users and 'Outputs' means responses generated by the Services to Inputs (Inputs and Outputs together are 'Customer Content')."
>
> Section E.1: "Customer Content is Customer's Confidential Information."

These terms cover Claude Team, Claude Enterprise, and the API. It is a binding promise. But it is a promise, not a physical limit: your data still goes to their computers.

**3. What would it take, in time and money, to move to private AI?**

**About 1 week to start. $3,500 to $175,000 to own it.** "Private AI" means the AI model runs on a computer that you control, so nothing leaves. A trial can start in about 1 week with no equipment. Equipment costs about $3,500 for a one-person test box and up to about $175,000 for a server for a whole office.

## The privacy scale, from least private to most private

Privacy terms fetched on 2026-10-02. Levels 1 to 6 send your data to Anthropic. Levels 7 and 8 do not.

| Level | Option | What happens to your data |
|---|---|---|
| 1 | Claude Free, Pro, Max | Training on, kept up to 5 years |
| 2 | Claude Free, Pro, Max | Training off |
| 3 | Claude Team or Enterprise (most businesses are here) | No training, kept until you delete |
| 4 | Claude Enterprise, auto-delete | Your admin sets the period |
| 5 | Anthropic API | Deleted within 30 days |
| 6 | Anthropic API + Zero Data Retention | Not stored, with exceptions |
| 7 | [Fireworks AI](https://fireworks.ai/) running an open model | Keeps no data. Never goes to Anthropic. |
| 8 | Your own box | Nothing leaves your office |

## How a question travels: two ways Claude can reach your files

Claude can reach a shared drive in two ways. Claude has direct connectors for file hosts such as Egnyte, Box, Google Drive, and SharePoint. Or you can use a connector like GXB's, which reads your files ahead of time.

- **Route 1, the file host's own connector.** Claude must search, open, and read the original files (PDF, PowerPoint, Excel) each time you ask. Each step goes through Anthropic's servers.
- **Route 2, the GXB connector.** GXB already read the shared drive and turned memos, reports, and spreadsheets into searchable text and tables. One search returns the answer.

Both routes send data to Anthropic. The GXB route takes fewer steps. In both routes, the connector request comes from Anthropic's servers, not from your laptop. Anthropic keeps everything that passes through it in your chat history, until you delete the chat. GXB also holds a text copy of the shared drive, so true privacy must include GXB too.

## What Anthropic's servers receive: one example

One question, step by step. Each step is plain text that goes to Anthropic. The company, the document, the names, and the numbers are made up.

**1. You type:** "Find the Q2 board update and list the risks it talks about."
Anthropic sees: your question.

**2. Claude asks the connector to search:**

```
search_documents({ "query": "Q2 2026 board update" })
```

Anthropic sees: the search words. Claude wrote them.

**3. The connector answers:**

```
3 results
1. /Shared/Leadership/Board/2026/Q2 2026 Board Update - CONFIDENTIAL.pdf
2. /Shared/Leadership/Board/2026/Q1 2026 Board Update - CONFIDENTIAL.pdf
3. /Shared/Leadership/Board/2026/Drafts/Q2 Board Update v3 (do not share).docx
```

Anthropic sees: your folder structure and file names.

**4. Claude asks to open the first file.** Anthropic sees: which file Claude chose.

**5. The connector sends the full text:**

```
PIPEFIELD SYSTEMS, INC.
Q2 2026 BOARD UPDATE                       CONFIDENTIAL. DO NOT FORWARD.

1. SUMMARY
   Revenue        $14.2M   (plan $15.0M, -5%)
   Cash           $9.8M    (about 11 months at current spend)

2. TOP CUSTOMERS
   Harlow Medical Group  $2,400,000  At risk. Asked for 20% discount.

3. RISKS
   b. Lawsuit: a former sales director claims unpaid commission ($1.3M).
   c. Data incident: a contractor laptop with customer files was stolen.
   d. Price increase: +9% on all renewals after Oct 1. Customers do not know yet.

4. PEOPLE
   Planned reduction of 12 roles on Aug 15. Not yet announced to staff.
   CFO search: offer range $310k to $340k base.

5. CORPORATE DEVELOPMENT
   Project Juniper: early talks to acquire a competitor for $18M to $22M.
```

Anthropic sees: every word and number in the document, including customers, salaries, a lawsuit, and layoffs that staff do not know about.

**6. Claude answers you** with the list of risks. Anthropic sees the answer, because Anthropic wrote it.

## From least private to most private

Plans, settings, and keep periods fetched on 2026-10-02.

| # | Plan and setting | Trains AI on it? | How long they say they keep it | Notes |
|---|---|---|---|---|
| 1 | Claude Free, Pro, or Max, "Help improve Claude" on | Yes | Up to 5 years | Personal terms. Each user picks this setting. |
| 2 | Claude Free, Pro, or Max, that setting off | No | Until you delete, then 30 days | Personal terms. No data processing agreement. |
| 3 | Claude Team or Enterprise (most businesses are here) | No, unless someone sends thumbs up/down feedback | Until you delete, then 30 days. Feedback: 5 years. | Business contract. Flagged chats: 2 years. |
| 4 | Claude Enterprise with custom retention | No | Your admin sets an automatic delete period | Adds audit logs. Same contract. |
| 5 | Anthropic API (an app like GXB's calls Claude) | No | Deleted within 30 days | Anthropic keeps no chat history. The app does. |
| 6 | Anthropic API with Zero Data Retention (ZDR) | No | Not stored after the answer | Needs Anthropic's approval. API only, so not Claude chat. |

At every level, your data still travels to Anthropic and is processed on their computers. The levels change what Anthropic may keep and use afterward.

What you can tell clients and investors today:

> "We use Claude under Anthropic's business contract. Anthropic is not permitted to train its models on our data, and it removes deleted data from its systems within 30 days. We also work with GXB to limit what Anthropic sees: our file connector usually sends Anthropic only the specific facts that a question needs, which is much less text than whole documents."

## Even with Anthropic's strongest option, three problems stay

Zero Data Retention (ZDR) means Anthropic does not store your prompts after it sends the answer. It is the best Anthropic offers. It also costs more: it needs Anthropic's approval, and you pay for each question at API prices instead of a flat price per person. One estimate: a heavy user on a $200 a month Claude plan uses about $5,000 a month of AI at API prices.

1. **You lose the Claude app.** ZDR covers only the API and Claude Code. It does not cover claude.ai, the desktop app, or the phone app, where most people use connectors today. You would need a different chat app that calls the API, such as one that GXB builds.
2. **Fable is not covered.** For Claude Fable and other models of that class, Anthropic keeps your prompts for 30 days for safety review, even under ZDR. To get true ZDR, you must use a less capable Claude model.
3. **It is still a promise.** Your data still goes to Anthropic's computers. You trust them to delete it as they say. Exceptions: they keep safety scores, chats their systems flag, and anything a court orders. In 2025 a court ordered OpenAI to keep all ChatGPT chats, including deleted ones, during a lawsuit.

Why a physical limit is better: AI companies trained on the public web and on books without asking. In 2025, Anthropic agreed to pay $1.5 billion to settle a lawsuit from book authors. That is a reason to prefer a physical limit to a promise. It is not evidence that Anthropic breaks its business contracts.

### It is not one company

OpenAI, Google, Anthropic, Meta, and SpaceXAI (the maker of Grok) have each been in the news for taking, keeping, or exposing data that was not theirs to use. Two of these stories are about customer data, like your files. SpaceXAI's coding tool uploaded users' whole code folders to the company's cloud, and Elon Musk promised to delete them. OpenAI's test agents posted images that users had uploaded on public websites. The Google story is a lawsuit that a court has not decided yet.

[![Five news headlines about AI companies and data](https://cdn.gxbsites.com/blobs/bd01bbbfd466409c8d7c9d408b40c9092767d9aa830212c48c40260ef3070367/asset.jpg)](https://cdn.gxbsites.com/blobs/bd01bbbfd466409c8d7c9d408b40c9092767d9aa830212c48c40260ef3070367/asset.jpg)

Headlines as published:

1. The Register, July 14, 2026: [Musk promises purge after Grok Build caught sending entire repos to the cloud](https://www.theregister.com/ai-and-ml/2026/07/14/musk-promises-purge-after-grok-build-caught-sending-entire-repos-to-the-cloud/5271123)
2. TechCrunch, September 25, 2026: [Unsecured OpenAI agents posted 53 user images on the internet without the lab's knowledge](https://techcrunch.com/2026/09/25/unsecured-openai-agents-posted-53-user-images-on-the-internet-without-the-labs-knowledge/)
3. TechCrunch, July 14, 2026: [Google faces another AI training lawsuit from major publishers](https://techcrunch.com/2026/07/14/google-faces-another-ai-training-lawsuit-from-major-publishers/)
4. The Register, September 8, 2025: [Anthropic to pay at least $1.5 billion to authors whose work it knowingly pirated](https://www.theregister.com/offbeat/2025/09/08/anthropic-coughs-15-bn-to-authors-whose-work-it-stole/1442543)
5. Tom's Hardware, February 9, 2025: [Meta staff torrented nearly 82TB of pirated books for AI training, court records reveal copyright violations](https://www.tomshardware.com/tech-industry/artificial-intelligence/meta-staff-torrented-nearly-82tb-of-pirated-books-for-ai-training-court-records-reveal-copyright-violations)

Notes are in the sources at the end.

## Private AI: the model runs on a computer in your office

1. Your question goes to the computer in your office.
2. The model searches your copy of the shared drive.
3. It reads the full documents, inside the office.
4. The answer comes back to you. Nothing left the office.

- **Nothing leaves.** The model, your files, and the chat history stay on a box you own. You need no promise from anyone, because there is no copy anywhere else.
- **Works with no internet.** You can unplug it from the internet ("air gap") and it still answers. It only needs your office network.
- **Rent vs. buy.** Claude is like renting: no upfront cost, and you pay for each use. Private AI is like buying the building: a large upfront cost, then almost nothing for each use (about $20 to $150 a month in power).

What you can tell clients and investors, with your own equipment:

> "Questions about our internal files are answered by AI that runs on hardware we own, inside our office. That data never leaves our network."

## How smart is a model you can own, and what does it cost?

Scores from the [Artificial Analysis Intelligence Index](https://artificialanalysis.ai/), an independent test of AI models. Higher is smarter. To make the scale easy to read, we count brains: Claude Fable 5.1 has 5 brains, so each brain is about 10.6 points. Scores and prices fetched on 2026-10-02.

| Model | Type | Score | Brains | Equipment to run it |
|---|---|---|---|---|
| Claude Haiku 4.5 | Rented (Anthropic) | 17 | 1.5 | |
| Claude Sonnet 4.6 | Rented (Anthropic) | 30 | 3 | |
| Qwen 3.8 27B | Open | 34 | 3 | Framework Desktop $3,449, or DGX Spark $4,699 list ($6,000+ in the market) |
| Qwen 3.8 Flash-Next | Open | 40 | 4 | 256GB Mac Studio $11,299 (faster) |
| Claude Opus 4.8 | Rented (Anthropic) | 42 | 4 | |
| GLM 5.3 Flash | Open | 42 | 4 | 256GB Mac Studio $11,299, or tinybox $91,000 |
| GLM 5.3 | Open | 45 | 4 | 512GB Mac Studio, about $17k to $20k |
| Claude Fable 5.1 | Rented (Anthropic) | 53 | 5 | |
| Claude Opus 5.5 | Rented (Anthropic) | 58 | 5.5 | |

### Open models are catching up

We compared the best closed model (Anthropic, OpenAI, Google, xAI) with the best open model you can download and own, month by month, on the same index. Scores and release dates fetched on 2026-10-02.

- In 2025, the best open model was usually 5 to 8 months behind the best closed model.
- Since June 2026, it has been 1 to 3 months behind.
- The best model you can own today has about 4 brains: about as smart as Claude Opus 4.8. Claude was at that level in May 2026.

For searching and summarizing your own files, the gap is small. For hard analysis, you will notice it. A box you buy now gets smarter each time a newer free model is loaded onto it. You do not need new equipment for that.

## Equipment options, from a desk box to a server

Prices, delivery dates, and model scores fetched on 2026-10-02. Memory prices are high and rising, so quotes may change.

| Option | Price | When it arrives | Best model it runs | People at once | Messages per day | Memory / speed |
|---|---|---|---|---|---|---|
| Claude (rented), for comparison | Per seat, per month | Now | Fable 5.1 (5 brains), Opus 5.5 (5.5) | No practical limit | No practical limit | Anthropic's data centers |
| [Framework Desktop](https://frame.work/desktop) (AMD Ryzen AI Max+ 395) | $3,449 | Check Framework's site | Qwen 3.8 27B (3) | 1 | About 200 | 128 GB · 256 GB/s |
| [NVIDIA DGX Spark](https://www.nvidia.com/en-us/products/workstations/dgx-spark/) | $4,699 list, $6,000+ in the market | Check reseller stock. A 64GB model ($4,999) ships October 23. | Qwen 3.8 27B (3) | 1 to 2 | About 400 | 128 GB · 273 GB/s |
| [Mac Studio](https://www.apple.com/mac-studio/), 256GB (M5 Ultra, 80-core GPU, 2TB) | $11,299 | Late January 2027 (Apple quotes 16 to 18 weeks) | GLM 5.3 Flash (4) | About 4 | About 1,000 | 256 GB · 1,200 GB/s |
| Mac Studio, 512GB | About $17k to $20k (no price yet) | Orders open late October. Expect February to March 2027. | GLM 5.3 (4) | 1 to 2, or about 8 with GLM 5.3 Flash | About 400, or about 1,500 with GLM 5.3 Flash | 512 GB · 1,200 GB/s |
| [tinybox green v2](https://tinygrad.org/#tinybox) (tiny corp, 4 NVIDIA RTX PRO 6000 Blackwell) | $91,000 | Made to order, 2 to 8 weeks | GLM 5.3 Flash, high quality (4) | 20 to 50 | 20,000+ | 384 GB · 7,168 GB/s |
| [Dell Pro Max with GB300](https://www.dell.com/en-us/shop/desktop-computers/spd/dellpromaxwithgb300fct6263) | $175,497 list | Ask Dell | GLM 5.3 (4) | 10 to 30 | 10,000+ | 252 GB GPU + 496 GB · 7,100 GB/s |

For scale: a team of 15 people who each send 20 messages a day uses about 300 messages a day. One 256GB Mac Studio covers that.

"People at once" means questions answered at the same moment. "Messages per day" is an estimate for a 10-hour work day, where one message reads about 15 pages and writes about 1 page. Mac Studio numbers are scaled from GXB's own Mac Studios (previous chip, measured September 27, 2026). Equipment only: setup and support are separate.

## Our recommendation: try open models first, with no equipment

The trial runs GLM 5.3 Flash, an open model, on [Fireworks AI](https://fireworks.ai/), through GXB's chat app. [Fireworks keeps no prompts or answers by default](https://docs.fireworks.ai/guides/security_compliance/data_handling) for open models, and Anthropic never sees the question. Other companies run the same open models, such as [Together AI](https://www.together.ai/), [Groq](https://groq.com/), and [Baseten](https://www.baseten.co/). A newer option is [Darkbloom](https://darkbloom.dev/), from Eigen Labs. It runs open models on other people's idle Macs, and [encrypts each question so the Mac's owner cannot read it](https://docs.darkbloom.dev/security/overview). Darkbloom is in public alpha and offers smaller models, so we would not use it for confidential files yet.

How the trial works:

1. Your question goes to GXB's chat app.
2. GXB searches your shared drive text.
3. The question and matching text go to Fireworks.
4. Fireworks writes the answer and sends it back.
5. Fireworks deletes everything. It keeps no copy.
6. The answer comes to you. GXB keeps a copy, as Anthropic does today, so we can find and fix bad answers.

### Why start here

- **No upfront cost.** No equipment to buy. The model costs about 1 to 2 cents per question. The trial takes about 1 week to set up. A box costs $3,500 to $175,000 (prices fetched on 2026-10-02).
- **The same model you would run on your own box.** Same model, same chat app. The trial tells you how a box would perform before you buy one. To move, we copy the setup onto the box.
- **No lock-in.** Open models run at many companies. We can change the company or the model at any time, and nothing else changes for you. Options include [Fireworks AI](https://fireworks.ai/), [Together AI](https://www.together.ai/), [Groq](https://groq.com/), [Baseten](https://www.baseten.co/), [DeepInfra](https://deepinfra.com/), [OpenRouter](https://openrouter.ai/), [Cerebras](https://www.cerebras.ai/), [Nebius](https://nebius.com/), [Darkbloom](https://darkbloom.dev/), and your own box. The one dependency is GXB's chat app. You can ask for your data and chat history at any time.
- **Built for your company.** It is our software, so we can add what you ask for. You can text a question from your phone. When an answer fails, it goes to GXB as a ticket, and we fix it. You can mix models, such as a low-cost model that answers yes/no questions over thousands of documents.

### The trade-offs

- **Not the smartest model.** GLM 5.3 Flash has about 4 brains. Claude's best has 5 to 5.5. Searching and summarizing will feel similar. Hard analysis will feel weaker.
- **Some rough edges.** Anthropic has spent years on the Claude app. GXB's chat app is newer, so some things will not work as smoothly at first. We fix them as you find them.
- **GXB sees what Anthropic sees today.** During the trial, GXB's chat server stores your questions and answers. That is how we find and fix bad answers. If GXB already runs your file connector, GXB already holds a text copy of your files, so this does not add a new company.

### The path to "nobody can see it"

To go fully private, we move the model, the chat app, and the shared drive copy onto a box in your office. GXB then has access only when you turn it on for a support visit. Outside your company, nobody can see your data, and that includes GXB.

### Before you buy a box, check two things

1. **Your current Claude use.** Sign in at claude.ai as an Owner. Click your initials (lower left), then Analytics. Under "How much is Claude costing?", click Export spend report, choose Last 90 Days, and download.
2. **What your clients and investors require.** If they sent a policy or a questionnaire, it tells you if a promise is enough, or if the data must stay on your own equipment.

What you can tell clients and investors, after the trial, if you keep it:

> "Questions about our internal files go to an open AI model on a provider that keeps no data. They do not go to Anthropic or OpenAI."

## Where these facts come from

Checked on 2026-10-02 unless a date is given.

- Anthropic Commercial Terms of Service, Sections B and E.1: [anthropic.com/legal/commercial-terms](https://www.anthropic.com/legal/commercial-terms)
- Anthropic, consumer data retention (5 years with training on, 30 days off): [privacy.claude.com](https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data)
- Anthropic, business and API retention, flagged chats (2 years), feedback (5 years): [privacy.claude.com](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data)
- Anthropic, which products ZDR applies to (API and Claude Code only): [privacy.claude.com](https://privacy.claude.com/en/articles/8956058-i-have-a-zero-data-retention-agreement-with-anthropic-what-products-does-it-apply-to)
- Anthropic, 30-day retention for Fable-class models, even under ZDR: [privacy.claude.com](https://privacy.claude.com/en/articles/15425996-data-retention-practices-for-covered-models)
- Claude plan vs. API price ($200 plan, about $5,000 of API-priced use for a heavy user): Forbes, March 5, 2026, explained by [Martin Alderson](https://martinalderson.com/posts/no-it-doesnt-cost-anthropic-5k-per-claude-code-user/)
- Fireworks AI, zero data retention by default for open models: [docs.fireworks.ai](https://docs.fireworks.ai/guides/security_compliance/data_handling)
- Darkbloom security model and prices: [docs.darkbloom.dev](https://docs.darkbloom.dev/security/overview)
- Mac Studio M5 Ultra price: [apple.com](https://www.apple.com/shop/buy-mac/mac-studio/m5-ultra-chip-36-core-cpu-80-core-gpu-256gb-memory-4tb-storage). 512GB date: [Macworld](https://www.macworld.com/article/2973459/2026-mac-studio-m5-release-date-specs-price-rumors.html). Pricing detail: [AppleInsider](https://appleinsider.com/articles/26/08/25/you-can-spend-18299-on-a-mac-studio-today-or-more-in-october)
- NVIDIA DGX Spark prices: [VideoCardz](https://videocardz.com/newz/nvidia-dgx-spark-drops-to-64gb-memory-but-costs-more-than-the-original-128gb-version), [NVIDIA](https://blogs.nvidia.com/blog/local-ai-dgx-spark-64gb-sync/)
- tinybox green v2: [tinycorp.myshopify.com](https://tinycorp.myshopify.com/products/tinybox-green-v2-with-4x-rtx-pro-6000-blackwell), specs: [tinygrad.org](https://tinygrad.org/#tinybox)
- Dell Pro Max with GB300: [dell.com](https://www.dell.com/en-us/shop/desktop-computers/spd/dellpromaxwithgb300fct6263)
- Framework Desktop prices: [Phoronix](https://www.phoronix.com/news/Framework-Desktop-Gorgon-Halo)
- Model scores and release dates: [Artificial Analysis Intelligence Index](https://artificialanalysis.ai/). Open models: models with downloadable weights from DeepSeek, Alibaba (Qwen), Z AI (GLM), Moonshot (Kimi), MiniMax, Xiaomi, Meta (Llama), and Mistral. GLM 5.3 Flash size: [z.ai](https://z.ai/blog/glm-5.3-flash)
- Speed and capacity estimates: GXB's own Mac Studio measurements (M3 Ultra, September 27, 2026), scaled by the M5 Ultra's memory speed.
- Headline image [1], SpaceXAI's Grok Build uploads: [The Register, July 14, 2026](https://www.theregister.com/ai-and-ml/2026/07/14/musk-promises-purge-after-grok-build-caught-sending-entire-repos-to-the-cloud/5271123), checked 2026-10-04. SpaceXAI says customers with Zero Data Retention were never kept; data from other users was kept by default during the early test period.
- Headline image [2], OpenAI agents posted user images: [TechCrunch, September 25, 2026](https://techcrunch.com/2026/09/25/unsecured-openai-agents-posted-53-user-images-on-the-internet-without-the-labs-knowledge/), checked 2026-10-04. Based on OpenAI's own statement.
- Headline image [3], publishers sue Google over Gemini training: [TechCrunch, July 14, 2026](https://techcrunch.com/2026/07/14/google-faces-another-ai-training-lawsuit-from-major-publishers/), checked 2026-10-04. A lawsuit, not yet decided.
- Headline image [4], Anthropic's $1.5 billion settlement with authors: [The Register, September 8, 2025](https://www.theregister.com/offbeat/2025/09/08/anthropic-coughs-15-bn-to-authors-whose-work-it-stole/1442543), checked 2026-10-04.
- Headline image [5], Meta and pirated books: [Tom's Hardware, February 9, 2025](https://www.tomshardware.com/tech-industry/artificial-intelligence/meta-staff-torrented-nearly-82tb-of-pirated-books-for-ai-training-court-records-reveal-copyright-violations), checked 2026-10-04. A judge later ruled that Meta's training was fair use; the claim about torrenting continued.

## Want to know where your data goes?

We can map where your company's data goes today, and set up a private AI trial in about a week. [Book a call](https://gxb.vc/book).
