{"id":202,"date":"2026-08-20T11:37:02","date_gmt":"2026-08-20T11:37:02","guid":{"rendered":"https:\/\/clickbaton.com\/blog\/?p=202"},"modified":"2026-08-20T11:37:35","modified_gmt":"2026-08-20T11:37:35","slug":"the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data","status":"publish","type":"post","link":"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/","title":{"rendered":"The AI Data Privacy Index: How 12 Leading AI Tools Handle Your Data"},"content":{"rendered":"<div id=\"ez-toc-container\" class=\"ez-toc-v2_0_86 counter-hierarchy ez-toc-counter ez-toc-white ez-toc-container-direction\">\n<div class=\"ez-toc-title-container\">\n<p class=\"ez-toc-title\" style=\"cursor:inherit\">Table of Contents<\/p>\n<span class=\"ez-toc-title-toggle\"><a href=\"#\" class=\"ez-toc-pull-right ez-toc-btn ez-toc-btn-xs ez-toc-btn-default ez-toc-toggle\" aria-label=\"Toggle Table of Content\"><span class=\"ez-toc-js-icon-con\"><span class=\"\"><span class=\"eztoc-hide\" style=\"display:none;\">Toggle<\/span><span class=\"ez-toc-icon-toggle-span\"><svg style=\"fill: #999;color:#999\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" class=\"list-377408\" width=\"20px\" height=\"20px\" viewBox=\"0 0 24 24\" fill=\"none\"><path d=\"M6 6H4v2h2V6zm14 0H8v2h12V6zM4 11h2v2H4v-2zm16 0H8v2h12v-2zM4 16h2v2H4v-2zm16 0H8v2h12v-2z\" fill=\"currentColor\"><\/path><\/svg><svg style=\"fill: #999;color:#999\" class=\"arrow-unsorted-368013\" xmlns=\"http:\/\/www.w3.org\/2000\/svg\" width=\"10px\" height=\"10px\" viewBox=\"0 0 24 24\" version=\"1.2\" baseProfile=\"tiny\"><path d=\"M18.2 9.3l-6.2-6.3-6.2 6.3c-.2.2-.3.4-.3.7s.1.5.3.7c.2.2.4.3.7.3h11c.3 0 .5-.1.7-.3.2-.2.3-.5.3-.7s-.1-.5-.3-.7zM5.8 14.7l6.2 6.3 6.2-6.3c.2-.2.3-.5.3-.7s-.1-.5-.3-.7c-.2-.2-.4-.3-.7-.3h-11c-.3 0-.5.1-.7.3-.2.2-.3.5-.3.7s.1.5.3.7z\"\/><\/svg><\/span><\/span><\/span><\/a><\/span><\/div>\n<nav><ul class='ez-toc-list ez-toc-list-level-1 ' ><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-1\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Key_findings_at_a_glance\" >Key findings at a glance<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-2\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Methodology_and_why_we_built_it_this_way\" >Methodology, and why we built it this way<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-3\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#The_full_scoring_table\" >The full scoring table<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-4\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#The_complete_rankings_with_the_one_line_version_of_why\" >The complete rankings, with the one line version of why<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-5\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Twelve_tools_in_depth\" >Twelve tools, in depth<\/a><ul class='ez-toc-list-level-3' ><li class='ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-6\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#1_Thomson_Reuters_CoCounsel_score_90100\" >1. Thomson Reuters CoCounsel, score 90\/100<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-7\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#2_Harvey_score_88100\" >2. Harvey, score 88\/100<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-8\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#3_Amazon_Q_score_78100\" >3. Amazon Q, score 78\/100<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-9\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#4_Mistral_score_74100\" >4. Mistral, score 74\/100<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-10\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#5_Anthropic_Claude_score_70100\" >5. Anthropic Claude, score 70\/100<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-11\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#6_OpenAI_ChatGPT_score_68100\" >6. OpenAI ChatGPT, score 68\/100<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-12\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#7_Google_Gemini_score_66100\" >7. Google Gemini, score 66\/100<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-13\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#8_Microsoft_Copilot_score_64100\" >8. Microsoft Copilot, score 64\/100<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-14\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#9_Perplexity_score_58100\" >9. Perplexity, score 58\/100<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-15\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#10_xAI_Grok_score_25100\" >10. xAI Grok, score 25\/100<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-16\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#11_Meta_AI_score_22100\" >11. Meta AI, score 22\/100<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-3'><a class=\"ez-toc-link ez-toc-heading-17\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#12_DeepSeek_hosted_service_score_12100\" >12. DeepSeek, hosted service, score 12\/100<\/a><\/li><\/ul><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-18\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Quick_reference_one_paragraph_on_each_tool\" >Quick reference: one paragraph on each tool<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-19\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Superlatives_the_best_and_worst_in_each_category\" >Superlatives: the best and worst in each category<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-20\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#How_each_tools_free_or_entry_tier_compares\" >How each tool&#8217;s free or entry tier compares<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-21\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#What_the_index_reveals_five_patterns_across_all_twelve_tools\" >What the index reveals: five patterns across all twelve tools<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-22\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#The_compliance_frameworks_behind_every_score_in_this_index\" >The compliance frameworks behind every score in this index<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-23\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#The_cost_of_getting_this_wrong_a_roundup_of_enforcement_already_underway\" >The cost of getting this wrong: a roundup of enforcement already underway<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-24\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#What_it_costs_to_access_the_tier_that_actually_protects_you\" >What it costs to access the tier that actually protects you<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-25\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#What_this_means_if_you_run_a_law_firm\" >What this means if you run a law firm<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-26\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#What_this_means_if_you_run_a_finance_or_operations_team\" >What this means if you run a finance or operations team<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-27\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#How_this_indexs_findings_interact_with_the_shift_toward_AI_agents\" >How this index&#8217;s findings interact with the shift toward AI agents<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-28\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Why_a_local_deployment_sits_outside_this_entire_scoring_exercise\" >Why a local deployment sits outside this entire scoring exercise<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-29\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#A_practical_checklist_matching_your_use_case_to_the_right_tier\" >A practical checklist: matching your use case to the right tier<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-30\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Where_each_tool_sits_on_a_simple_decision_tree\" >Where each tool sits on a simple decision tree<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-31\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Applying_this_index_three_worked_examples\" >Applying this index: three worked examples<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-32\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Questions_to_ask_any_AI_vendor_not_covered_in_this_index\" >Questions to ask any AI vendor not covered in this index<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-33\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Common_mistakes_when_reading_an_AI_privacy_policy\" >Common mistakes when reading an AI privacy policy<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-34\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Sample_language_for_your_own_vendor_evaluation\" >Sample language for your own vendor evaluation<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-35\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#A_glossary_of_the_compliance_terms_in_this_index\" >A glossary of the compliance terms in this index<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-36\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Why_some_well_known_AI_tools_are_not_in_this_index\" >Why some well known AI tools are not in this index<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-37\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Limitations_of_this_index_and_how_to_use_it_responsibly\" >Limitations of this index, and how to use it responsibly<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-38\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#How_this_research_was_conducted\" >How this research was conducted<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-39\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Disclosure\" >Disclosure<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-40\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Where_this_index_expects_the_biggest_changes_over_the_next_year\" >Where this index expects the biggest changes over the next year<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-41\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Why_this_stops_being_optional_heading_into_2027\" >Why this stops being optional heading into 2027<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-42\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Key_numbers_from_this_index_in_one_place\" >Key numbers from this index, in one place<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-43\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Frequently_asked_questions\" >Frequently asked questions<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-44\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#The_bottom_line\" >The bottom line<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-45\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#How_we_will_keep_this_index_current\" >How we will keep this index current<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-46\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#How_to_cite_this_index\" >How to cite this index<\/a><\/li><li class='ez-toc-page-1 ez-toc-heading-level-2'><a class=\"ez-toc-link ez-toc-heading-47\" href=\"https:\/\/clickbaton.com\/blog\/the-ai-data-privacy-index-how-12-leading-ai-tools-handle-your-data\/#Sources_and_further_reading\" >Sources and further reading<\/a><\/li><\/ul><\/nav><\/div>\n<div id=\"bsf_rt_marker\"><\/div>\n<p class=\"wp-block-paragraph\"><em>An independent, sourced comparison of what happens to your prompts, files, and client data across ChatGPT, Gemini, Copilot, Claude, Meta AI, Grok, Perplexity, Mistral, DeepSeek, Amazon Q, Harvey, and CoCounsel, scored against a single transparent methodology, with a link to the original policy behind every claim.<\/em><\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/clickbaton.com\/blog\/wp-content\/uploads\/2026\/08\/ai_privacy_index_leaderboard.svg\" alt=\"A leaderboard style illustration ranks twelve labeled AI tool icons from highest to lowest score on a tiered podium, with a magnifying glass hovering over the data flowing beneath them\" class=\"wp-image-204\" style=\"aspect-ratio:1.7144048363560558;width:721px;height:auto\"\/><figcaption class=\"wp-element-caption\"><strong><em>A leaderboard style illustration ranks twelve labeled AI tool icons from highest to lowest score on a tiered podium, with a magnifying glass hovering over the data flowing beneath them<\/em><\/strong><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Nearly every organization now uses generative AI somewhere inside its walls. Far fewer can answer a simple question about any specific tool on that list: what actually happens to the information typed into it. According to KPMG&#8217;s Q4 2025 AI Quarterly Pulse Survey, <strong>77 percent of AI leaders now cite data privacy as a significant concern for their AI strategy<\/strong>, up sharply from 53 percent earlier the same year, a jump the report attributes directly to how fast agentic and generative tools have spread into daily workflows, according to <a href=\"https:\/\/secureframe.com\/blog\/data-privacy-statistics\">figures compiled by Secureframe<\/a>. A separate 2026 survey from Writer and Workplace Intelligence, covering 1,200 C suite executives, found that <strong>67 percent of executives believe their company has already suffered a data breach caused by an unapproved AI tool<\/strong>, according to <a href=\"https:\/\/writer.com\/blog\/enterprise-ai-adoption-2026\/\">Writer&#8217;s own published findings<\/a>. Perhaps most telling, K2view&#8217;s 2026 State of Enterprise Data Compliance survey found that <strong>98 percent of organizations report using generative AI with enterprise data, while only 13 percent have implemented technical controls to keep sensitive data out of those systems in the first place<\/strong>, a gap summarized in <a href=\"https:\/\/www.k2view.com\/news-blog\/2026-state-of-enterprise-data-compliance-survey\/\">K2view&#8217;s survey release<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That gap, between how widely these tools are used and how little most organizations actually know about their data practices, is the reason this index exists. We spent weeks reading the actual privacy policies, trust center documentation, data processing addenda, and independent compliance research behind twelve of the AI tools most commonly used by legal and business teams, and scored each one against the same eight category framework, described in full below. Every fact in every profile links to its original source, so you can verify it, and so other researchers, journalists, and IT teams can cite the specific claim rather than the index as a whole.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>This is not a benchmark of which tool writes the best email or drafts the sharpest contract clause.<\/strong> Plenty of other comparisons already cover quality and capability. This index answers a narrower, and for a law firm or a finance team, considerably higher stakes question: if you or your employees put real client information, financial figures, or confidential business data into this tool, what actually happens to it, who can see it, how long is it kept, and what would you need to prove that to a regulator, an auditor, or a client who asked.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Key_findings_at_a_glance\"><\/span>Key findings at a glance<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The two purpose built legal AI platforms in this index, CoCounsel and Harvey, scored highest overall<\/strong>, not because they are more secure in some abstract sense, but because neither one offers a free consumer tier at all, which removes the single biggest liability dragging down every general purpose competitor: a default configuration that trains on user conversations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Every mainstream consumer AI product we reviewed trains on your conversations by default on its free tier, with the sole partial exception of Mistral, which excludes its paid Le Chat Pro tier from training as well.<\/strong> ChatGPT, Gemini, Grok, Meta AI, and Perplexity all ship with training enabled out of the box on their free products, requiring a user to actively find and flip a setting to opt out, and in Grok&#8217;s case, the training applies to public content whether or not the person has ever opened the Grok product at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Jurisdiction turned out to matter as much as policy wording.<\/strong> DeepSeek&#8217;s hosted service stores user data in the People&#8217;s Republic of China, where the 2017 National Intelligence Law compels organizations to cooperate with state intelligence work on request, a structural fact no contract or privacy policy can override, which is why it scores lowest in this index regardless of how its technical safeguards read on paper.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A large compliance certification list does not automatically mean data stays where you think it does.<\/strong> Microsoft 365 Copilot carries a strong compliance portfolio and an EU Data Boundary commitment, yet a routing feature called Flex Routing became active by default for new EU and EFTA tenants in 2026, sending some processing outside that boundary unless an administrator manually disables it, a detail that pulled its score down despite otherwise solid enterprise documentation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The full scoring table, methodology, and all twelve detailed profiles follow below.<\/strong><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Methodology_and_why_we_built_it_this_way\"><\/span>Methodology, and why we built it this way<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An index is only as useful as its ability to be checked, argued with, and reproduced. Here is exactly how every score in this piece was built, so you can weigh it, disagree with parts of it, or apply the same framework to a tool we did not cover.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We evaluated each tool against eight categories, drawn directly from the questions a security or compliance reviewer actually asks during AI vendor due diligence, weighted by how much they typically matter to a legal or business team handling confidential material. Each category is scored from zero to ten based on the vendor&#8217;s own published policy, trust center documentation, and, where relevant, independent verification such as regulatory findings or third party security research, then scaled to its weight below. <strong>Every score reflects the vendor&#8217;s default, standard commercial configuration, not the strongest custom enterprise contract a large customer with significant leverage might individually negotiate<\/strong>, since that is the realistic starting point for the mid size firms and business teams this index is written for.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/clickbaton.com\/blog\/wp-content\/uploads\/2026\/08\/methodology_scoring_wheel.svg\" alt=\"A radial wheel diagram divides into eight labeled wedges of varying size, each representing one scoring category and its weight, arranged around a central AI data privacy index label\" class=\"wp-image-205\" style=\"width:691px;height:auto\"\/><figcaption class=\"wp-element-caption\"><strong><em>A radial wheel diagram divides into eight labeled wedges of varying size, each representing one scoring category and its weight, arranged around a central AI data privacy index label<\/em><\/strong><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>Default training posture, worth 20 of 100 points.<\/strong> Does the tool&#8217;s standard commercial or paid tier use customer conversations, files, or outputs to train future models by default, and if so, how easy is it to opt out. This category carries the heaviest weight because it determines whether a single careless prompt can end up shaping a model other customers interact with later.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Zero data retention availability, worth 15 points.<\/strong> Can an organization contractually eliminate storage of its prompts and outputs entirely, rather than merely excluding them from training. Retention and training are separate questions. A tool can honestly promise not to train on your data while still keeping a stored copy on a server for weeks, which matters enormously if that server is ever breached or subpoenaed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Data residency and regional control, worth 10 points.<\/strong> Can an organization specify or restrict which country or region processes and stores its data, and does the vendor&#8217;s default routing actually honor that commitment under normal operating conditions, including periods of high demand.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Compliance certifications, worth 15 points.<\/strong> Does the vendor hold independently audited certifications relevant to a regulated business, specifically SOC 2 Type II, ISO\/IEC 27001, ISO\/IEC 42001, and the availability of a signed HIPAA Business Associate Agreement for organizations handling health information. We weight Type II attestations, which verify controls over a period of months, more heavily than a Type I attestation, which only confirms controls existed on a single date.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Human review transparency, worth 10 points.<\/strong> Does the vendor disclose whether human staff or contractors can read customer conversations, under what circumstances, and does the organization have any way to disable that review.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Subprocessor transparency and contract terms, worth 10 points.<\/strong> Does the vendor publish a current list of the third party subprocessors that may touch customer data, and does it offer a real, signed Data Processing Addendum rather than a general privacy policy alone.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Regulatory and incident track record, worth 10 points.<\/strong> Has the vendor faced a regulatory fine, an enforcement action, or a significant, publicly documented security incident tied to how it handles user data, and how did it respond. This category looks backward deliberately, because a company&#8217;s response to its own past failure is often the clearest signal of how seriously it takes the underlying commitment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Free and entry level tier protection, worth 10 points.<\/strong> Because employees routinely reach for whichever version of a tool is fastest to access, often a personal, unmanaged account entirely outside their employer&#8217;s visibility, we separately score how protected the cheapest or free version of each product is, rather than assuming every user will be sitting inside a properly licensed enterprise deployment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A note on what this index cannot tell you.<\/strong> Contract terms are legally binding but cannot be technically verified from the outside, which is a real limitation of any policy based review, ours included. Vendor policies change, sometimes with little notice, as this index itself documents happening to more than one company covered here. Treat every score as a snapshot as of the research date below, verify the current policy and your specific contract before making a decision that depends on it, and remember that none of this constitutes legal advice. We are not lawyers, and this index is not a substitute for your own counsel&#8217;s review of your specific data, your specific jurisdiction, and your specific vendor agreement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Research for this index was conducted primarily in July and August 2026<\/strong>, drawing on each vendor&#8217;s own trust center, privacy policy, and enterprise documentation as the primary source for every factual claim, supplemented by independent security research and regulatory filings where noted.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_full_scoring_table\"><\/span>The full scoring table<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/clickbaton.com\/blog\/wp-content\/uploads\/2026\/08\/twelve_tools_score_chart.svg\" alt=\"A horizontal bar chart ranks all twelve AI tools from CoCounsel at 90 down to DeepSeek at 12, colored teal for high scores, amber for middle scores, and red for the lowest scores\" class=\"wp-image-206\" style=\"aspect-ratio:1.5790131168019987;width:789px;height:auto\"\/><figcaption class=\"wp-element-caption\"><strong><em>A horizontal bar chart ranks all twelve AI tools from CoCounsel at 90 down to DeepSeek at 12, colored teal for high scores, amber for middle scores, and red for the lowest scores<\/em><\/strong><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">This table is free to reference, embed, or cite in your own work. We only ask that you link back to this page as the source, so readers can see the full methodology and check the underlying research themselves.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Rank<\/th><th>Tool<\/th><th>Total score \/100<\/th><th>Trains on paid tier by default<\/th><th>Zero data retention available<\/th><th>Free tier trains by default<\/th><\/tr><\/thead><tbody><tr><td>1<\/td><td>Thomson Reuters CoCounsel<\/td><td>90<\/td><td>No<\/td><td>Yes<\/td><td>No free tier<\/td><\/tr><tr><td>2<\/td><td>Harvey<\/td><td>88<\/td><td>No<\/td><td>Yes<\/td><td>No free tier<\/td><\/tr><tr><td>3<\/td><td>Amazon Q (Business\/Developer)<\/td><td>78<\/td><td>No<\/td><td>Yes, Developer Pro by default<\/td><td>Developer Free requires opt out<\/td><\/tr><tr><td>4<\/td><td>Mistral (Le Chat \/ La Plateforme)<\/td><td>74<\/td><td>No, from Pro tier up<\/td><td>Yes, Scale plan, API only<\/td><td>Yes, Experiment tier<\/td><\/tr><tr><td>5<\/td><td>Anthropic Claude<\/td><td>70<\/td><td>No, Team\/Enterprise\/API<\/td><td>Yes, API addendum<\/td><td>Yes, since September 2025<\/td><\/tr><tr><td>6<\/td><td>OpenAI ChatGPT<\/td><td>68<\/td><td>No, Team\/Enterprise\/API<\/td><td>Yes, qualifying orgs<\/td><td>Yes, Free and Plus<\/td><\/tr><tr><td>7<\/td><td>Google Gemini<\/td><td>66<\/td><td>No, Workspace\/Vertex<\/td><td>Yes, Vertex, contractual<\/td><td>Yes, consumer app<\/td><\/tr><tr><td>8<\/td><td>Microsoft Copilot<\/td><td>64<\/td><td>No, commercial M365<\/td><td>Not standardized<\/td><td>Consumer Copilot not enterprise ready<\/td><\/tr><tr><td>9<\/td><td>Perplexity<\/td><td>58<\/td><td>No, Enterprise Pro\/Max<\/td><td>Yes, Sonar API<\/td><td>Yes, Free\/Pro\/Max<\/td><\/tr><tr><td>10<\/td><td>xAI Grok<\/td><td>25<\/td><td>Limited enterprise documentation<\/td><td>Not publicly documented<\/td><td>Yes, all public posts, opt in default<\/td><\/tr><tr><td>11<\/td><td>Meta AI<\/td><td>22<\/td><td>No enterprise consumer equivalent<\/td><td>Not applicable<\/td><td>Yes, largely without opt out in the US<\/td><\/tr><tr><td>12<\/td><td>DeepSeek, hosted service<\/td><td>12<\/td><td>Not applicable, no enterprise DPA<\/td><td>No<\/td><td>Yes, and processed in China<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How to read this table.<\/strong> A high score means the tool&#8217;s default, standard commercial configuration keeps your data more contained, more transparent, and more contractually protected. It does not mean the tool is more accurate, more capable, or a better fit for your specific task. A law firm&#8217;s document review workflow and a marketing team&#8217;s brainstorming session have very different risk profiles even when using the identical product, and the checklist later in this guide will help you map your own use case to the right tier and the right tool.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_complete_rankings_with_the_one_line_version_of_why\"><\/span>The complete rankings, with the one line version of why<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ol class=\"wp-block-list\">\n<li><strong>Thomson Reuters CoCounsel, 90\/100.<\/strong> Enterprise only, zero retention API architecture, triple certified, no training on customer data at any tier, no publicly documented incident.<\/li>\n\n\n\n<li><strong>Harvey, 88\/100.<\/strong> Enterprise only, SOC 2 Type II and ISO 27001, configurable data residency, first legal AI startup certified under the EU-US Data Privacy Framework.<\/li>\n\n\n\n<li><strong>Amazon Q, 78\/100.<\/strong> Inherits AWS&#8217;s broad compliance stack including HIPAA and ISO 42001, identity aware retrieval that respects existing document permissions, privacy by default on the paid developer tier.<\/li>\n\n\n\n<li><strong>Mistral, 74\/100.<\/strong> French entity operating under EU jurisdiction by default, the only major consumer facing product that excludes its Pro tier from training, genuine self hosting option for maximum control.<\/li>\n\n\n\n<li><strong>Anthropic Claude, 70\/100.<\/strong> Strongest certification stack in the index including ISO 42001, but a September 2025 consumer policy reversal now trains on Free, Pro, and Max conversations by default unless a user opts out.<\/li>\n\n\n\n<li><strong>OpenAI ChatGPT, 68\/100.<\/strong> Solid enterprise privacy commitments and SOC 2 Type 2 coverage, offset by a 2024 GDPR fine, an ongoing court order affecting deleted chat retention, and free tier training by default.<\/li>\n\n\n\n<li><strong>Google Gemini, 66\/100.<\/strong> Enterprise and Workspace tiers are genuinely strong, but the consumer app explicitly discloses human review of conversations and defaults to an 18 month retention window.<\/li>\n\n\n\n<li><strong>Microsoft Copilot, 64\/100.<\/strong> Strong compliance documentation undercut by a 2026 default routing change that can send EU tenant data outside the EU Data Boundary unless an administrator manually intervenes.<\/li>\n\n\n\n<li><strong>Perplexity, 58\/100.<\/strong> A real, clean split between a training by default consumer product and a genuinely protective Enterprise tier with SOC 2 Type II and a seven day file retention window.<\/li>\n\n\n\n<li><strong>xAI Grok, 25\/100.<\/strong> Trains on your entire public post history by default, whether or not you have ever used Grok, and is currently the subject of enforcement action in at least eight countries.<\/li>\n\n\n\n<li><strong>Meta AI, 22\/100.<\/strong> Feeds conversational signals directly into advertising personalization with an opt out that is unavailable to most users outside the EU and Brazil.<\/li>\n\n\n\n<li><strong>DeepSeek, hosted service, 12\/100.<\/strong> Data is processed and stored in the People&#8217;s Republic of China under laws that compel state access, with no DPA, no BAA, and no lawful EU transfer mechanism currently documented.<\/li>\n<\/ol>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Twelve_tools_in_depth\"><\/span>Twelve tools, in depth<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"1_Thomson_Reuters_CoCounsel_score_90100\"><\/span>1. Thomson Reuters CoCounsel, score 90\/100<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/clickbaton.com\/blog\/wp-content\/uploads\/2026\/08\/legal_tools_spotlight.svg\" alt=\"A courthouse building with a shield overlapping its center, flanked by two labeled cards for CoCounsel scoring 90 and Harvey scoring 88, both noted as having no free tier\" class=\"wp-image-207\" style=\"width:773px;height:auto\"\/><figcaption class=\"wp-element-caption\"><strong><em>A courthouse building with a shield overlapping its center, flanked by two labeled cards for CoCounsel scoring 90 and Harvey scoring 88, both noted as having no free tier<\/em><\/strong><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">CoCounsel Legal, built from Thomson Reuters&#8217; 2023 acquisition of Casetext, is the highest scoring tool in this index, and the reason is structural as much as technical. <strong>There is no free or individual consumer tier at all.<\/strong> Every CoCounsel deployment is a professional, contracted engagement, which removes the single weakness that drags down almost every other product in this index: a default consumer configuration that trains on whatever a person happens to type.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Thomson Reuters states plainly that CoCounsel is <strong>not trained on any customer data<\/strong>, and that the underlying models are instead developed using content generated and reviewed by its own team of bar admitted attorneys and data scientists, according to the company&#8217;s own <a href=\"https:\/\/legal.thomsonreuters.com\/blog\/the-two-non-negotiables-of-secure-legal-ai\/\">guidance on government legal AI<\/a>. The platform holds <strong>SOC 2 Type II, ISO 27001, and ISO 42001 certification<\/strong>, runs on Azure infrastructure, and uses what the company describes as a zero retention API architecture for its interactions with underlying large language models, meaning prompts are not persisted after processing, according to <a href=\"https:\/\/theaiagentindex.com\/agents\/cocounsel\">independent verification published by The AI Agent Index<\/a> and Thomson Reuters&#8217; own <a href=\"https:\/\/legal.thomsonreuters.com\/blog\/responsible-ai-in-courts-the-answer-is-cocounsel-legal\/\">security documentation<\/a>. The company states CoCounsel is used by <strong>99.6 percent of Fortune 500 companies and all United States federal courts<\/strong> in some capacity across its broader legal and tax products.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We found no publicly documented data breach or regulatory action specific to CoCounsel&#8217;s AI data handling as of this research. The tradeoff is one of fit, not safety: CoCounsel&#8217;s core value proposition ties closely to Thomson Reuters&#8217; own Westlaw and Practical Law content, meaning firms evaluating it are often evaluating a broader ecosystem commitment, not a standalone tool, and its pricing sits at enterprise scale rather than the self serve range a solo practitioner might expect.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"2_Harvey_score_88100\"><\/span>2. Harvey, score 88\/100<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Harvey, the legal AI platform used by firms including A&amp;O Shearman and Paul Weiss, scores nearly as high as CoCounsel for almost identical structural reasons: <strong>it is enterprise only, with no consumer tier to weaken the average<\/strong>, and its security posture is unusually well documented for a company of its age.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Harvey holds <strong>SOC 2 Type II and ISO 27001 certification from the auditing firm Schellman<\/strong>, publishes a formal Security Addendum with binding terms on data protection, access, and incident response service levels, and states it does not train its production models on customer data, according to the company&#8217;s own <a href=\"https:\/\/www.harvey.ai\/security\">security overview<\/a> and <a href=\"https:\/\/theplanettools.ai\/tools\/harvey-ai\">independent legal AI review<\/a>. Notably, <strong>Harvey was the first AI or large language model startup to certify under the EU-US Data Privacy Framework<\/strong>, and the company says it has withstood a two week assumed breach red team exercise conducted by Bishop Fox without a failed customer security assessment to date, according to Harvey&#8217;s own <a href=\"https:\/\/www.harvey.ai\/blog\/security-by-design\">account of its security program<\/a>. Harvey offers <strong>configurable data residency<\/strong>, letting firms with GDPR or jurisdiction specific requirements specify where their data is processed.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where Harvey loses ground relative to CoCounsel is largely a matter of degree rather than category: it holds two of the three certifications CoCounsel carries, having not yet been independently confirmed for ISO 42001 in our research, and as a younger, faster growing company it has a shorter public track record to evaluate against. For firms specifically prioritizing the deepest legal research grounding alongside AI drafting, this is a genuine and reasonable point of differentiation from CoCounsel, not a security gap.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"3_Amazon_Q_score_78100\"><\/span>3. Amazon Q, score 78\/100<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Amazon Q, AWS&#8217;s generative AI assistant split across Amazon Q Business and Amazon Q Developer, is the highest scoring general purpose product in this index, largely because it inherits the compliance infrastructure AWS has spent two decades building for its broader cloud business.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Amazon Q Business is compliant with <strong>HIPAA, SOC 1, 2, and 3, PCI, and ISO 42001<\/strong>, according to <a href=\"https:\/\/docs.aws.amazon.com\/amazonq\/latest\/qbusiness-ug\/compliance-validation.html\">AWS&#8217;s own compliance documentation<\/a>, and operates on the AWS shared responsibility model, where Amazon secures the underlying infrastructure while the customer configures access controls on top of it. A distinctive strength is Amazon Q Business&#8217;s <strong>identity aware retrieval<\/strong>: the system validates each user&#8217;s identity against AWS IAM Identity Center and only surfaces answers drawn from documents that specific user already has permission to see, rather than pooling all indexed content into a single shared context, according to <a href=\"https:\/\/aws.amazon.com\/blogs\/machine-learning\/build-private-and-secure-enterprise-generative-ai-apps-with-amazon-q-business-and-aws-iam-identity-center\">AWS&#8217;s technical documentation on the feature<\/a>. On the developer side, <strong>Amazon Q Developer Pro does not use customer data for service improvement by default<\/strong>, a meaningfully stronger starting position than most consumer coding assistants, while the free tier requires an explicit opt out of telemetry collection, according to a <a href=\"https:\/\/dev.to\/nicoherzhauser\/protecting-your-data-a-developers-guide-to-aws-ai-opt-out-policies-400g\">developer focused audit of AWS&#8217;s AI opt out policies<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Amazon Q loses points relative to the two legal specific tools above it for a straightforward reason: it is a broad, general purpose enterprise product rather than one purpose built around a single, unusually strict professional confidentiality standard, and its documentation, while thorough, is spread across many separate AWS services rather than centralized in one clear trust center the way CoCounsel and Harvey present it.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"4_Mistral_score_74100\"><\/span>4. Mistral, score 74\/100<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Mistral, the French AI company behind Le Chat and the La Plateforme API, is the highest scoring general purpose consumer facing product in this index, for one specific reason almost no competitor matches: <strong>its paid Le Chat Pro tier, at roughly 15 dollars a month, excludes user input from training by default<\/strong>, not just its enterprise tier, according to <a href=\"https:\/\/weventure.de\/en\/blog\/mistral\">independent European privacy analysis<\/a>. Every other mainstream consumer product in this index keeps training enabled through at least one paid individual tier before finally excluding it at the team or enterprise level.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mistral is incorporated in France and operates under EU jurisdiction as its default posture, with <strong>La Plateforme running primarily on EU based infrastructure and a Data Processing Addendum written with GDPR as the baseline rather than an afterthought<\/strong>, according to <a href=\"https:\/\/meetily.ai\/llm-privacy\/mistral\">Meetily&#8217;s policy summary<\/a>. For organizations that need the strongest possible control, Mistral&#8217;s models are genuinely open weight, meaning a firm can <strong>self host them entirely<\/strong>, achieving zero external data exposure by design, an option most closed model competitors simply do not offer at any price. Zero Data Retention is available on the Scale plan for stateless API calls including chat completions and embeddings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mistral is not without friction. A French lawyer filed a complaint with the CNIL, France&#8217;s data protection authority, in February 2025, <strong>alleging that free tier users faced a meaningfully more cumbersome opt out process than paid subscribers<\/strong>, a complaint the CNIL had not yet resolved as of this research, according to <a href=\"https:\/\/www.waimakers.com\/en\/resources\/gdpr-compliance\/mistral-ai\">WAIMAKERS&#8217; compliance tracking<\/a>. Mistral has also expanded its Google Cloud Platform footprint to include United States processing capacity alongside its EU infrastructure, introducing a degree of CLOUD Act exposure for workloads routed through that expanded capacity that a purely EU hosted deployment would not carry.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"5_Anthropic_Claude_score_70100\"><\/span>5. Anthropic Claude, score 70\/100<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Claude&#8217;s enterprise and developer facing policies are among the strongest documented in this index. Its consumer product&#8217;s policy, however, changed in a way that meaningfully affects this score, and both facts deserve equal, honest treatment.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the strong side: Anthropic&#8217;s commercial surfaces, meaning the <strong>Claude API, Team, and Enterprise plans, do not use customer inputs or outputs for training by default<\/strong>, a commitment written into the commercial terms, and enterprise API customers can add a <strong>Zero Data Retention addendum that prevents conversation data from being written to disk at any point during or after a session<\/strong>, according to <a href=\"https:\/\/readysolutions.ai\/blog\/2026-06-08-claude-data-handling-due-diligence\/\">detailed 2026 compliance research<\/a>. Anthropic holds <strong>SOC 2 Type I and Type II, ISO 27001:2022, and ISO\/IEC 42001:2023<\/strong>, the AI specific management standard, and will sign a HIPAA Business Associate Agreement for eligible services, a combination Cleveland Clinic relied on when deploying Claude across 120 hospitals, according to <a href=\"https:\/\/anonyome.com\/knowledge-center\/ai-privacy\/claude-privacy\/\">Anonyome&#8217;s privacy research<\/a>. FedRAMP certification was reported in progress as of early 2026.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On the weaker side, and this matters for any team relying on individual Claude Pro or Max subscriptions rather than a managed Enterprise deployment: <strong>in August 2025, Anthropic changed its consumer policy so that Free, Pro, and Max users must actively opt out if they do not want their conversations used to train future models<\/strong>, with a deadline of September 28, 2025, after which conversations for users who took no action became eligible for training and retention of up to five years, up from a 30 day standard, according to <a href=\"https:\/\/anarlog.so\/blog\/anthropic-data-retention-policy\/\">Anarlog&#8217;s detailed retention policy breakdown<\/a>. Critics, cited in independent privacy research, have described the opt in interface, a large pre toggled accept button, as a <strong>potential dark pattern<\/strong>, and as of this research the question of its GDPR compliance remained contested with no regulatory decision yet issued, according to <a href=\"https:\/\/anonyome.com\/knowledge-center\/ai-privacy\/claude-privacy\/\">Anonyome&#8217;s analysis<\/a>. This is a real and material reversal from Anthropic&#8217;s earlier, stricter consumer default, and any team using Claude Pro or Max for client adjacent work should confirm their organization&#8217;s settings directly rather than relying on Anthropic&#8217;s earlier reputation.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"6_OpenAI_ChatGPT_score_68100\"><\/span>6. OpenAI ChatGPT, score 68\/100<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">ChatGPT is the most widely deployed AI product in this index, and its enterprise privacy commitments are genuinely solid: <strong>ChatGPT Team, Enterprise, Edu, and the API do not use inputs or outputs for training by default<\/strong>, a commitment stated directly in OpenAI&#8217;s own <a href=\"https:\/\/openai.com\/enterprise-privacy\/\">enterprise privacy documentation<\/a>. OpenAI holds a <strong>SOC 2 Type 2 examination covering its API and ChatGPT business products<\/strong>, ISO\/IEC 27001:2022 and 27701:2019 certifications, and offers a Data Processing Addendum and HIPAA Business Associate Agreement for qualifying customers, formalized further with the January 2026 launch of ChatGPT for Healthcare, according to <a href=\"https:\/\/openai.com\/security-and-privacy\/\">OpenAI&#8217;s security and privacy page<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The gaps that keep ChatGPT&#8217;s score in the middle of this index are well documented elsewhere in our research. <strong>Free and Plus tier conversations may be used to improve OpenAI&#8217;s models unless a user actively opts out<\/strong>, according to <a href=\"https:\/\/www.strac.io\/blog\/chatgpt-data-privacy\/\">Strac&#8217;s ChatGPT privacy breakdown<\/a>, and even where training is disabled, conversations are still transmitted and retained for a standard 30 day window for abuse monitoring, meaning &#8220;not trained on&#8221; and &#8220;not stored&#8221; are two separate promises that are easy to conflate. OpenAI was also the subject of the first GDPR fine ever issued against a generative AI company, a <strong>15 million euro penalty from Italy&#8217;s Garante in December 2024<\/strong>, and remains subject to an ongoing US federal court order, discussed in our companion guide to cloud AI risk, that at one point required preservation of ChatGPT conversations users believed they had deleted, as part of unrelated litigation with The New York Times.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"7_Google_Gemini_score_66100\"><\/span>7. Google Gemini, score 66\/100<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Gemini presents one of the starkest internal splits in this index between its consumer and enterprise identities, and that split is exactly what shapes its middle of the pack score.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google states directly that <strong>enterprise data used within Gemini for Workspace and Gemini for Cloud is not used for model training and is not reviewed by humans<\/strong>, a commitment backed by Gemini Enterprise&#8217;s inherited compliance framework of <strong>ISO 27001, 27017, and 27018, and FedRAMP authorization for US government use<\/strong>, according to <a href=\"https:\/\/www.c-sharpcorner.com\/article\/does-google-use-my-data-to-train-gemini-enterprise-ai\/\">C-Sharp Corner&#8217;s enterprise privacy analysis<\/a>. Vertex AI, Google Cloud&#8217;s developer platform, offers zero data retention equivalent terms for eligible enterprise customers through contractual commitments layered onto its Data Processing Addendum, alongside SOC 2 Type 2 and HIPAA BAA eligibility, according to <a href=\"https:\/\/meetily.ai\/llm-privacy\/gemini\">Meetily&#8217;s policy tracking<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The consumer Gemini app tells a different story, and Google is unusually direct about it: the product&#8217;s own guidance warns users <strong>not to enter anything they would not want a human reviewer to see<\/strong>, because selected conversations may be reviewed by trained human staff to evaluate response quality, according to <a href=\"https:\/\/www.strac.io\/blog\/gemini-data-privacy\">Strac&#8217;s Gemini privacy research<\/a>. Consumer Gemini defaults to an <strong>eighteen month retention window<\/strong>, and disabling training and human review requires turning off Gemini Apps Activity entirely, which also erases chat history as a side effect, according to <a href=\"https:\/\/anarlog.so\/blog\/google-gemini-data-retention-policy\/\">independent retention policy documentation<\/a>. Security researchers have also flagged Google&#8217;s newer Personal Intelligence and Gemini Spark features, which connect Gmail, Photos, and search history into a single AI reasoning context and, as of mid 2026, can act autonomously across connected tools, as raising questions about where that reasoning happens and how long the combined context is retained, concerns detailed in <a href=\"https:\/\/concentric.ai\/google-gemini-security-risks\/\">Concentric&#8217;s security research<\/a>.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"8_Microsoft_Copilot_score_64100\"><\/span>8. Microsoft Copilot, score 64\/100<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Microsoft 365 Copilot&#8217;s commercial documentation reads, at first pass, like one of the strongest in this index. <strong>Prompts, responses, and data accessed through Microsoft Graph are not used to train foundation large language models<\/strong>, and the product inherits the full weight of Microsoft 365&#8217;s existing commercial privacy, security, and GDPR compliance commitments, according to <a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/copilot\/microsoft-365-copilot-privacy\">Microsoft&#8217;s own Copilot privacy documentation<\/a>. The <strong>EU Data Boundary<\/strong> commits to processing and storing EU customer data within the EU and EEA, and admins can layer Microsoft Purview retention policies, audit logging, and eDiscovery controls directly on top of Copilot activity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Two developments specific to 2026 pull Copilot&#8217;s score down meaningfully. First, <strong>a routing feature called Flex Routing became active by default for new EU, EFTA, and UK tenants created after March 25, 2026<\/strong>, and can send Copilot processing to infrastructure outside the EU Data Boundary during periods of high demand unless an administrator manually disables it, a change flagged as compliance relevant by <a href=\"https:\/\/www.waimakers.com\/en\/resources\/ai-data-security\/microsoft-365-copilot\">WAIMAKERS&#8217; AI data security guide<\/a> and confirmed by <a href=\"https:\/\/changepilot.cloud\/blog\/microsoft-365-copilot-flex-routing-eu-data-boundary-mc1269223\">ChangePilot&#8217;s dedicated coverage<\/a>, which noted organizations had only until April 17, 2026 to review and adjust the setting before it took effect. Second, Microsoft added <strong>Anthropic&#8217;s Claude as a subprocessor for supported Office experiences beginning January 7, 2026<\/strong>, a change German data protection authorities specifically flagged as requiring an updated Data Protection Impact Assessment and Transfer Impact Assessment before continued use, according to <a href=\"https:\/\/compound.law\/en-DE\/tools\/copilot-microsoft-365\/\">Compound&#8217;s German GDPR compliance analysis<\/a>. Separately, the consumer Copilot product, available free at copilot.microsoft.com, is explicitly described by independent researchers as <strong>not suitable for processing personal data about EU data subjects in most professional contexts<\/strong> without additional legal review, according to <a href=\"https:\/\/sonomos.ai\/blog\/is-microsoft-copilot-gdpr-compliant-2026\/\">Sonomos&#8217; GDPR compliance guide<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Copilot&#8217;s commercial product also carries the significant EchoLeak vulnerability disclosed in June 2025, covered in depth in our companion guide to AI agent risk, a zero click prompt injection flaw rated 9.3 out of 10 in severity that allowed attacker controlled data exfiltration with no user interaction required, since patched but a meaningful mark against the product&#8217;s track record for this index&#8217;s incident history category.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"9_Perplexity_score_58100\"><\/span>9. Perplexity, score 58\/100<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Perplexity, the AI powered search and answer engine, shows a cleaner version of the consumer versus enterprise split seen elsewhere in this index, with a genuinely strong Enterprise tier offsetting a training by default consumer product.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Perplexity Enterprise data is never used for AI training purposes<\/strong>, uploaded files are retained for a <strong>limited seven day window<\/strong>, and the company holds <strong>SOC 2 Type II certification<\/strong>, according to Perplexity&#8217;s own <a href=\"https:\/\/www.perplexity.ai\/help-center\/en\/articles\/11564572-data-collection-at-perplexity\">help center documentation<\/a>. Perplexity also states that its contractual agreements with the third party model providers it routes queries through, including OpenAI and Anthropic, <strong>explicitly prohibit those providers from using Perplexity traffic to train their own models<\/strong>, according to <a href=\"https:\/\/www.perplexity.ai\/help-center\/en\/articles\/10354963-are-third-party-model-providers-training-on-my-data\">Perplexity&#8217;s own disclosure<\/a>. The Sonar API, used by developers building on Perplexity&#8217;s infrastructure, operates under a strict Zero Data Retention policy with prompts and responses deleted immediately after processing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">On <strong>Free, Pro, and Max plans, AI training is enabled by default<\/strong>, requiring users to manually disable an &#8220;AI data retention&#8221; toggle in account settings to opt out, and opting out does not retroactively remove data already incorporated into training, according to <a href=\"https:\/\/www.strac.io\/blog\/perplexity-data-privacy\/\">Strac&#8217;s Perplexity privacy analysis<\/a>. Because Perplexity is fundamentally a search tool, its risk profile has a distinct shape from a standalone chatbot: users routinely paste substantial context, a contract clause, a stack trace, a candidate&#8217;s resume, directly into a query to get a better grounded answer, meaning the practical exposure on an unmanaged consumer account can be higher per query than an equivalent chatbot conversation, even before considering the training default.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"10_xAI_Grok_score_25100\"><\/span>10. xAI Grok, score 25\/100<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Grok, built by xAI and deeply integrated into the X platform, is the second lowest scoring tool in this index, and the reason is structural: <strong>Grok&#8217;s training data draws not just from conversations with the assistant, but from the entirety of a user&#8217;s public X posts, by default, whether or not that person has ever opened Grok at all<\/strong>, according to <a href=\"https:\/\/anonyome.com\/knowledge-center\/ai-privacy\/grok-privacy\/\">Anonyome&#8217;s detailed Grok privacy research<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">An opt out toggle exists, but researchers describe it as providing <strong>incomplete protection<\/strong>, since a user&#8217;s data remains available to X for other purposes under the platform&#8217;s 2026 terms even after the specific Grok training toggle is disabled, and data already incorporated into a completed training run cannot be retroactively removed, according to the same research. The regulatory response has been unusually broad and fast for a single product: <strong>regulators in at least eight jurisdictions, including the European Commission under the Digital Services Act, the UK&#8217;s ICO and Ofcom, and data protection authorities in Ireland, Canada, Brazil, France, and Spain, have confirmed formal action against X or xAI<\/strong>, according to an <a href=\"https:\/\/medium.com\/@AxiomHiveAi\/x-xais-grok-and-the-intersection-of-ai-training-data-privacy-and-minor-protection-988f748bed23\">independent regulatory analysis published on Medium<\/a>, with the Irish Data Protection Commission specifically opening a formal inquiry in April 2025 into the lawfulness of X&#8217;s earlier use of EU user data for Grok training, following an earlier Irish High Court order in September 2024 requiring X to permanently stop using EU and EEA users&#8217; public posts from a specific prior period for training.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Our research did not surface a clearly documented, separately governed enterprise tier for Grok with materially different data handling terms comparable to the enterprise offerings reviewed elsewhere in this index, which is itself a data point: for a business or legal team, the absence of a clear, separately contracted enterprise privacy posture is a meaningful gap relative to every other major lab covered here.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"11_Meta_AI_score_22100\"><\/span>11. Meta AI, score 22\/100<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n\n<p class=\"wp-block-paragraph\">Meta AI scores second from the bottom in this index, not primarily because of technical weakness, but because of how directly its data practices are tied to Meta&#8217;s advertising business, and how limited a typical user&#8217;s ability to opt out actually is.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Meta now feeds conversational signals from Meta AI interactions directly into its advertising personalization models<\/strong>, building unified interest profiles applied across Facebook, Instagram, Messenger, and Threads, according to <a href=\"https:\/\/www.auditsocials.com\/blog\/meta-ai-privacy-policy-ad-targeting-changes-2026\">AuditSocials&#8217; 2026 policy analysis<\/a>. The relevant setting is available under Settings, Privacy, AI Data Usage, but is <strong>opt out by default rather than opt in<\/strong>, and is described by the same research as buried within the settings menu. Meta&#8217;s position is that continued use of its updated Terms of Service, effective January 2026, constitutes consent. Privacy advocates in the EU have already filed complaints with the Irish Data Protection Commission arguing the practice violates GDPR&#8217;s purpose limitation principle.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Critically, <strong>most users outside the European Union and Brazil currently have no meaningful way to opt out of having their public content used for AI training at all<\/strong>, according to <a href=\"https:\/\/thedataprivacygroup.com\/blog\/meta-user-privacy\/\">The Data Privacy Group&#8217;s research<\/a>, and the privacy organization NOYB, led by Max Schrems, issued Meta a formal cease and desist letter over its plan to use European users&#8217; public data for AI training, a dispute that remained active as of this research. Meta does state that content from private, non public posts is excluded from AI training, meaning a user&#8217;s realistic exposure depends heavily on their own historical sharing habits, a distinction most people are unlikely to have tracked over years of platform use.<\/p>\n\n\n\n<h3 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"12_DeepSeek_hosted_service_score_12100\"><\/span>12. DeepSeek, hosted service, score 12\/100<span class=\"ez-toc-section-end\"><\/span><\/h3>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/clickbaton.com\/blog\/wp-content\/uploads\/2026\/08\/jurisdiction_zones_map.svg\" alt=\"Three jurisdiction zones, the European Union, United States, and China, each with a labeled server icon showing how government access to data differs by law rather than by contract\" class=\"wp-image-208\" style=\"aspect-ratio:1.935753024614101;width:793px;height:auto\"\/><figcaption class=\"wp-element-caption\"><strong><em>Three jurisdiction zones, the European Union, United States, and China, each with a labeled server icon showing how government access to data differs by law rather than by contract<\/em><\/strong><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">DeepSeek scores lowest in this index, and unlike every other product covered here, the deciding factor is not a settings toggle or a training default. <strong>It is jurisdiction, and jurisdiction cannot be configured away.<\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\">DeepSeek&#8217;s own privacy policy states directly that it <strong>collects, processes, and stores personal data in the People&#8217;s Republic of China<\/strong>, according to <a href=\"https:\/\/witness.ai\/blog\/deepseek-security-concerns\/\">Witness AI&#8217;s enterprise security analysis<\/a>. China&#8217;s 2017 National Intelligence Law requires that, in its own text, <strong>any organization or citizen shall support, assist, and cooperate with the state intelligence work<\/strong>, a legal obligation that sits above and outside any contractual privacy commitment DeepSeek itself might offer. This is not a claim that DeepSeek&#8217;s data is actively being misused. It is a structural fact about the legal environment its servers operate within, one that no Data Processing Addendum can contract around, a distinction laid out clearly by <a href=\"https:\/\/lumichats.com\/blog\/is-deepseek-safe-to-use-2026-usa\/\">LumiChats&#8217; 2026 assessment<\/a>.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The practical consequences have already materialized. <strong>Italy&#8217;s Garante blocked the DeepSeek app in January 2025<\/strong>, and data protection authorities in France, Ireland, Germany, Belgium, and Portugal opened their own investigations into the hosted service, according to <a href=\"https:\/\/www.promptquorum.com\/local-llms\/deepseek-local-china-data-privacy-2026\/\">PromptQuorum&#8217;s regulatory tracking<\/a>. Independent security researchers at SecurityScorecard separately identified <strong>passwords and authentication tokens stored in plaintext<\/strong> within the mobile app, alongside integration with ByteDance services and broad device permission requests, according to <a href=\"https:\/\/securityscorecard.com\/blog\/what-you-need-to-know-about-deepseek-security-issues-and-vulnerabilities\/\">SecurityScorecard&#8217;s published research<\/a>. DeepSeek currently offers <strong>no Data Processing Addendum, no HIPAA Business Associate Agreement, and no documented lawful mechanism for transferring EU personal data<\/strong> to its Chinese infrastructure. It is worth separating two distinct products here: the hosted app and API, scored above, versus DeepSeek&#8217;s genuinely open weight models, which, self hosted entirely within an organization&#8217;s own infrastructure with no connection back to DeepSeek&#8217;s servers, present a fundamentally different and far more defensible risk profile, a distinction covered in the local AI section later in this guide.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Quick_reference_one_paragraph_on_each_tool\"><\/span>Quick reference: one paragraph on each tool<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For readers who want the condensed version of every profile above in one scannable place, here it is, tool by tool, in ranked order.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>CoCounsel<\/strong> is Thomson Reuters&#8217; enterprise only legal AI platform, never trains on customer data, holds triple certification including the AI specific ISO 42001, and shows no documented incident in our research, making it the highest scoring tool in this index.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Harvey<\/strong> is the enterprise only legal AI platform used by major global law firms, SOC 2 Type II and ISO 27001 certified, the first legal AI startup certified under the EU-US Data Privacy Framework, and structurally strong for the same reason as CoCounsel: no consumer tier to weaken it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Amazon Q<\/strong> inherits AWS&#8217;s decades deep compliance infrastructure including HIPAA and ISO 42001, offers identity aware retrieval that respects existing document permissions, and is privacy by default on its paid developer tier, making it the strongest general purpose enterprise option in this index.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mistral<\/strong> is the only mainstream consumer product whose entry paid tier excludes training by default, operates under EU jurisdiction from a French legal entity, and offers a genuine self hosting option, though a CNIL complaint over free tier opt out friction and expanded US processing capacity keep it short of the top three.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Claude<\/strong> carries the deepest certification stack in this index on its commercial surfaces, but a September 2025 policy change now trains on Free, Pro, and Max conversations by default, a real and documented reversal from its earlier stricter consumer posture.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ChatGPT<\/strong> offers solid, SOC 2 Type 2 backed enterprise privacy commitments, undercut by free and Plus tier training by default, a 15 million euro GDPR fine, and an ongoing court order affecting how long some conversations must be preserved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Gemini<\/strong> shows one of the sharpest splits in this index, with a genuinely strong, FedRAMP authorized enterprise and Vertex AI tier sitting alongside a consumer app that explicitly warns users a human reviewer may read their conversations.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Copilot<\/strong> carries strong Microsoft 365 compliance credentials and an EU Data Boundary commitment, both meaningfully weakened by a 2026 default routing feature that can send some EU tenant data outside that boundary, and by the severe EchoLeak vulnerability disclosed in 2025.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Perplexity<\/strong> cleanly separates a training by default consumer product from a genuinely protective, SOC 2 Type II certified Enterprise tier with a short seven day file retention window, though its search and answer format means users tend to paste unusually sensitive context into individual queries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Grok<\/strong> trains on a user&#8217;s entire public X post history by default, whether or not that person has ever used Grok directly, and is currently the subject of confirmed regulatory action in at least eight countries.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Meta AI<\/strong> feeds conversational data directly into advertising personalization with an opt out unavailable to most users outside the EU and Brazil, making it one of the two lowest scoring tools in this index.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>DeepSeek&#8217;s<\/strong> hosted service stores data in China under laws that compel state cooperation with intelligence work, a jurisdictional fact no privacy policy can override, placing it last in this index regardless of its technical capability or cost advantage.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Superlatives_the_best_and_worst_in_each_category\"><\/span>Superlatives: the best and worst in each category<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Beyond the overall ranking, breaking the index down by individual category surfaces some of the most useful, and most surprising, findings.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Best free tier protection: Mistral.<\/strong> Its Experiment tier still trains by default like most competitors, but Mistral is the only company in this index whose first paid consumer tier, Le Chat Pro at roughly 15 dollars monthly, excludes training entirely, a threshold every other consumer product only clears at a team or enterprise price point.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Worst free tier protection: xAI Grok.<\/strong> No other tool in this index trains on data from a user who has never even opened the product, which is precisely what happens to anyone whose public X posts get pulled into Grok&#8217;s training set by default.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Deepest certification stack: Anthropic Claude.<\/strong> Claude is the only tool in this index confirmed to hold all of SOC 2 Type I and Type II, ISO 27001, and ISO 42001 simultaneously, though as this index documents, that certification depth applies specifically to its commercial surfaces, not its consumer default.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Most transparent about human review: Google Gemini.<\/strong> Somewhat counterintuitively, Gemini&#8217;s consumer product earns credit here for being unusually blunt about a real risk. Google&#8217;s own guidance tells users directly not to type anything into consumer Gemini that they would not want a human reviewer to read, a level of plain spoken disclosure this index did not find matched elsewhere.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Strongest jurisdictional position: Mistral, followed closely by the two legal specific tools.<\/strong> Mistral&#8217;s default EU incorporation and infrastructure, paired with a genuine self hosting option, gives it a structural jurisdiction advantage no US or China based competitor in this index can fully replicate without a customer specifically negotiating for it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Weakest jurisdictional position: DeepSeek, by a wide margin.<\/strong> No other tool in this index operates under a legal framework that compels state cooperation with intelligence work as a matter of national law, independent of anything the company itself might want to promise its customers.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Most improved documentation transparency: Amazon Q.<\/strong> AWS&#8217;s decision to publish a specific, itemized compliance validation list, including the newer ISO 42001 AI specific standard, alongside its identity aware retrieval architecture, gave researchers building this index an unusually clear picture relative to how AWS documentation has historically been organized across dozens of separate service pages.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Most concerning single incident: the Microsoft 365 Copilot EchoLeak vulnerability.<\/strong> A 9.3 out of 10 severity, zero click prompt injection flaw in one of the most widely deployed enterprise AI products in the world, requiring no user interaction whatsoever to trigger, is the most severe single technical incident documented across every tool in this index, covered in full in our companion guide to AI agent risk.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_each_tools_free_or_entry_tier_compares\"><\/span>How each tool&#8217;s free or entry tier compares<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/clickbaton.com\/blog\/wp-content\/uploads\/2026\/08\/free_vs_paid_fork.svg\" alt=\"Two diverging paths show the same prompt sent through a free tier, ending in a training pool, versus a paid protected tier, ending in a locked vault, illustrating the tier gap found across most tools in this index\" class=\"wp-image-209\" style=\"aspect-ratio:1.935753024614101;width:820px;height:auto\"\/><figcaption class=\"wp-element-caption\"><strong><em>Two diverging paths show the same prompt sent through a free tier, ending in a training pool, versus a paid protected tier, ending in a locked vault, illustrating the tier gap found across most tools in this index<\/em><\/strong><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">Because free and personal tier access is how AI tools most often spread inside an organization without a formal decision ever being made, it is worth isolating that specific comparison on its own.<\/p>\n\n\n\n<figure class=\"wp-block-table\"><table class=\"has-fixed-layout\"><thead><tr><th>Tool<\/th><th>Free tier trains by default<\/th><th>Opt out available<\/th><th>What opting out costs you<\/th><\/tr><\/thead><tbody><tr><td>ChatGPT<\/td><td>Yes, Free and Plus<\/td><td>Yes, in Data Controls<\/td><td>Nothing, setting persists<\/td><\/tr><tr><td>Gemini<\/td><td>Yes, consumer app<\/td><td>Yes, via Gemini Apps Activity<\/td><td>Loses chat history entirely<\/td><\/tr><tr><td>Copilot<\/td><td>Consumer version not enterprise appropriate<\/td><td>Limited<\/td><td>Product not designed for this use case<\/td><\/tr><tr><td>Claude<\/td><td>Yes, since September 2025<\/td><td>Yes, in Privacy settings<\/td><td>Nothing, but requires active action<\/td><\/tr><tr><td>Meta AI<\/td><td>Yes, largely<\/td><td>EU and Brazil only<\/td><td>Formal objection process required<\/td><\/tr><tr><td>Grok<\/td><td>Yes, all public posts<\/td><td>Yes, incomplete protection<\/td><td>Past data already trained on, cannot be pulled back<\/td><\/tr><tr><td>Perplexity<\/td><td>Yes, Free\/Pro\/Max<\/td><td>Yes, AI data retention toggle<\/td><td>Nothing, setting persists<\/td><\/tr><tr><td>Mistral<\/td><td>Yes, Experiment tier only<\/td><td>Yes<\/td><td>Upgrading to Pro removes the issue entirely<\/td><\/tr><tr><td>DeepSeek<\/td><td>Yes, and stored in China<\/td><td>Not meaningfully<\/td><td>Jurisdiction cannot be opted out of<\/td><\/tr><tr><td>Amazon Q Developer<\/td><td>Only the Free tier<\/td><td>Yes, disable telemetry<\/td><td>Nothing, Pro is private by default<\/td><\/tr><tr><td>Harvey<\/td><td>No free tier exists<\/td><td>Not applicable<\/td><td>Not applicable<\/td><\/tr><tr><td>CoCounsel<\/td><td>No free tier exists<\/td><td>Not applicable<\/td><td>Not applicable<\/td><\/tr><\/tbody><\/table><\/figure>\n\n\n\n<p class=\"wp-block-paragraph\">The pattern holds across nearly every row: <strong>the free version of an AI tool is, with rare exception, the version most likely to be training on whatever gets typed into it<\/strong>, and the two tools that avoid this table entirely, Harvey and CoCounsel, do so simply by never offering a free version in the first place.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_the_index_reveals_five_patterns_across_all_twelve_tools\"><\/span>What the index reveals: five patterns across all twelve tools<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Reading twelve privacy policies back to back surfaces patterns that reading any single one, in isolation, never would.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The free tier is where nearly every serious risk in this index concentrates.<\/strong> Nine of the twelve tools we reviewed train on conversations by default at their free or lowest paid tier. This matters disproportionately because free and personal tier access is exactly how AI tools actually spread inside organizations, through an employee signing up on their own initiative, not through a procurement process. A firm that has carefully vetted and licensed an Enterprise tier for its whole staff has solved only part of the problem if employees can still open a personal, unmanaged account on the same product in a separate browser tab, a gap our companion guide to cloud AI risk covers as <strong>shadow AI<\/strong>, and this index shows just how differently the same company&#8217;s own products can behave a single settings screen apart.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A large compliance certification list is a floor, not a ceiling.<\/strong> SOC 2, ISO 27001, and similar audits verify that a company follows its own stated controls. They do not verify that those controls guarantee your data never leaves a specific jurisdiction, as Microsoft Copilot&#8217;s Flex Routing situation shows clearly: a well certified, GDPR compliant product can still ship a new default that quietly moves data outside its own advertised boundary, discovered only because independent researchers and, in Germany&#8217;s case, a national regulator, went looking.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Purpose built professional tools outperformed general purpose giants across the board.<\/strong> CoCounsel and Harvey, the two tools built specifically for one narrow professional context with no consumer product to weaken the average, scored highest in this index by a meaningful margin over every general purpose competitor, including tools from companies with vastly larger security teams and longer public track records. The lesson generalizes past legal AI: a tool with no free tier, a single well defined customer base, and nothing to gain from harvesting consumer conversations for training has fewer structural reasons to compromise on data handling in the first place.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Geography is now a first order security variable, not a footnote.<\/strong> The gap between Mistral, deliberately built and marketed around EU jurisdiction from day one, and DeepSeek, whose Chinese jurisdiction is the single deciding factor in its last place score, shows that where a company is incorporated and where its servers physically sit now belongs in the same due diligence conversation as encryption standards and access controls, a shift that would have seemed like an unusual thing to weight this heavily even three years ago.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Policies change, sometimes for the worse, and reputations lag the change.<\/strong> Anthropic&#8217;s own consumer policy reversal in September 2025, and Mistral&#8217;s expanded US processing footprint, both show that a vendor&#8217;s earlier reputation for strict privacy defaults is not a permanent guarantee. The only reliable practice is checking the current, live policy for the specific tier your organization actually uses, on a recurring schedule, rather than trusting a reputation formed at the moment your organization first evaluated the tool.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_compliance_frameworks_behind_every_score_in_this_index\"><\/span>The compliance frameworks behind every score in this index<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/clickbaton.com\/blog\/wp-content\/uploads\/2026\/08\/certification_badges_board.svg\" alt=\"Four certification badges labeled SOC 2, ISO 27001, ISO 42001, and HIPAA BAA displayed on a review board, representing the audits behind the certification category of this index\" class=\"wp-image-210\" style=\"width:820px;height:auto\"\/><figcaption class=\"wp-element-caption\"><strong><em>Four certification badges labeled SOC 2, ISO 27001, ISO 42001, and HIPAA BAA displayed on a review board, representing the audits behind the certification category of this index<\/em><\/strong><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">The certifications and legal frameworks referenced throughout this index did not appear at random, and understanding where they came from helps explain why this index weights them the way it does.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>SOC 2<\/strong>, maintained by the American Institute of Certified Public Accountants, predates the generative AI boom by more than a decade, originally built to give cloud service customers a standardized way to evaluate a vendor&#8217;s security controls without needing to conduct their own audit of every vendor individually. Its relevance to AI specifically is inherited rather than purpose built: an AI company&#8217;s SOC 2 report covers the infrastructure and access controls surrounding its product, not the AI model&#8217;s behavior itself, which is precisely why this index treats it as one input among eight rather than a single deciding factor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ISO\/IEC 27001<\/strong>, first published in 2005 and periodically updated since, plays a similar role internationally, and is frequently the certification a European counterparty specifically asks for, given its status as the dominant global standard for information security management outside the United States.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ISO\/IEC 42001<\/strong>, published in December 2023, is the newest and most specific framework in this index, and its recency shows in how few of the twelve tools we reviewed hold it. Unlike the two standards above, it was built specifically to address AI governance: how an organization manages the lifecycle risk of developing, deploying, and monitoring AI systems, including questions general information security standards were never designed to answer, like how a company governs its own model training pipeline. This index treats a vendor&#8217;s ISO 42001 status as a meaningful signal of AI specific governance maturity precisely because the standard is young enough that holding it reflects a deliberate, relatively recent investment rather than a certification a company has simply carried forward for years.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The General Data Protection Regulation<\/strong>, the EU&#8217;s 2018 privacy law, sits behind nearly every Data Processing Addendum referenced in this index, and its Article 28 specifically requires that any processor handling personal data on a controller&#8217;s behalf do so under a binding contract covering the subject matter, duration, and nature of that processing, which is the legal basis for the DPA category this index scores separately from a vendor&#8217;s general privacy policy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The 2017 National Intelligence Law<\/strong>, the piece of Chinese legislation at the center of DeepSeek&#8217;s last place score in this index, has no real Western regulatory equivalent, which is exactly why it functions differently from every other framework named here. It does not set standards a company can choose to meet or exceed. It is a background legal obligation that exists independent of any company&#8217;s own policy, which is the structural reason this index treats DeepSeek&#8217;s low score as a jurisdictional fact rather than a fixable policy gap.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_cost_of_getting_this_wrong_a_roundup_of_enforcement_already_underway\"><\/span>The cost of getting this wrong: a roundup of enforcement already underway<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Skeptics of any privacy index sometimes assume the risk being described is theoretical. The regulatory record behind the twelve tools in this index says otherwise. Enforcement is not a future possibility here. It is already a documented pattern, tool by tool.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>OpenAI<\/strong> paid the first ever GDPR fine issued against a generative AI company, <strong>15 million euros from Italy&#8217;s Garante in December 2024<\/strong>, for an inadequate legal basis for training on personal data and a failure to properly report an earlier breach, according to reporting covered in depth in our companion guide to cloud AI risk. OpenAI also remains bound by a US federal court order that, at its broadest point, required indefinite preservation of ChatGPT conversations users had actively deleted, as part of unrelated copyright litigation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>xAI and X<\/strong> are currently the subject of confirmed formal action from regulators in at least eight jurisdictions, spanning the European Commission, the UK, Ireland, Canada, Brazil, France, and Spain, following an Irish High Court order that required X to permanently stop using certain EU user data for Grok training after processing it without an adequate legal basis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Meta<\/strong> faces an active cease and desist demand from the privacy organization NOYB over its plan to train AI on European users&#8217; public posts, alongside complaints filed with the Irish Data Protection Commission specifically challenging whether Meta AI conversational data feeding into advertising personalization satisfies GDPR&#8217;s purpose limitation principle.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>DeepSeek<\/strong> was blocked outright by Italy&#8217;s Garante in January 2025, with data protection authorities in France, Ireland, Germany, Belgium, and Portugal opening their own separate investigations into the hosted service, and multiple governments have restricted or banned its use on official devices entirely, citing the jurisdictional risk this index details.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Microsoft<\/strong> faced formal criticism from Germany&#8217;s DSK, a conference of the country&#8217;s data protection supervisory authorities, over standard Copilot data processing terms, and the Flex Routing default change documented in this index required a formal compliance review window for EU and EFTA customers before the new default took effect.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mistral<\/strong> faces an unresolved complaint filed with France&#8217;s CNIL over whether its free tier opt out process meets GDPR&#8217;s accessibility requirements, though Mistral has since added an easier opt out path for free users following the complaint.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Six of the twelve tools in this index have a documented, named regulatory action, investigation, or formal complaint tied specifically to how they handle user data<\/strong>, not a hypothetical future risk, but an active or recently resolved matter as of this research. The remaining six, notably including both purpose built legal AI platforms, show no such documented action in our research, a pattern that lines up closely, though not perfectly, with the overall scoring in this index: the tools built narrowly around one professional context, with the least incentive to harvest broad consumer data, are also the tools least likely to have drawn a regulator&#8217;s attention in the first place.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_it_costs_to_access_the_tier_that_actually_protects_you\"><\/span>What it costs to access the tier that actually protects you<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Nearly every finding in this index traces back to a tier boundary, free versus paid, individual versus enterprise, and that boundary usually has a real price attached to it, worth stating plainly since cost is often the deciding factor for a smaller firm or team choosing between the protection this index describes and the convenience of staying on a free account.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Among the general purpose tools in this index, the pattern is remarkably consistent: <strong>the tier that excludes training by default typically starts in the range of 20 to 30 dollars per user each month<\/strong>, roughly the pricing band occupied by ChatGPT Team, Claude Team, and Gemini for Workspace&#8217;s entry business tier, with Perplexity&#8217;s Enterprise Pro and Microsoft 365 Copilot&#8217;s commercial add on licenses landing in a similar range once bundled with an existing productivity subscription. Mistral is the clear outlier on affordability, with Le Chat Pro&#8217;s training exclusion available at roughly 15 dollars monthly, the lowest price point in this index for a tier that excludes training by default, a genuine advantage for a solo practitioner or very small team watching costs closely.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The two highest scoring tools in this index, Harvey and CoCounsel, do not publish self serve pricing at all, reflecting their enterprise only sales model, and firms evaluating either should expect a custom contract negotiation rather than a credit card checkout, typically appropriate for firms with the budget and caseload to justify a dedicated legal AI platform rather than a general purpose tool&#8217;s business tier. Amazon Q&#8217;s pricing follows AWS&#8217;s consumption based model rather than a flat per seat fee, which can make it either meaningfully cheaper or more expensive than a flat rate competitor depending on actual usage volume, worth modeling against your team&#8217;s specific expected use before committing.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The honest budget conclusion this index points toward is that meaningful data protection, for nearly every tool covered here, is available somewhere between 15 and 30 dollars per user monthly<\/strong>, a real but usually manageable cost increase over a free account, and one considerably smaller than the cost of the incidents documented throughout this guide when that gap goes unaddressed. A local deployment inverts this cost structure entirely, trading a recurring per seat subscription for an upfront hardware and setup investment, a tradeoff worth modeling specifically against your team&#8217;s size and expected usage volume rather than assumed in either direction.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_this_means_if_you_run_a_law_firm\"><\/span>What this means if you run a law firm<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every finding in this index sharpens considerably once client confidentiality and Rule 1.6, covered in depth in our companion guide to cloud AI risk, enters the picture. A handful of implications are specific enough to this index&#8217;s findings that they deserve direct treatment here.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The two highest scoring tools in this index happen to be the two built specifically for legal work, and that is not a coincidence a firm should ignore.<\/strong> If your firm is currently running client matters through a general purpose consumer AI account, even a paid one, this index gives you a concrete, sourced comparison to bring to a partner meeting: CoCounsel and Harvey are not simply marketed at lawyers, they structurally avoid the single biggest privacy weakness present in nine of the other ten tools in this index.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A tool&#8217;s overall enterprise reputation does not tell you what your specific attorneys are actually using day to day.<\/strong> Several tools in this index, Claude, ChatGPT, and Gemini among them, offer both a strong Enterprise tier and a meaningfully weaker consumer tier under the identical brand name. A firm that licensed ChatGPT Enterprise firm wide has done real, meaningful work, but that work is undone the moment an associate, working late and without firm issued credentials handy, opens a personal ChatGPT account in a browser tab to save time. The fix is not a memo. It is confirming, technically, which version of a tool your network actually allows, a control most of the checklist items later in this guide are built to verify directly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Jurisdiction now belongs in a conflicts check, not just a security review.<\/strong> A firm handling cross border matters, particularly anything touching national security sensitive, export controlled, or government client material, should treat DeepSeek&#8217;s finding in this index as a template for the kind of question worth asking about every AI vendor: not just what does the privacy policy promise, but what law governs the country where the servers physically sit, and what would that country&#8217;s government be legally entitled to demand.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"What_this_means_if_you_run_a_finance_or_operations_team\"><\/span>What this means if you run a finance or operations team<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The same patterns land differently, but no less seriously, for a business team handling financial data, vendor contracts, and competitive strategy rather than privileged legal communications.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>The training default finding in this index should specifically worry any team that pastes financial figures into a free or personal AI account.<\/strong> Nine of twelve tools reviewed here train on free tier conversations by default, and unreleased earnings figures, vendor pricing, or merger related financial modeling typed into any of those nine tools on an unmanaged account is, structurally, no different from the client confidentiality exposure a law firm faces, just without a bar association enforcing the consequence. Our companion guide to cloud AI risk documents survey research finding that a meaningful share of employees have specifically pasted financial or sales figures into personal AI accounts their employer never approved.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Amazon Q&#8217;s identity aware retrieval model is worth specific attention if your team already runs on AWS.<\/strong> Unlike a flat, shared context window, Q Business restricts what any given employee can retrieve from an indexed knowledge base to only the documents that employee already has permission to see under your existing access controls. For a finance team wary of an AI tool accidentally surfacing payroll data to someone outside HR, or a specific client&#8217;s financials to someone outside that account team, this architecture is a meaningfully different risk shape than a general purpose chatbot with a single shared retrieval pool, and it is worth asking any AI vendor your team evaluates whether they offer an equivalent.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mistral&#8217;s self hosting option deserves serious consideration for any team handling data that cannot leave a specific jurisdiction or network under any circumstances<\/strong>, mergers and acquisitions due diligence, unreleased financial statements ahead of a public filing, or trade secret protected pricing models among them. Being able to run a genuinely capable model entirely inside infrastructure your own team controls, with zero external data flow to audit or trust, is a fundamentally different guarantee than the strongest contractual promise any cloud vendor in this index can offer, a point the next section develops directly.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_this_indexs_findings_interact_with_the_shift_toward_AI_agents\"><\/span>How this index&#8217;s findings interact with the shift toward AI agents<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This index has focused on a specific question: what happens to your data inside a single AI conversation. A parallel shift, covered in depth in our companion guide to AI agent risk, is changing that question&#8217;s shape for several of the tools covered here, and is worth flagging directly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Google&#8217;s Gemini Spark, referenced earlier in this index&#8217;s Gemini profile, moved in 2026 from a tool that surfaces data to one that can <strong>execute tasks autonomously across Workspace and, by summer 2026, third party tools through the Model Context Protocol<\/strong>, according to the same Concentric research cited above. Microsoft 365 Copilot has similarly expanded into autonomous agent capabilities layered on top of the core assistant this index evaluated. Amazon Q Business&#8217;s identity aware retrieval architecture, one of this index&#8217;s most favorably noted features, was originally built for question answering, and AWS has been extending Q toward more autonomous, task completing behavior as well.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The practical implication for this index&#8217;s findings is that a training default and a retention window, the two heaviest weighted categories in our methodology, describe what happens to a conversation. They do not fully describe what happens when that same tool is granted the ability to read your calendar, send an email, or modify a file on its own initiative, a meaningfully different risk category our companion guide to AI agent risk covers in full, including the aggregation of access, prompt injection, and human trust exploitation risks that apply specifically to autonomous tool use rather than conversational data handling. <strong>A tool that scores well in this index for how it handles a conversation is not automatically equally safe once that same tool&#8217;s agentic features are switched on<\/strong>, and any organization enabling an agentic feature inside a tool covered here should treat that as a separate evaluation, using the companion guide&#8217;s own checklist, rather than assuming this index&#8217;s conversational data score covers it.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_a_local_deployment_sits_outside_this_entire_scoring_exercise\"><\/span>Why a local deployment sits outside this entire scoring exercise<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">It would be easy, and dishonest, to simply declare that running an AI model locally scores 100 out of 100 on this index and call it a day. That is not quite right, and the honest version of the argument is more interesting than the inflated one.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/clickbaton.com\/blog\/wp-content\/uploads\/2026\/08\/local_ai_outside_the_board.svg\" alt=\"A small local device icon sits deliberately off to the side of the twelve tool leaderboard, connected to none of the scoring categories, with a caption noting several categories do not apply\" class=\"wp-image-211\" style=\"width:820px;height:auto\"\/><figcaption class=\"wp-element-caption\"><strong><em>A small local device icon sits deliberately off to the side of the twelve tool leaderboard, connected to none of the scoring categories, with a caption noting several categories do not apply<\/em><\/strong><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong>Several of this index&#8217;s eight categories simply stop applying when a model runs entirely on hardware your own organization owns, with no connection back to an outside vendor.<\/strong> There is no default training posture to score, because there is no vendor collecting your conversations to train anything. There is no zero data retention question to negotiate, because there is no third party retaining your data in the first place, at any price, under any contract tier. There is no subprocessor list to request, because there are no subprocessors, no fourth parties, no chain of companies your data might pass through on its way to an answer. Data residency stops being a contractual promise you have to trust and becomes a physical fact you can verify yourself, by looking at which building the server sits in.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Two categories genuinely do not resolve in a local deployment&#8217;s favor automatically, and a fair index has to say so.<\/strong> Compliance certifications like SOC 2 and ISO 27001 are audits of a vendor&#8217;s controls. A self hosted, locally run deployment does not have a vendor to audit in that sense, which means the certification question shifts entirely onto your own organization&#8217;s internal controls, and a small firm or business team taking on local AI needs to actually build and document those controls rather than inheriting them from a vendor&#8217;s existing audit. Similarly, a local deployment&#8217;s regulatory and incident track record is, by definition, your own organization&#8217;s track record, not a vendor&#8217;s, which cuts both ways: no history of someone else&#8217;s breach to inherit, but also no vendor security team, no vendor incident response process, and no vendor&#8217;s dedicated compliance staff standing behind you if something does go wrong.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What a local deployment does provide, unambiguously and by construction rather than by policy promise, is the elimination of every risk in this index that depends on trusting a company you have no contract leverage over.<\/strong> Every score in this index, even CoCounsel&#8217;s 90 and Harvey&#8217;s 88, ultimately rests on trusting that a vendor&#8217;s stated policy accurately describes what actually happens to your data, backed by a contract you would have to sue to enforce if it turned out not to be true. A local deployment replaces that trust relationship with a physical fact: the data did not leave the room, because there was never a network path for it to leave through. For the categories of material this index&#8217;s audience handles most often, privileged client communications, unreleased financial data, competitively sensitive strategy, that is a fundamentally different, and for many firms and business teams, a more defensible position than even the highest scoring cloud tool in this table can offer, provided the organization is willing to take on the operational responsibility that comes with it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">That tradeoff, real control in exchange for real operational responsibility, is precisely the calculation a growing number of legal and business teams are making as locally deployable AI tools mature. If your organization handles the kind of material scored throughout this index and has not yet evaluated what a properly contained, locally run AI deployment would look like for your highest sensitivity workflows, this index gives you the specific, sourced comparison to justify starting that evaluation now rather than waiting for the next policy change covered in some future version of this piece to force the question.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"A_practical_checklist_matching_your_use_case_to_the_right_tier\"><\/span>A practical checklist: matching your use case to the right tier<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">The right answer to which AI tool your organization should use is rarely a single tool for every task. It is matching the sensitivity of what you are working on to the tier of protection that material actually needs, which this index&#8217;s findings can help make concrete.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>For public facing content, general research, or brainstorming with nothing confidential involved<\/strong>, most tools in this index, including free tiers, present limited practical risk, because the material was never sensitive in the first place. This is the one category where a training by default free tier is a genuinely reasonable tradeoff for cost or convenience, provided your team actually understands that is what they are agreeing to, and provided nobody quietly starts using the same free tab for something more sensitive six months later without anyone revisiting the original decision.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>For internal but not highly sensitive business information<\/strong>, this index points toward at minimum a paid tier with training disabled by default, which as the free tier table above shows, still requires actively checking which specific tier your team is using rather than assuming the paid badge alone settles the question. A surprising number of organizations discover, once they actually check, that half their team is on the protected tier and the other half never finished the upgrade, a gap this index&#8217;s free tier comparison table is specifically designed to help you find before it becomes a genuine incident rather than a paperwork problem.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>For anything touching privileged legal communication, protected health information, or unreleased financial data ahead of a public filing<\/strong>, this index&#8217;s findings point clearly toward either a purpose built professional tool like the two legal AI platforms scored here, an enterprise tier with a signed Zero Data Retention agreement, or a properly contained local deployment, not because the middle tier options are unsafe in a general sense, but because the stakes of a low probability failure are simply too asymmetric to accept a default consumer configuration for this category of material.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>For data that legally, contractually, or competitively cannot leave a specific jurisdiction or network under any circumstances<\/strong>, mergers and acquisitions due diligence, government classified adjacent work, or trade secret protected formulas among them, this index&#8217;s findings point toward the local deployment discussion above as the only option that removes the underlying question entirely, rather than managing it through a contract with a company you would have to sue to enforce.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Mapping every task your team actually does with AI against these four tiers, honestly and specifically, is a more useful exercise than picking a single tool and hoping it covers every use case adequately. Few organizations in this index&#8217;s audience actually need to abandon their existing tools entirely. Most need a clearer, written map of which tool is approved for which category of work, backed by the specific, sourced findings in this index rather than a general sense that the enterprise version is probably fine.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_each_tool_sits_on_a_simple_decision_tree\"><\/span>Where each tool sits on a simple decision tree<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/clickbaton.com\/blog\/wp-content\/uploads\/2026\/08\/decision_tree_flowchart.svg\" alt=\"A flowchart walks through four yes or no questions about sensitivity and jurisdiction, ending in a recommended tier ranging from any tier being reasonable to a fully local deployment\" class=\"wp-image-212\" style=\"aspect-ratio:1.764828303850156;width:820px;height:auto\"\/><figcaption class=\"wp-element-caption\"><strong><em>A flowchart walks through four yes or no questions about sensitivity and jurisdiction, ending in a recommended tier ranging from any tier being reasonable to a fully local deployment<\/em><\/strong><\/figcaption><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\">If the full index feels like more than you need in the moment, this condensed decision path captures most of the practical guidance above.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Are you working with genuinely public, non sensitive material?<\/strong> If yes, most tools in this index, used at any tier, present limited practical risk, and cost or convenience are reasonable deciding factors.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Are you working with internal but not highly sensitive business material?<\/strong> If yes, this index points toward any tool&#8217;s paid tier with training confirmed disabled, checked against the specific tier table earlier in this guide rather than assumed from the product&#8217;s general reputation.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Are you working with privileged legal communication, protected health information, or market sensitive financial data?<\/strong> If yes, this index&#8217;s findings point toward a purpose built professional tool, an enterprise tier with a signed Zero Data Retention agreement in hand, or a properly contained local deployment, not a standard paid consumer tier regardless of how well that tier otherwise scored in this index.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Does the material carry a jurisdictional restriction, a client requirement, or a regulatory obligation that data never leave a specific network or country?<\/strong> If yes, this index&#8217;s findings point toward Mistral&#8217;s self hosting option, a local deployment built specifically around your infrastructure, or, at minimum, a vendor offering fully verified, contractually locked data residency in the specific jurisdiction your restriction requires, evaluated using the vendor questions listed earlier in this guide.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Is the tool in question DeepSeek&#8217;s hosted service?<\/strong> If yes, and the material is anything beyond genuinely public and non sensitive, this index&#8217;s finding is that the jurisdictional risk applies regardless of which other question above you answered, because it is not a risk any tier or contract can configure away.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Applying_this_index_three_worked_examples\"><\/span>Applying this index: three worked examples<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Abstract findings are easier to use once they are applied to a specific, realistic situation. Here are three, drawn from the kind of teams this index is written for.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A six attorney family law practice currently using ChatGPT Plus on individual partner credit cards.<\/strong> Working through this index&#8217;s findings, the first issue is immediate: ChatGPT Plus trains on conversations by default, and partners have likely been drafting settlement language and summarizing client intake using personal accounts entirely outside any firm oversight. The index points toward two reasonable paths. The lower cost path upgrades the firm to ChatGPT Team, which excludes training by default and centralizes billing and admin oversight, paired with a firm policy restricting what categories of client material are appropriate even at that tier. The stronger path, given this index&#8217;s finding that purpose built legal tools scored highest overall, evaluates Harvey or CoCounsel directly, weighing the higher cost against the meaningfully stronger structural privacy position documented in this index, a calculation that becomes easier to justify as the firm&#8217;s caseload involves more genuinely sensitive matters.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A forty person manufacturing company finance team using a mix of tools employees picked individually.<\/strong> This index&#8217;s free tier comparison table is the most useful starting point here, since the realistic first step is not choosing a single new tool but auditing which of the twelve tools, and which specific tier of each, employees are actually using today. A team that discovers a mix of personal Gemini, free Perplexity, and occasional Grok use through personal X accounts has, according to this index&#8217;s scoring, effectively no consistent data protection at all across its own financial and vendor data. The practical fix this index points toward is consolidating onto a single enterprise tier, Amazon Q if the company already runs on AWS given its identity aware retrieval advantage documented above, or Mistral if EU jurisdiction and a genuine self hosting path matter for the company&#8217;s specific vendor contracts, paired with blocking or restricting the lowest scoring consumer tools on managed devices.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A regional bank&#8217;s legal and compliance department handling merger related due diligence.<\/strong> This is the clearest case in this index for the local deployment discussion above. The material involved, unreleased financial figures, competitively sensitive negotiation strategy, and privileged legal analysis, sits at the intersection of every highest stakes category this index covers. Even Harvey or CoCounsel&#8217;s strong 88 and 90 scores still rest on trusting a vendor&#8217;s contractual promise. For this specific, time bounded, unusually high stakes category of work, this index&#8217;s findings point toward evaluating a properly contained local deployment specifically for the due diligence workflow, while continuing to use a cloud tool from higher in this index&#8217;s ranking for the department&#8217;s ordinary, lower stakes daily work.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Questions_to_ask_any_AI_vendor_not_covered_in_this_index\"><\/span>Questions to ask any AI vendor not covered in this index<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">New AI tools launch constantly, and this index cannot cover all of them. The eight category methodology above is designed to be reusable, and here is the condensed version, as a set of direct questions worth putting to any vendor your organization is evaluating.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Does your standard paid tier, not just your top enterprise tier, exclude our data from training by default, and can you point to the specific clause in your terms that says so.<\/strong> A verbal assurance from a sales representative is not a substitute for contract language, and this index found real, material gaps between what several companies&#8217; marketing implies and what their actual policy, tier by tier, states.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Can we get a Zero Data Retention agreement, and if not, what is your maximum retention window for a standard account.<\/strong> Remember that training and retention are separate promises. A vendor can honestly answer no to the first question in this list while still storing your data for weeks or months.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Where, specifically, is our data processed and stored, and does that answer change under any circumstances, such as high demand or a specific feature we might enable.<\/strong> Microsoft Copilot&#8217;s Flex Routing situation, documented in this index, is the clearest cautionary example of why the second half of this question matters as much as the first.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What compliance certifications do you hold, and can you provide the actual audit report, not just a badge on your marketing site.<\/strong> Ask specifically whether any SOC 2 report is Type I or Type II, and request the current ISO certificate number so it can be independently verified against the certifying body&#8217;s public registry.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Who can access our data internally, under what circumstances, and is that access logged and auditable by us.<\/strong> A vendor that cannot answer this specifically, or that answers only in terms of general policy rather than a concrete access control mechanism, has likely not built one worth trusting.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What is your complete, current subprocessor list, and will you notify us before adding a new one.<\/strong> This index found at least one major vendor, Microsoft, that added a significant new AI subprocessor without the kind of proactive customer notification a security conscious organization should expect.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Has your company faced a regulatory action, a fine, or a significant publicly documented security incident related to how you handle user data, and what changed afterward.<\/strong> Every vendor of any size will eventually face some version of this question honestly. What separates the tools that scored well in this index from the ones that scored poorly is not the absence of any past issue, but a track record of resolving it with a real structural fix rather than a statement.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>If we self host or run your model on our own infrastructure, is that a real, documented option, and what does it cost relative to your hosted service.<\/strong> As this index&#8217;s discussion of local deployment covers, the strongest possible answer to nearly every question above is removing the vendor from the data path entirely, and it is worth knowing whether a given vendor even offers that path before assuming it does not.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Common_mistakes_when_reading_an_AI_privacy_policy\"><\/span>Common mistakes when reading an AI privacy policy<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Building this index meant reading roughly forty separate privacy policies, trust center pages, and compliance documents in close succession. A few mistakes showed up often enough, across companies that otherwise have little in common, that they are worth naming directly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Confusing &#8220;we do not train on your data&#8221; with &#8220;we do not store your data.&#8221;<\/strong> These are two entirely separate promises, and this index found several vendors, OpenAI and Perplexity among them, that make the first commitment clearly on a given tier while still retaining data for a standard window, often 30 days, for abuse monitoring. Neither promise implies the other. Always check both separately.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Assuming the enterprise tier&#8217;s promises automatically apply to every product under the same brand.<\/strong> Microsoft 365 Copilot&#8217;s strong commercial commitments do not extend to the free consumer Copilot product at copilot.microsoft.com, and Google&#8217;s enterprise Gemini for Workspace commitments do not extend to the consumer Gemini app, even though both pairs share a name, a logo, and in some cases a login screen. This index treats these as the functionally different products they are, because a policy reader who does not will draw the wrong conclusion about whichever version their employees actually end up using.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Treating &#8220;opt out available&#8221; as equivalent to &#8220;not collected.&#8221;<\/strong> An opt out toggle, as this index&#8217;s free tier table shows repeatedly, typically affects only future data going forward. Every vendor we reviewed that offers an opt out was explicit, when asked directly, that data already used in a completed training run cannot be retroactively removed. The safest assumption for any conversation that predates an opt out decision is that it may already be baked into a model somewhere.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Reading a certification badge as proof of a specific promise it does not actually make.<\/strong> A SOC 2 certification proves an organization follows its own documented controls consistently. It does not, by itself, prove those controls include not training on your data, or that your specific data resides in a specific country. Read the actual privacy policy and DPA for the specific commitment you need, and treat certification badges as supporting evidence for that commitment, not a replacement for checking it directly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Missing that a vendor&#8217;s own default can change without the customer&#8217;s active consent.<\/strong> This index documents at least two clear examples, Anthropic&#8217;s September 2025 consumer policy shift and Microsoft&#8217;s 2026 Flex Routing default, of a vendor changing what happens to existing users&#8217; data through a default setting change rather than requiring active reconfirmation. The practical lesson is to review your organization&#8217;s actual current settings on a recurring schedule, not just at the moment you first signed up.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Sample_language_for_your_own_vendor_evaluation\"><\/span>Sample language for your own vendor evaluation<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">For readers who want to move directly from this index&#8217;s findings to an actual conversation with a vendor or an internal policy draft, here is a starting template, built directly from the eight category methodology above, adaptable to whichever tool you are evaluating.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>For a vendor security questionnaire or request for proposal:<\/strong> &#8220;Vendor shall confirm in writing whether Customer Data, including all prompts, uploaded files, and generated outputs, is used to train or fine tune any model, on both the proposed commercial tier and any lower tiers Customer personnel may independently access. Vendor shall provide its current SOC 2 report, specifying Type I or Type II, its ISO 27001 and, if held, ISO 42001 certificates, and its current subprocessor list, updated no less frequently than quarterly. Vendor shall specify the maximum data retention period for Customer Data absent a Zero Data Retention agreement, and the specific country or countries in which Customer Data is processed and stored under standard operating conditions and under conditions of elevated system load.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>For an internal AI use policy, addressed to employees:<\/strong> &#8220;Employees may use [approved tool and tier] for work involving [approved data categories], and may not use personal or unmanaged accounts on any AI tool, regardless of vendor, for any material relating to a client matter, unreleased financial information, or any data covered by a signed confidentiality agreement. Where a task requires a tool not on the approved list, employees must request review before use rather than proceeding on their own judgment. Questions about whether a specific task or data category is covered should be directed to [named policy owner].&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>For a client facing engagement letter or data handling disclosure:<\/strong> &#8220;We may use artificial intelligence tools in the course of providing services to you. Where such tools are used, we take reasonable steps to ensure that tools processing your confidential information operate under contractual terms excluding your data from vendor model training, and we are available to discuss our specific AI tool policies and vendor selections upon request.&#8221;<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">These templates are starting points, not finished legal language, and should be reviewed by your own counsel before use, consistent with the limitations noted earlier in this index. They are built specifically to translate this index&#8217;s eight scoring categories into the kind of concrete, checkable commitment a vendor, an employee, or a client can actually act on, rather than a general aspiration to use AI responsibly that nobody can verify later.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"A_glossary_of_the_compliance_terms_in_this_index\"><\/span>A glossary of the compliance terms in this index<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>SOC 2.<\/strong> A voluntary auditing framework, maintained by the American Institute of Certified Public Accountants, that evaluates a company&#8217;s controls around security, availability, processing integrity, confidentiality, and privacy. A <strong>Type I<\/strong> report confirms controls existed and were suitably designed on a single date. A <strong>Type II<\/strong> report, considerably more rigorous, confirms those controls actually operated effectively over a period of months, typically six to twelve. This index weights Type II attestations more heavily for exactly that reason.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ISO\/IEC 27001.<\/strong> An international standard for information security management systems, covering how an organization identifies, manages, and reduces information security risk across its people, processes, and technology, independently audited and certified on a recurring basis.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>ISO\/IEC 42001.<\/strong> A newer international standard, published in December 2023, specifically for artificial intelligence management systems, the first of its kind. It covers how an organization governs the development, deployment, and ongoing risk management of AI systems specifically, distinct from general information security.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>HIPAA Business Associate Agreement, or BAA.<\/strong> A legally required contract under the US Health Insurance Portability and Accountability Act between a covered healthcare entity and any vendor that handles protected health information on its behalf, specifying how that vendor will safeguard the data. A vendor&#8217;s willingness to sign a BAA, and which specific features are covered under it, is a direct signal of how seriously it treats regulated health data.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Data Processing Addendum, or DPA.<\/strong> A binding legal contract, distinct from a general privacy policy, specifying exactly how a vendor is permitted to process personal data on a customer&#8217;s behalf, typically required under GDPR and similar frameworks whenever personal data is involved in the relationship.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Zero Data Retention, or ZDR.<\/strong> A specific contractual arrangement, usually available only on business, API, or enterprise tiers, where a vendor commits to never storing a customer&#8217;s prompts or outputs at all, as distinct from merely excluding them from training while still keeping a temporary stored copy.<\/p>\n\n\n<div class=\"wp-block-image\">\n<figure class=\"aligncenter size-full is-resized\"><img decoding=\"async\" src=\"https:\/\/clickbaton.com\/blog\/wp-content\/uploads\/2026\/08\/zero_retention_steps.svg\" alt=\"A four step diagram shows a prompt sent, processed in memory only, a response returned, and nothing written to disk, with a faded crossed out server icon representing the absence of a fifth step\" class=\"wp-image-213\" style=\"width:820px;height:auto\"\/><\/figure>\n<\/div>\n\n\n<p class=\"wp-block-paragraph\"><strong><em>Data residency. A contractual or technical commitment specifying which country or region physically processes and stores an organization&#8217;s data, relevant both to regulatory compliance and to which government&#8217;s laws could compel access to that data.<\/em><\/strong><\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Subprocessor.<\/strong> A third party a primary vendor relies on to help deliver its service, such as a cloud hosting provider, a customer support platform, or in Microsoft Copilot&#8217;s case, another AI company entirely, which may also gain access to or store a copy of customer data as part of that relationship.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>EU Data Boundary.<\/strong> Microsoft&#8217;s specific commitment that data belonging to EU and EFTA customers using its commercial cloud services will be stored and processed within the EU, distinct from the broader, less formal concept of general data residency used elsewhere in this glossary.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_some_well_known_AI_tools_are_not_in_this_index\"><\/span>Why some well known AI tools are not in this index<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No comparison covering twelve tools can cover every AI product on the market, and readers who work with a tool not covered here deserve a direct explanation of the scope decision, not silence.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>General purpose consumer assistants built into an existing non AI product<\/strong>, such as Notion AI or Salesforce&#8217;s Agentforce and Einstein products, were excluded from this specific index because their data handling is typically inherited from, and difficult to meaningfully separate from, the host platform&#8217;s own broader data policies, a genuinely different evaluation than the twelve standalone or clearly delineated AI products covered here. A future companion piece focused specifically on embedded AI features inside existing business software is a natural extension of this index&#8217;s methodology.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Smaller or more specialized foundation model providers<\/strong>, including Cohere and a number of newer entrants, were set aside primarily due to more limited independent research and regulatory history available to verify against at the time of this research, not because of any specific concern. The methodology and vendor question list earlier in this guide are built specifically so a reader can apply the same framework to any of these tools directly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Consumer companion or entertainment focused AI products<\/strong>, such as Character.AI and similar platforms, fall outside this index&#8217;s scope because their primary use case and risk profile, centered on personal and often minors&#8217; use, differs enough from the professional legal and business context this index is written for that combining them into the same scoring framework would have produced a misleading comparison in both directions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Apple Intelligence<\/strong> was considered but ultimately set aside for this research window because its enterprise and business specific data handling documentation, distinct from its consumer facing on device processing commitments, was less mature and less independently verified at the time of this research than the twelve tools included here. It is a strong candidate for inclusion in a future update to this index as its enterprise specific offering matures.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">If a tool you use daily is not covered here, the eight category methodology, the vendor question list, and the common mistakes section earlier in this guide are written specifically to be applied directly to that tool, without needing to wait for a future version of this index to formally score it for you.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Limitations_of_this_index_and_how_to_use_it_responsibly\"><\/span>Limitations of this index, and how to use it responsibly<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">No comparison of twelve companies&#8217; legal documents, however carefully sourced, should be read as a substitute for your own review, and we want to be direct about exactly where this index&#8217;s limits sit.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Policies change, and this index is a snapshot, not a live feed.<\/strong> Every fact here was verified against a specific source as of the research window noted in the methodology section. Anthropic&#8217;s own consumer policy reversal, documented in this same index, is proof that a vendor&#8217;s data handling commitments can change materially within months. Before making a decision that depends on any specific claim in this piece, confirm it against the vendor&#8217;s current, live documentation, linked throughout.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>A published policy is a contractual promise, not a technical guarantee.<\/strong> We scored what each vendor states it does, cross referenced against independent research and regulatory findings where available. None of us can independently verify, from outside a company&#8217;s own infrastructure, that every engineer with system access follows the policy perfectly in every instance. Contract terms create legal recourse if violated. They do not create technical impossibility of violation, a distinction our companion guide to cloud AI risk covers in more depth.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>This index compares default, standard commercial configurations, not your specific negotiated contract.<\/strong> A large enterprise customer with significant purchasing power can often negotiate terms stronger than what any vendor publishes publicly, a custom retention window, a bespoke data processing addendum, dedicated infrastructure. If your organization has negotiated terms different from what is described here, your contract controls, not this index.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>We are not lawyers, and nothing here constitutes legal advice.<\/strong> Whether a specific tool, at a specific tier, satisfies your specific jurisdiction&#8217;s regulatory requirements or your profession&#8217;s specific ethical obligations is a question for your own counsel, informed by the sourced facts in this index rather than replaced by them.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>We welcome corrections.<\/strong> If a vendor covered here has updated its policy since this research was conducted, or if you believe a specific claim is inaccurate or has since changed, the sourced link for every claim is provided specifically so it can be checked, and we will update this index as material changes come to our attention.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_this_research_was_conducted\"><\/span>How this research was conducted<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Transparency about method matters as much as transparency about findings, so here is the actual process behind this index, not just its conclusions.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Each of the twelve profiles above began with the vendor&#8217;s own primary documentation: its published privacy policy, enterprise or trust center pages, and, where publicly available, its Data Processing Addendum. We treated vendor owned documentation as the primary source for factual claims about that vendor&#8217;s own stated policy, since a company&#8217;s own terms are the actual binding commitment a customer could point to. We then cross referenced each claim against independent research, security analysis, and, where relevant, regulatory filings or news coverage, specifically to catch cases where a vendor&#8217;s marketing language and its actual binding terms diverge, which this index found happening more than once.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">Where a vendor&#8217;s own documentation was ambiguous, outdated relative to more recent independent reporting, or contradicted by a regulatory finding, we noted the discrepancy directly in that tool&#8217;s profile rather than defaulting silently to the vendor&#8217;s preferred framing. Scores were assigned using the eight category methodology described earlier, applied consistently across all twelve tools using the same rubric, then reviewed a second time against the full set of sources before being finalized. We did not accept vendor input, sponsorship, or pre publication review from any of the twelve companies covered in this index in exchange for inclusion or a specific score.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>This index required no direct testing or accounts with any of the twelve products to produce<\/strong>, since it evaluates documented policy and independently verified track record rather than technical behavior we observed firsthand. That is a real limitation, noted plainly in the limitations section above, and one reason we encourage readers to treat this as a rigorously sourced starting point for their own vendor due diligence rather than a final, unappealable verdict.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Disclosure\"><\/span>Disclosure<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">In the interest of the same transparency this index asks of the twelve companies it evaluates, our own position deserves the same treatment. This index was published by a company building privacy focused, locally run AI software aimed at the same legal and business audience this piece is written for. We have a direct commercial interest in readers finding local AI deployment appealing, a bias worth naming plainly rather than leaving for a reader to guess at.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We have tried to manage that bias the same way we would ask any vendor in this index to manage its own conflicts: through sourcing rather than assertion. Every specific claim about every one of the twelve tools, including the two highest scoring tools, CoCounsel and Harvey, both of which are cloud hosted commercial products with no connection to us, links directly to an independently verifiable source. The scoring methodology is published in full, ahead of the individual scores, specifically so a skeptical reader can check whether a given score follows honestly from the stated method, rather than the method having been reverse engineered to fit a predetermined ranking. The local deployment section of this index deliberately does not assign local AI a numeric score on the same one hundred point scale the twelve vendor tools received, and explains directly why several of this index&#8217;s own categories, built around evaluating a third party vendor, do not cleanly apply to a deployment with no vendor in the data path at all. That is a more honest position than simply declaring a winner, and we would rather a reader trust this index&#8217;s twelve vendor profiles and disagree with our own conclusion in the final section, than trust neither.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Where_this_index_expects_the_biggest_changes_over_the_next_year\"><\/span>Where this index expects the biggest changes over the next year<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An index like this one is a snapshot, and it would be incomplete without naming, plainly, where we expect today&#8217;s snapshot to look meaningfully different within the next year, based on the trajectory each tool is already on.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Microsoft&#8217;s Flex Routing situation is likely to either resolve cleanly or escalate into a formal regulatory finding.<\/strong> Given the specific, dated compliance deadline German authorities already imposed in 2026, documented in this index, we expect either a clearer, more restrictive default from Microsoft or a more formal enforcement action within the next research cycle, and Copilot&#8217;s score is the single most likely to move in this index over the coming year.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Purpose built professional AI tools, the category currently topping this index, are likely to multiply.<\/strong> Harvey and CoCounsel&#8217;s structural advantage in this index, no consumer tier to weaken the average, is a replicable pattern, and we expect competitors built around other narrow, high stakes professional contexts, accounting, medicine, government contracting, to adopt a similar enterprise only structure specifically because it scores well against exactly this kind of scrutiny.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Jurisdictional scoring is likely to become more contested, not less, as more capable models emerge from more countries.<\/strong> DeepSeek will very likely not remain the only widely used AI product processing data under a legal framework that compels state cooperation with intelligence work, and this index&#8217;s jurisdictional weighting is a methodology built to be applied consistently to whichever new entrant tests it next, not a judgment specific to one country.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Consumer training defaults may tighten under regulatory pressure rather than loosen.<\/strong> The regulatory actions already documented against xAI, Meta, and OpenAI in this index, combined with the EU AI Act&#8217;s continuing rollout, point toward consumer training by default becoming a harder default for companies to defend publicly over time, even if, as Anthropic&#8217;s own reversal shows in this index, the trend is not guaranteed to move in a single direction for every company simultaneously.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Why_this_stops_being_optional_heading_into_2027\"><\/span>Why this stops being optional heading into 2027<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every finding in this index sits inside a broader trend that shows no sign of slowing, and it is worth stepping back from the twelve individual profiles to see the shape of it clearly.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">KPMG&#8217;s first quarterly Global AI Pulse survey, drawing on senior leaders across twenty countries, found that <strong>nearly three in four business leaders are now somewhat or greatly concerned about data security, privacy, and risk specifically, the single highest concern category among every factor the survey measured<\/strong>, ahead of cost, talent, and implementation complexity, according to <a href=\"https:\/\/kpmg.com\/xx\/en\/media\/press-releases\/2026\/03\/kpmg-global-ai-pulse-survey.html\">KPMG&#8217;s own release of the findings<\/a>. A separate, broader risk survey found that <strong>55 percent of businesses rank data protection and privacy violations among their top perceived threats from AI adoption<\/strong>, trailing only concerns about AI errors and hallucinations, according to <a href=\"https:\/\/www.ajg.com\/news-and-insights\/features\/ai-adoption-and-risk-benchmarking-2026\/\">the 2026 AI Adoption and Risk Survey<\/a>. These are not fringe concerns held by a cautious minority. They are now the majority, mainstream position among the business leaders actually making AI purchasing decisions, which is precisely the audience this index is written for.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">What makes this moment specifically 2026 rather than a permanent, unchanging state of affairs is the collision of three trends this index has documented directly. <strong>Adoption is accelerating faster than governance can keep pace with it<\/strong>, visible in K2view&#8217;s finding that 98 percent of organizations now use generative AI with enterprise data while only 13 percent have built the technical controls to manage what enters it. <strong>Enforcement is shifting from theoretical to active<\/strong>, visible in the six of twelve tools in this index already carrying a named regulatory action. And <strong>the tools built specifically to address this gap, from purpose built professional platforms to genuinely local deployments, are maturing at exactly the pace this demand requires<\/strong>, closing the practical gap between wanting better data protection and being able to actually afford and operate it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">None of this means the underlying technology is going away, and nothing in this index should be read as an argument against AI adoption broadly. It means the window for treating AI vendor selection as an afterthought, a quick signup rather than a deliberate decision matched to the sensitivity of what will flow through it, is closing. The organizations that come out of 2027 in the strongest position will very likely be the ones that treated this index&#8217;s underlying question, not which tool writes the best prose, but which tool can be trusted with what you are about to give it, as the first question rather than the last. Twelve tools were scored in this specific index. The question it asks applies to the thirteenth tool your organization evaluates next month, and the one after that, with or without a future update to this exact page to score it for you.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Key_numbers_from_this_index_in_one_place\"><\/span>Key numbers from this index, in one place<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<ul class=\"wp-block-list\">\n<li><strong>90 out of 100<\/strong>, the highest score in this index, earned by Thomson Reuters CoCounsel, followed by Harvey at 88.<\/li>\n\n\n\n<li><strong>12 out of 100<\/strong>, the lowest score in this index, earned by DeepSeek&#8217;s hosted service, primarily due to its jurisdiction in China.<\/li>\n\n\n\n<li><strong>9 of 12<\/strong> tools reviewed train on conversations by default at their free or lowest paid tier.<\/li>\n\n\n\n<li><strong>8 categories<\/strong>, weighted from 10 to 20 points each, make up this index&#8217;s full 100 point methodology.<\/li>\n\n\n\n<li><strong>6 of 12<\/strong> tools in this index carry a documented, named regulatory action, investigation, or formal complaint specifically tied to their data handling practices.<\/li>\n\n\n\n<li><strong>77 percent<\/strong>, the share of AI leaders who told KPMG&#8217;s Q4 2025 Pulse Survey that data privacy is now a significant concern for their AI strategy, up from 53 percent earlier the same year.<\/li>\n\n\n\n<li><strong>67 percent<\/strong>, the share of C suite executives who told Writer&#8217;s 2026 survey they believe their company has already suffered a data breach caused by an unapproved AI tool.<\/li>\n\n\n\n<li><strong>98 percent versus 13 percent<\/strong>, the gap K2view&#8217;s 2026 survey found between organizations using generative AI with enterprise data and organizations that have implemented technical controls to keep sensitive data out of that pipeline.<\/li>\n\n\n\n<li><strong>8 countries<\/strong>, the number of jurisdictions with confirmed formal regulatory action against X or xAI over Grok&#8217;s data practices as of this research.<\/li>\n\n\n\n<li><strong>15 million euros<\/strong>, the GDPR fine Italy&#8217;s Garante issued against OpenAI in December 2024, the first such penalty against a generative AI company.<\/li>\n\n\n\n<li><strong>1 of 12<\/strong>, the number of tools in this index, Mistral, whose entry paid consumer tier excludes user data from training by default.<\/li>\n\n\n\n<li><strong>2 of 12<\/strong>, the number of tools in this index, Harvey and CoCounsel, with no consumer or free tier at all.<\/li>\n\n\n\n<li><strong>15 to 30 dollars<\/strong>, the typical monthly per user price range across this index at which a general purpose tool&#8217;s training exclusion becomes available, with Mistral&#8217;s roughly 15 dollar Le Chat Pro tier the most affordable entry point to that protection.<\/li>\n\n\n\n<li><strong>3 international standards<\/strong>, SOC 2, ISO 27001, and the newer ISO 42001, form the backbone of the certification category in this index&#8217;s methodology, with ISO 42001 held by only a minority of the twelve tools reviewed.<\/li>\n<\/ul>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Frequently_asked_questions\"><\/span>Frequently asked questions<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Which AI tool is the most private overall?<\/strong><br>Among the twelve tools in this index, Thomson Reuters CoCounsel scored highest at 90 out of 100, followed closely by Harvey at 88, both benefiting structurally from having no consumer tier at all. Among general purpose tools available to any business, Amazon Q and Mistral scored highest.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Which AI tool should I avoid for sensitive data?<\/strong><br>Based on this index&#8217;s findings, DeepSeek&#8217;s hosted service carries the most serious structural risk due to its Chinese jurisdiction, and both Meta AI and xAI Grok carry meaningfully weaker consumer data protections than the rest of the field, with training enabled by default and limited or no meaningful opt out for most users.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Is ChatGPT safe to use for business?<\/strong><br>ChatGPT Team, Enterprise, and the API do not train on your data by default and carry solid SOC 2 Type 2 and ISO 27001 certification, according to this index&#8217;s research. The Free and Plus consumer tiers train by default unless a user actively opts out, and OpenAI has a documented GDPR fine and an ongoing court matter affecting deleted chat retention, both covered in this index and our companion guide to cloud AI risk.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Does Claude train on my conversations?<\/strong><br>It depends entirely on which product you use. Claude&#8217;s commercial surfaces, the API, Team, and Enterprise plans, do not train on your data by default. As of September 2025, Claude&#8217;s consumer Free, Pro, and Max tiers do train on conversations by default unless you actively opt out in your privacy settings, a change from Anthropic&#8217;s earlier, stricter consumer policy.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Is it safe for a law firm to use a general purpose AI tool like ChatGPT or Gemini instead of a legal specific platform?<\/strong><br>This index found that purpose built legal AI platforms scored meaningfully higher than every general purpose competitor, primarily because they carry no consumer tier weakness to offset their enterprise commitments. A firm can still use a general purpose tool&#8217;s enterprise tier appropriately for many tasks, but this index&#8217;s findings suggest doing so requires more active verification, of which specific tier is actually in use and whether training is genuinely disabled, than a purpose built legal platform typically requires.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What does zero data retention actually mean?<\/strong><br>It means a vendor has contractually committed not to store your prompts or outputs at all, as distinct from the separate promise of not using that data for training. A tool can honestly promise not to train on your data while still keeping a stored copy for a retention window, sometimes 30 days or longer, which is why this index scores these as two separate categories.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Why did DeepSeek score so much lower than every other tool in this index?<\/strong><br>Every other tool in this index operates under a legal jurisdiction, the United States, the European Union, or in Amazon Q and CoCounsel&#8217;s case, infrastructure with strong contractual data residency options, where government access to customer data generally requires a legal process like a court order. DeepSeek&#8217;s hosted service processes and stores data in China, where the 2017 National Intelligence Law legally compels organizations to cooperate with state intelligence work on request, a structural difference no contract can offset.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Is Microsoft Copilot GDPR compliant?<\/strong><br>Microsoft 365 Copilot, the commercial enterprise product, can be deployed in a GDPR compliant configuration with the right license, a signed Data Processing Agreement, and the EU Data Boundary enabled, according to independent analysis referenced in this index. As of 2026, a default routing feature called Flex Routing can send some processing outside that boundary for new EU and EFTA tenants unless an administrator manually disables it, which this index treats as a material caveat to that compliance posture.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What is the difference between SOC 2 Type I and Type II?<\/strong><br>A Type I report confirms an organization&#8217;s controls were suitably designed as of a single date. A Type II report, considerably more rigorous, confirms those controls actually operated effectively over an extended period, typically six to twelve months. This index weights Type II certifications more heavily for that reason, and treats a company holding only Type I as a meaningfully weaker signal.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Can I trust a vendor&#8217;s privacy policy if it has changed recently?<\/strong><br>A recent change is not automatically a red flag, since policies legitimately evolve as products and regulations change. What matters is the direction of the change and how it was communicated. This index documents one clear example, Anthropic&#8217;s September 2025 shift to opt out consumer training, where independent researchers specifically criticized the interface used to implement the change as a potential dark pattern, which is a more useful signal than the mere fact that a change occurred.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Does using a tool&#8217;s enterprise tier automatically protect all my organization&#8217;s data?<\/strong><br>Only for the traffic that actually flows through that specific tier. This index found repeatedly that employees retain the ability to open a personal, unmanaged account on the identical product, entirely outside their employer&#8217;s enterprise agreement and visibility, which is why the free tier comparison table in this index exists as a separate, deliberate section.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How often should my organization review its AI vendor&#8217;s privacy policy?<\/strong><br>Given that this index documents material policy changes occurring within a single calendar year at more than one company, a recurring review, at minimum every six months and ideally tied to any contract renewal date, is a more defensible practice than a one time review conducted only during initial vendor selection.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Is a locally run AI model automatically the safest option?<\/strong><br>This index&#8217;s findings suggest a properly contained local deployment removes several risk categories entirely, since there is no vendor to train on your data, retain it, or expose it through a subprocessor. It does not automatically satisfy compliance categories like third party certification, since those audits assume an external vendor to certify, which means an organization choosing this path takes on the responsibility of building and documenting its own equivalent controls, a tradeoff covered in detail in the local deployment section of this index.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>What is the AI specific ISO 42001 certification, and why does it matter?<\/strong><br>ISO\/IEC 42001, published in December 2023, is the first international management system standard specifically for artificial intelligence, covering how an organization governs the development, deployment, and ongoing risk management of AI systems, distinct from the broader information security scope of ISO 27001. This index found it held by Anthropic, Amazon Q, Harvey pending broader confirmation, and CoCounsel among the tools reviewed, and treats it as a meaningful, still relatively rare signal of AI specific governance maturity.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Does this index cover every AI tool on the market?<\/strong><br>No. This index covers twelve tools chosen specifically because they are among the most commonly used by the legal and business audience this guide is written for. The methodology section of this index is designed to be reusable, and the section on questions to ask any vendor not covered here is written specifically so readers can apply the same framework to a tool outside this list.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Does a higher score in this index mean a tool produces better quality output?<\/strong><br>No. This index exclusively measures data handling, training defaults, retention, certifications, and regulatory track record. A tool&#8217;s writing quality, reasoning capability, or feature set is a completely separate evaluation this index does not attempt, and a lower scoring tool here may well be the better choice for a task involving no sensitive data at all.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Why does this index weight training default so much more heavily than other categories?<\/strong><br>Training is the one category in this index with no clean undo. A retention window eventually expires. A subprocessor relationship can be renegotiated. Data that has already shaped a trained model, as several vendor policies in this index state directly, generally cannot be extracted or reversed after the fact, which is why this index treats it as the single highest stakes category among the eight.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>If a tool scored well in this index, does that mean my organization does not need its own AI use policy?<\/strong><br>No. Even the highest scoring tool in this index depends on your organization actually configuring and using the correct tier consistently. Our companion guide to cloud AI risk includes a full framework for building a short, effective AI use policy, and this index&#8217;s findings are most useful when paired with that kind of internal governance, not as a replacement for it.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Can a vendor pay to improve its score or ranking in this index?<\/strong><br>No. This index accepted no vendor payment, sponsorship, or pre publication review from any of the twelve companies covered, disclosed directly in the disclosure section above alongside our own commercial interest in the local AI category this index discusses.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>How does this index handle a vendor that offers materially different terms in different countries?<\/strong><br>Where we found a documented, meaningful difference, such as Meta&#8217;s EU and Brazil specific opt out rights not available elsewhere, we noted it directly in that tool&#8217;s profile rather than scoring only the most or least favorable regional version. A global organization operating across multiple jurisdictions should confirm which specific regional terms apply to each of its offices individually.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Why does this index compare tools that serve such different purposes, like a search engine and a legal drafting platform?<\/strong><br>Because the underlying question this index asks, what happens to your data once it leaves your hands, applies identically regardless of what the tool is for. A finance team pasting a sensitive figure into Perplexity to fact check a claim carries the same category of exposure as a paralegal pasting the same figure into a drafting assistant, even though the two products serve entirely different purposes.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Does a tool&#8217;s score in this index change if my organization negotiates a custom enterprise contract?<\/strong><br>It can, and this index says so directly in the limitations section above. Every score here reflects a vendor&#8217;s standard, published commercial terms. A large customer with real negotiating leverage can sometimes secure stronger commitments, a dedicated Zero Data Retention agreement, custom data residency, a shorter standard retention window, than what the vendor publishes for a typical customer, and your signed contract, not this index, governs your actual relationship with that vendor.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Is a tool that scored low in this index automatically unsafe for every use case?<\/strong><br>No. A low score in this index reflects weaker default data handling, not unusable software. A tool like Grok or Meta AI scored poorly here specifically because of training defaults and limited opt out rights, factors that matter enormously for confidential client or financial material and matter far less for a genuinely public, low stakes task where the underlying capability of the tool might still make it a reasonable choice.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"The_bottom_line\"><\/span>The bottom line<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Twelve companies, twelve different sets of incentives, and twelve meaningfully different answers to the same simple question: what happens to your data after you hit send. The pattern that emerges across all of them is not that any single company is secretly malicious. It is that <strong>the free or cheapest version of nearly every AI product is the version most likely to be trained on whatever you type into it<\/strong>, and that the gap between a company&#8217;s enterprise reputation and its actual consumer default is often wider than most users, and most of their employers, realize.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">The two tools that avoided nearly every pitfall in this index did so for a structural reason worth sitting with: <strong>they never built a free consumer tier to weaken the average in the first place.<\/strong> That is not an accident, and it is not available to every organization&#8217;s budget. But it points toward a genuinely actionable takeaway for any firm or business team working through this index&#8217;s findings: the safest AI tool is rarely the one with the best marketing page. It is the one built narrowly enough around your specific, highest stakes use case that it never had a reason to compromise on the questions this index asked.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">For the material that carries the most risk if this index&#8217;s findings turn out to matter in your specific case, privileged legal communications, unreleased financial data, competitively sensitive strategy, even the highest scoring cloud tool in this table is still, ultimately, a trust relationship with a company you do not control. A properly contained local deployment is the one path in this entire index that replaces that trust relationship with a physical fact. If your organization has read this far because that specific category of risk applies to your daily work, this index has given you the sourced comparison to justify evaluating that path seriously, starting with the highest sensitivity workflow you can identify today. <em>(Add your product name, a short description, and a link here before publishing.)<\/em><\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_we_will_keep_this_index_current\"><\/span>How we will keep this index current<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">An index like this one has a shelf life, and pretending otherwise would undercut the entire premise of publishing sourced, checkable claims in the first place. Vendor policies change, as this index itself documents happening to more than one company between its own research window and publication.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\">We intend to revisit this index on a recurring basis, checking each of the twelve profiles against the vendor&#8217;s current live documentation, and will note the date of the most recent review at the top of this piece going forward. If a vendor covered here materially changes its training default, retention window, certification status, or faces a new regulatory action, we will update the relevant profile and adjust its score accordingly, with the change documented rather than silently edited in. If you work at one of the twelve companies covered here and believe a specific claim is outdated or inaccurate, every claim in this index links directly to its source specifically so it can be checked, corrected, and cited precisely, rather than debated in the abstract.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Is it worth paying for an AI tool at all if the free version does most of what I need?<\/strong><br>This index&#8217;s findings suggest the answer depends entirely on what you are actually using it for. For genuinely non sensitive tasks, a free tier&#8217;s training default is a reasonable tradeoff many users make consciously. The moment a task involves a client&#8217;s name, an unreleased figure, or anything covered by a confidentiality obligation, this index&#8217;s findings point toward the cost of the paid, training excluded tier as a small price relative to the exposure of getting that specific judgment call wrong even once.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"How_to_cite_this_index\"><\/span>How to cite this index<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">This index is meant to be referenced, and we would rather make that easy than leave it to guesswork. When citing a specific finding, please link directly to this page, and where possible, name the specific tool and score you are referencing, since we expect to update individual profiles over time as documented in the section on keeping this index current above. A citation along the lines of &#8220;according to the AI Data Privacy Index&#8221; alongside a direct link gives your own readers the fastest path back to the full sourced methodology behind the specific number or finding you are citing, which is a more useful citation, for your readers and for ours, than a screenshot of the table alone.<\/p>\n\n\n\n<h2 class=\"wp-block-heading\"><span class=\"ez-toc-section\" id=\"Sources_and_further_reading\"><\/span>Sources and further reading<span class=\"ez-toc-section-end\"><\/span><\/h2>\n\n\n\n<p class=\"wp-block-paragraph\">Every factual claim in this index links to its original source above. For anyone who wants the complete research trail in one place, or who wants to verify a specific vendor&#8217;s profile independently, here is the full list, organized by tool.<\/p>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>General research and statistics<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/secureframe.com\/blog\/data-privacy-statistics\">110+ Data Privacy Statistics: The Facts You Need To Know In 2026<\/a>, Secureframe, aggregating KPMG&#8217;s Q4 2025 AI Quarterly Pulse Survey findings on AI leader privacy concerns.<\/li>\n\n\n\n<li><a href=\"https:\/\/writer.com\/blog\/enterprise-ai-adoption-2026\/\">Enterprise AI adoption in 2026<\/a>, Writer, covering the 2026 survey with Workplace Intelligence on executive perceptions of AI related data breaches.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.k2view.com\/news-blog\/2026-state-of-enterprise-data-compliance-survey\/\">2026 State of Enterprise Data Compliance survey<\/a>, K2view, on the gap between generative AI adoption and technical data controls.<\/li>\n\n\n\n<li><a href=\"https:\/\/kpmg.com\/xx\/en\/media\/press-releases\/2026\/03\/kpmg-global-ai-pulse-survey.html\">Three out of four global leaders will prioritize AI investment despite economic uncertainty<\/a>, KPMG International, on data security and privacy as the single highest ranked leader concern.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.ajg.com\/news-and-insights\/features\/ai-adoption-and-risk-benchmarking-2026\/\">The 2026 AI Adoption and Risk Survey: AI in Action<\/a>, Gallagher, on data protection and privacy violations as a top ranked perceived AI risk.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>OpenAI ChatGPT<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/openai.com\/security-and-privacy\/\">Security and privacy at OpenAI<\/a>, OpenAI&#8217;s own trust and compliance overview, covering SOC 2 Type 2 and ISO certifications.<\/li>\n\n\n\n<li><a href=\"https:\/\/openai.com\/enterprise-privacy\/\">Enterprise privacy at OpenAI<\/a>, OpenAI&#8217;s own commitments for Team, Enterprise, Edu, and Healthcare products regarding training exclusion and retention control.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.strac.io\/blog\/chatgpt-data-privacy\/\">ChatGPT Data Privacy: What OpenAI Collects &amp; Trains On<\/a>, Strac, detailing the tier by tier default training differences between Free, Plus, Team, and Enterprise.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Google Gemini<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.c-sharpcorner.com\/article\/does-google-use-my-data-to-train-gemini-enterprise-ai\/\">Does Google Use My Data to Train Gemini Enterprise AI?<\/a>, C-Sharp Corner, on Gemini Enterprise&#8217;s training exclusion and inherited Google Cloud compliance framework.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.strac.io\/blog\/gemini-data-privacy\">Gemini Data Privacy: What Google Collects &amp; Reviews<\/a>, Strac, on the consumer versus Workspace privacy split and human review disclosure.<\/li>\n\n\n\n<li><a href=\"https:\/\/anarlog.so\/blog\/google-gemini-data-retention-policy\/\">Everything You Should Know About Google Gemini Data Retention Policy<\/a>, Anarlog, on the eighteen month default consumer retention window and Personal Intelligence settings.<\/li>\n\n\n\n<li><a href=\"https:\/\/concentric.ai\/google-gemini-security-risks\/\">Google Gemini security risks and privacy concerns explained<\/a>, Concentric, on Personal Intelligence and Gemini Spark&#8217;s cross service data reasoning context.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Microsoft Copilot<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/learn.microsoft.com\/en-us\/microsoft-365\/copilot\/microsoft-365-copilot-privacy\">Data, Privacy, and Security for Microsoft 365 Copilot<\/a>, Microsoft&#8217;s own documentation on training exclusion and EU Data Boundary coverage.<\/li>\n\n\n\n<li><a href=\"https:\/\/compound.law\/en-DE\/tools\/copilot-microsoft-365\/\">Microsoft 365 Copilot GDPR Compliance in Germany, 2026 Update<\/a>, Compound, on the Anthropic subprocessor addition and German DSK compliance concerns.<\/li>\n\n\n\n<li><a href=\"https:\/\/changepilot.cloud\/blog\/microsoft-365-copilot-flex-routing-eu-data-boundary-mc1269223\">Microsoft 365 Copilot Flex Routing: Your Data Left EU Data Boundary<\/a>, ChangePilot, on the 2026 default routing change affecting EU and EFTA tenants.<\/li>\n\n\n\n<li><a href=\"https:\/\/sonomos.ai\/blog\/is-microsoft-copilot-gdpr-compliant-2026\/\">Is Microsoft Copilot GDPR Compliant? A 2026 Guide<\/a>, Sonomos, on the distinction between consumer and commercial Copilot compliance posture.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.waimakers.com\/en\/resources\/ai-data-security\/microsoft-365-copilot\">Microsoft 365 Copilot, AI Data Security &amp; GDPR Guide<\/a>, WAIMAKERS, on subprocessor details and regional processing commitments.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Anthropic Claude<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/anonyome.com\/knowledge-center\/ai-privacy\/claude-privacy\/\">Claude privacy: How Anthropic handles your data<\/a>, Anonyome, on SOC 2, HIPAA BAA status, and the contested September 2025 consumer opt in interface.<\/li>\n\n\n\n<li><a href=\"https:\/\/anarlog.so\/blog\/anthropic-data-retention-policy\/\">Anthropic Claude Data Retention Policy 2026<\/a>, Anarlog, detailing the August to September 2025 consumer policy change and its five year retention implication for opted in users.<\/li>\n\n\n\n<li><a href=\"https:\/\/readysolutions.ai\/blog\/2026-06-08-claude-data-handling-due-diligence\/\">Claude Data Retention Isn&#8217;t a Mystery. Your Approval Process Is<\/a>, Ready Solutions AI, on the full certification list including ISO 42001 and the commercial versus consumer policy boundary.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Meta AI<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.auditsocials.com\/blog\/meta-ai-privacy-policy-ad-targeting-changes-2026\">What Does Meta&#8217;s Privacy Update Mean for AI Tools &amp; Data Use?<\/a>, AuditSocials, on conversational data feeding into advertising personalization.<\/li>\n\n\n\n<li><a href=\"https:\/\/thedataprivacygroup.com\/blog\/meta-user-privacy\/\">Meta&#8217;s AI-Fuelled Future Puts User Privacy on the Line<\/a>, The Data Privacy Group, on the limited geographic availability of opt out rights.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>xAI Grok<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/anonyome.com\/knowledge-center\/ai-privacy\/grok-privacy\/\">Grok privacy: Does X train AI on your tweets?<\/a>, Anonyome, on the default training scope covering a user&#8217;s full public post history.<\/li>\n\n\n\n<li><a href=\"https:\/\/medium.com\/@AxiomHiveAi\/x-xais-grok-and-the-intersection-of-ai-training-data-privacy-and-minor-protection-988f748bed23\">Regulatory Headwinds, X\/xAI&#8217;s Grok and the Intersection of AI Training, Data Privacy, and Minor Protection<\/a>, an independent regulatory analysis documenting formal action across eight jurisdictions.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Perplexity<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.perplexity.ai\/help-center\/en\/articles\/11564572-data-collection-at-perplexity\">Data Collection at Perplexity<\/a>, Perplexity&#8217;s own help center documentation on Enterprise tier training exclusion and retention.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.perplexity.ai\/help-center\/en\/articles\/10354963-are-third-party-model-providers-training-on-my-data\">Are third-party model providers training on my data?<\/a>, Perplexity&#8217;s own disclosure of its contractual terms with OpenAI and Anthropic.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.strac.io\/blog\/perplexity-data-privacy\/\">Perplexity Data Privacy: What It Retains &amp; Trains On<\/a>, Strac, on the consumer tier training default and the search specific oversharing risk.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Mistral<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/weventure.de\/en\/blog\/mistral\">Mistral AI &amp; data protection: The secure AI alternative from Europe<\/a>, on Le Chat Pro&#8217;s training exclusion and self hosting option.<\/li>\n\n\n\n<li><a href=\"https:\/\/meetily.ai\/llm-privacy\/mistral\">Mistral La Plateforme Data Retention Policy 2026<\/a>, Meetily, on the EU jurisdiction, DPA structure, and Zero Data Retention scope.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.waimakers.com\/en\/resources\/gdpr-compliance\/mistral-ai\">Mistral AI, GDPR Compliance Guide<\/a>, WAIMAKERS, on the CNIL complaint over free tier opt out friction and expanded US processing capacity.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>DeepSeek<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/witness.ai\/blog\/deepseek-security-concerns\/\">DeepSeek Security Concerns: What Businesses Need to Know<\/a>, Witness AI, on the National Intelligence Law and Chinese data storage requirement.<\/li>\n\n\n\n<li><a href=\"https:\/\/lumichats.com\/blog\/is-deepseek-safe-to-use-2026-usa\/\">Is DeepSeek Safe to Use in 2026?<\/a>, LumiChats, on the structural jurisdictional distinction from US and EU providers.<\/li>\n\n\n\n<li><a href=\"https:\/\/securityscorecard.com\/blog\/what-you-need-to-know-about-deepseek-security-issues-and-vulnerabilities\/\">What You Need To Know About DeepSeek Security Issues and Vulnerabilities<\/a>, SecurityScorecard, on plaintext credential storage and ByteDance integration findings.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.promptquorum.com\/local-llms\/deepseek-local-china-data-privacy-2026\/\">Does Local DeepSeek Solve the China Data Problem?<\/a>, PromptQuorum, on the Garante block and the distinct risk profile of self hosted open weight DeepSeek models.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Amazon Q<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/docs.aws.amazon.com\/amazonq\/latest\/qbusiness-ug\/compliance-validation.html\">Compliance validation for Amazon Q Business<\/a>, AWS&#8217;s own documentation listing HIPAA, SOC 1\/2\/3, PCI, and ISO 42001 coverage.<\/li>\n\n\n\n<li><a href=\"https:\/\/aws.amazon.com\/blogs\/machine-learning\/build-private-and-secure-enterprise-generative-ai-apps-with-amazon-q-business-and-aws-iam-identity-center\">Build private and secure enterprise generative AI apps with Amazon Q Business and AWS IAM Identity Center<\/a>, AWS, on the identity aware retrieval architecture.<\/li>\n\n\n\n<li><a href=\"https:\/\/dev.to\/nicoherzhauser\/protecting-your-data-a-developers-guide-to-aws-ai-opt-out-policies-400g\">Protecting Your Data: A Developer&#8217;s Guide to AWS AI Opt-Out Policies<\/a>, on Amazon Q Developer&#8217;s tier by tier training defaults.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Harvey<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.harvey.ai\/security\">Secure legal AI for the most sensitive matters<\/a>, Harvey&#8217;s own security overview covering its Security Addendum and third party audit partnerships.<\/li>\n\n\n\n<li><a href=\"https:\/\/www.harvey.ai\/blog\/security-by-design\">Security by Design: How Harvey Engineered Trust from Day One<\/a>, Harvey, on its SOC 2 Type II, ISO 27001, and EU-US Data Privacy Framework certification.<\/li>\n\n\n\n<li><a href=\"https:\/\/theplanettools.ai\/tools\/harvey-ai\">Harvey AI Review 2026: Is the $11B Legal AI Worth It?<\/a>, ThePlanetTools.ai, independent verification of Harvey&#8217;s certification stack and configurable data residency.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Thomson Reuters CoCounsel<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/legal.thomsonreuters.com\/blog\/responsible-ai-in-courts-the-answer-is-cocounsel-legal\/\">Responsible AI for court systems with CoCounsel Legal<\/a>, Thomson Reuters, on SOC 2 Type II, ISO 27001, and zero retention API architecture.<\/li>\n\n\n\n<li><a href=\"https:\/\/legal.thomsonreuters.com\/blog\/the-two-non-negotiables-of-secure-legal-ai\/\">Two data non-negotiables of government legal AI<\/a>, Thomson Reuters, on CoCounsel&#8217;s no training on customer data commitment.<\/li>\n\n\n\n<li><a href=\"https:\/\/theaiagentindex.com\/agents\/cocounsel\">CoCounsel Review (2026): Thomson Reuters Legal AI<\/a>, The AI Agent Index, independent verification of CoCounsel&#8217;s triple certification and adoption figures.<\/li>\n\n\n\n<li><a href=\"https:\/\/legal.thomsonreuters.com\/blog\/the-consumer-vs-professional-ai-privacy-standards-for-legal-work\/\">Consumer and professional AI privacy standards for legal work<\/a>, Thomson Reuters, on the structural difference between consumer grade and purpose built legal AI data handling.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><strong>Additional context on regulatory frameworks<\/strong><\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li><a href=\"https:\/\/www.dataprotectionreport.com\/2023\/04\/italian-garante-bans-chat-gpt-from-processing-personal-data-of-italian-data-subjects\/\">Italian Garante bans ChatGPT from processing personal data<\/a>, Data Protection Report, background on the regulator most active across this index&#8217;s findings.<\/li>\n\n\n\n<li>Our companion guides, <em>7 Hidden Risks of Cloud AI for Law Firms and Business Data<\/em> and <em>AI Agents Are Quietly Becoming Your Biggest Data Risk<\/em>, cover the confidentiality, discovery, and autonomous agent risks that sit alongside this index&#8217;s data handling findings, referenced throughout this piece as further reading on adjacent topics this index does not itself cover in depth.<\/li>\n<\/ul>\n\n\n\n<p class=\"wp-block-paragraph\"><\/p>\n","protected":false},"excerpt":{"rendered":"<p>An independent, sourced comparison of what happens to your prompts, files, and client data across ChatGPT, Gemini, Copilot, Claude, Meta AI, Grok, Perplexity, Mistral, DeepSeek, Amazon Q, Harvey, and CoCounsel, scored against a single transparent methodology, with a link to the original policy behind every claim.<\/p>\n","protected":false},"author":1,"featured_media":203,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[4,102],"tags":[80,84,70,87,74,19,103,94,71,20,101,105,89],"class_list":["post-202","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-cyber-security","category-data-privacy","tag-agentic","tag-agentic-ai","tag-ai","tag-ai-access","tag-ai-agents","tag-ai-bots","tag-ai-data","tag-ai-fraud","tag-ai-scams","tag-blocking-ai-bots","tag-compliant-ai-technology","tag-data-leaks","tag-data-privacy"],"_links":{"self":[{"href":"https:\/\/clickbaton.com\/blog\/wp-json\/wp\/v2\/posts\/202","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/clickbaton.com\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/clickbaton.com\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/clickbaton.com\/blog\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/clickbaton.com\/blog\/wp-json\/wp\/v2\/comments?post=202"}],"version-history":[{"count":1,"href":"https:\/\/clickbaton.com\/blog\/wp-json\/wp\/v2\/posts\/202\/revisions"}],"predecessor-version":[{"id":214,"href":"https:\/\/clickbaton.com\/blog\/wp-json\/wp\/v2\/posts\/202\/revisions\/214"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/clickbaton.com\/blog\/wp-json\/wp\/v2\/media\/203"}],"wp:attachment":[{"href":"https:\/\/clickbaton.com\/blog\/wp-json\/wp\/v2\/media?parent=202"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/clickbaton.com\/blog\/wp-json\/wp\/v2\/categories?post=202"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/clickbaton.com\/blog\/wp-json\/wp\/v2\/tags?post=202"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}