Historical source and event dates are not site publication dates. Product plans, policies and availability may have changed since retrieval.
The setup
A team evaluating Claude's API for a product has a different document to read than someone signing up for the consumer chat app. Anthropic publishes a separate Commercial Terms of Service for API and commercial customers, apart from its consumer terms — exactly the kind of document a procurement or security reviewer needs before adopting the API, rather than the marketing page.
What the documents show
The commercial terms state plainly that 'Anthropic may not train models on Customer Content from Services,' an explicit contractual prohibition on using API inputs and outputs for model training. On deletion, the terms include a destruction-request clause: a party 'will destroy Discloser's Confidential Information promptly upon request, except where retained to comply with law or copies in Recipient's automated back-up systems.' The document does not itself state a numeric retention period, pointing instead to a separate Data Processing Addendum for that detail. Anthropic's Usage Policy, effective 15 September 2025, is a separate, uniform conduct document that applies to consumer and commercial users alike, distinct from either terms of service.
The friction
The commercial terms' own language limits how absolute the no-training and deletion commitments are: destruction is 'prompt,' not instant, and explicitly excludes backup copies and anything retained for legal compliance, so 'delete on request' is not a guarantee of immediate, total erasure. Because the retention period itself is not stated here but deferred to a separate DPA, a reviewer's checklist grows by one more document that has to be separately requested and read before the data-handling picture is complete.
What changed in the work
For a team choosing between the consumer product and the API, the commercial terms document a different contractual baseline: no training on customer content under a signed agreement, versus whatever separate terms govern the consumer chat product. Editorially, that means the choice between the two surfaces is not only about interface or price; it changes which written data-handling commitments actually apply to the account.
- Have you actually requested and read the separate Data Processing Addendum, not just the terms of service?
- Does your team's use case run through the commercial API, or the consumer product with different terms?
- What does 'promptly' mean in practice for your compliance timeline, and does that match what a regulator or auditor expects?
Reading the terms does not tell you how Anthropic behaves in practice, only what it has committed to in writing for commercial customers as of 16 September 2026. That written commitment is still the right starting point for a procurement review, ahead of any vendor's marketing claims about privacy.
Sources & verification
Preserved from the earlier archive. These sources have not all been freshly rechecked for this expansion.
- Commercial Terms of ServiceSource date: not stated · Retrieved: 2026-09-16
The contractual no-training-on-customer-content clause and the conditional destruction-request provision for commercial and API customers.
- Usage PolicySource date: 2025-09-15 · Retrieved: 2026-09-16
The separate, uniform conduct policy that applies alongside (not instead of) the commercial or consumer terms of service.
Continue the workflow
- Audit knowledge-base access with allowed and denied tests
A minimum-rights test for a small team that checks both useful access and denied access across a shared knowledge base.
- Calculate the total cost of a workflow, not just the subscription
Compare a manual process and an automated alternative without relying on volatile plan prices.
- Run a vendor exit drill before the exit is urgent
Find out whether a team can leave a workflow vendor without losing data, behavior, access, or business continuity.
- Okta wants AI agents to be identities, not shared secrets
Okta's own documentation proposes short-lived, revocable credentials for AI agents in place of the hardcoded API keys many teams use today.