Skip to main content
Hub365 AI
Turning that setting off doesn't erase what you already typed
OperationsSeptember 24, 2026·10 min read

Turning that setting off doesn't erase what you already typed

Small South Florida firms have been pasting client material into AI for months. What happens to what's already in there, the one gesture that works backwards, and the one-line rule that makes your current habit safe.

Naty here.

Training settings point forward. They govern what you type from now on and they don't rewind, and what's saved stays saved. Both tools also have a button people press out of politeness that feeds the whole conversation back in. Deleting works backwards. Nothing else does.

Tuesday brought a model built for legal work, and the detail that mattered was buried: large firms had been building their own tooling for months with lab engineers working inside. Contract reviewers, document review systems for acquisitions. A ten-person firm in Fort Lauderdale has a monthly subscription and identical confidentiality duties.

And it isn't starting from zero. Eight months of use are already in there. Every piece of advice available is about what not to paste tomorrow, written for someone who hasn't pasted anything yet. They have. March, May, last Tuesday.


Three things people believe, and what the companies themselves publish

None of this is our opinion. They publish it and anyone can open it.

"I turned training off, so I'm fine"

Do it, it helps. It also only governs the future.

OpenAI is blunt: turning off "Improve the model for everyone" does not delete or hide saved chats. Its own wording for what stays: "Regular chats remain in history."

Anthropic's version for Claude: switching off model improvement stops future training, but your data stays in training runs already in progress, and in models already trained.

Not identical claims, and worth not blurring: one is about your saved chats, the other about runs already moving. What they share is the direction. The switch is a door, not an eraser.

"I archived it"

This is the one that surprised us, because archiving feels like locking something away. OpenAI: archiving a chat does not change whether it can be used to train the models. Your setting still governs. Archiving tidies your screen and nothing else.

"I gave it a thumbs-up to help"

Here's the detail almost nobody knows. Both tools treat the thumbs separately, and each says something different.

OpenAI puts it in its own FAQ, immediately after explaining how to opt out of training: give feedback with a thumbs-up or thumbs-down and the entire conversation attached to that feedback may be used to train the models. The thumbs reopens the door you just closed.

Anthropic says something different, and the two shouldn't be blurred: it doesn't mention training, it mentions time. Data attached to thumbs feedback is retained for five years. Its page never says the thumbs enables training, and we're not going to add that for them.

It's the most innocent button on the screen, and you press it when the answer was good, which is exactly when you'd handed over your best material.


The one gesture that works backwards

Delete the conversation. Not archive, not toggle. Delete.

Anthropic publishes the clock: a deleted conversation leaves your history immediately and their back-end storage within 30 days, and isn't used for future training. In ChatGPT, deleting a chat and deleting your account are separate from the training toggle and have to be done deliberately.

Two caveats, or this reads like a complete fix and it isn't:

What went into a trained model went in. Neither company promises otherwise and we won't promise it for them.

On a business plan, some of this isn't your call. OpenAI publishes that in managed workspaces data export and account deletion aren't self-service and route to the workspace owner. Deleting a single conversation usually still works. Above all of it sit your organization's retention policies, which makes this a conversation with whoever administers the account.


Going forward, and precision matters here or none of it helps

On Tuesday, in this same publication, we walked through asking AI for a client deck. Step one was paste the raw material: call notes, the client's email, your quote, unsorted. The prompt read:

Build a [6]-slide deck for [client name], who is [their role, and what kind of business].

What I know about their situation is below, unsorted.

We stand by it. Delegating the mess is the whole point. But be exact about where the problem sits, because the wrong fix is very comforting.

The bracket isn't the problem. Swapping [client name] for [Client A] feels like a fix and barely is one. The name sits once in the bracket and dozens of times in what you paste underneath: email header, signature, quote, call notes, next to the registered company name, the amounts, the phone, probably the address. Sanitizing the label and dumping the rest untouched is the worst available combination, because you end up equally exposed and convinced you're done.

What works: find-and-replace over the block in your own editor before pasting. Not three terms, all of the ones you just read: the person's name, the trading name, the registered name, which is rarely the trading name, the signature email, the phone, the address, the matter number. Each replaced consistently, so "Martinez Construction" reads "the construction company" everywhere.

The first pass takes a few minutes, because you have to see what's in there. After that it's two, and by the third time you're writing the material without names to begin with, which is where this stops being a task.

This isn't a new house rule. Layer 4 of our business lockdown guide has said it since July, word for word: "No sensitive data in public tools. Don't paste customer info into AI chats without retention control." Look at the end of that sentence, because almost nobody does: without retention control. That qualifier is exactly what this page takes apart, because you've just seen that on an ordinary account the retention control you think you have isn't the one you have.

Five things rarely need to go in whole: health or financial data on an identifiable person, credentials, a full contract with the registered name, your client list straight from the system, and anything you wouldn't want quoted back to you on a call.

That fourth connects to yesterday. Wednesday's reactivation exercise has you export that list to a sheet of your own. Your sheet is fine. A chat isn't.


Naty and Todd's corner

Naty: Here's why I think almost nobody will open that history, even after reading all of this and agreeing with it. It isn't laziness. You suspect what's in there, and as long as you don't look, you don't fully know. When I had the spa it was the same with the client cards: I knew that drawer was a mess and I opened it as rarely as possible.

Todd: And there's a less comfortable reason underneath. In a profession with duties, finding out creates an obligation. Until you've looked, it's an oversight. Once you've looked, it's a decision you made. Nobody says that out loud, but that's the part with weight on it.

Naty: Which is why it helps me to take the moral charge off whatever turns up. It isn't a failing of yours. It's what happens when you use a new tool with nobody telling you how, which is what all of us did. Whoever pasted a client's email in March wasn't being careless. They were working with what they had.

Todd: And it helps to size up what actually happens if you open it. In the large majority of cases you review, decide, note the date and carry on with your day. If something serious turns up, that's a conversation with whoever owns the file, and that conversation exists whether you look or not. The only question is whether you're the one who starts it.


What you're doing today, and it's twelve minutes

This isn't a blank sheet to fill in. It runs on what's already in your account.

  1. Open your history, scroll to your last five long conversations. The real ones, where you pasted something whole.
  2. Look for a proper name in each. Client, opposing party, company. There it is: that's what didn't need to go in.
  3. Decide one at a time, delete or keep. No general right answer. And per the warning above: live matter means not today.
  4. Check which ones you gave a thumbs-up. Good enough to rate usually means it came from your best material.
  5. Open your data settings before you close and see whether training is on. Almost nobody ever has.

If all five turn up nothing, you finished early knowing you're clean instead of assuming it.

Want the eight prompts that walk through the review? Thursday's 2pm post has them: What your AI already knows about your clients.


Frequently asked questions

So is AI training on my clients' data? We're not claiming that. What's verifiable is what each company publishes about its own settings: switching them off doesn't erase the past, archiving changes nothing, thumbs feedback isn't free. What happened to one specific firm's data is something neither we nor that firm can know.

If I delete the conversation, is it really gone? Anthropic publishes: out of your history immediately, out of their storage within 30 days, not used for future training. What's already inside a trained model is a different question nobody promises to reverse.

My firm uses a business plan. Does that change things? Favorably on the main point: OpenAI publishes that it doesn't train on those workspaces by default. What stops being self-service is data export and account deletion, which route through the workspace owner, and your organization's retention policies govern above that. The conversation you need is with whoever administers the account.

Isn't it easier to just ban AI at the firm? Easier, and it almost never works. People use it from personal accounts instead, where you have no visibility at all. A one-line rule everyone follows protects more than a ban everyone routes around.

Does this only apply to lawyers? No. Any trade holding someone else's information under an obligation: accountants, advisors, medical practices, agencies running other people's accounts. Firms are the example because the duty is written down and carries sanctions. The mechanism is identical everywhere.


To close

The public conversation about AI and data is written for someone who hasn't started. Your firm started months ago.

The forward decision is a habit and takes upkeep. The backward one is a task with an ending: done once, closed.

Twelve minutes, five conversations, one proper name in each. That's the only thing here to do today.

And if you open your history and find nothing worth deleting, that's an answer too, worth exactly as much as the other one.


Keep reading

September 24, 2026
Share

Related Articles

Ready to implement this for your business?

Hub365 AI handles GEO, SEO, AI tools, and automation - in English and Spanish.

Book a Free Strategy Call

Loading comments...

Leave a Comment

Share your thoughts with the community. We read every comment.

FREE NEWSLETTER

Start building your edge with AI

The AI Edge

One email a week. Practical AI moves for service businesses. No hype. For business owners who want the edge before their competitor. You do not need to be technical.

Explore free resources