Anthropic

anthropic.com · generative ai & ai assistants

By default, your conversations can train the models, and deletion is conditional by design: safety flags override it and copies travel past the company you typed to. What was absorbed into a trained model does not come back out.

Reported incidents

A Claude model read a stranger's personal details during a security test

2026-09-09

Affected Claude models in third-party cybersecurity evaluations

On 9 September 2026 Anthropic disclosed a fourth incident in which one of its Claude models, set a hacking exercise in a test environment, reached the internet and got into a real third party's system. An early Claude Opus 4.6 checkpoint read the personal information of one person linked to that third party, collected credentials and changed system settings. Anthropic said it notified the affected party. On 30 July 2026 it had disclosed three earlier incidents at the same testing partner, Irregular, in which models reached the production systems of three organisations, one holding several hundred rows of production data. Anthropic said the test environments were misconfigured.

Code for its verification dashboard found open on a government-authorised server

2026-02-19 via Persona

Affected Front-end code on its FedRAMP (government) environment

Researchers found 2,456 files of Persona's front-end code, about 53 megabytes, openly reachable on a Google Cloud endpoint tied to its FedRAMP environment for US government use, The Rage reported on 19 February 2026. The code showed 269 kinds of check, including face matching against watchlists and screening against adverse media in 14 categories. Persona said the environment held no customer data, was isolated from production and exposed no personal data. Persona had run a short age check trial for Discord in the UK; both firms told Fortune it lasted less than a month and had ended before the files were found.

Claude chats used for training if users allow it, and kept for five years

2025-08-28

Affected Claude Free, Pro and Max

On 28 August 2025 Anthropic changed its consumer terms and privacy policy so that chats and coding sessions on Claude Free, Pro and Max can be used to train its models. For users who allow it, Anthropic keeps that data for five years instead of 30 days. Existing users were asked to choose by 8 October 2025 and had to make a choice to keep using Claude. Business, government, education and API use are not covered. Anthropic said "we do not sell users' data to third parties."

Reported by Anthropic

Loses bid to move DoorDash drivers' face scan lawsuit into arbitration

2024-08-13 via Persona

Affected Driver identity checks for DoorDash

An Illinois appeals court ruled on 13 August 2024 that Persona cannot force two DoorDash drivers' biometric privacy claims into arbitration. Charles Washington and Katie Sims sued Persona in Will County in late 2021, in a proposed class action under Illinois's Biometric Information Privacy Act. Registering as drivers in 2021, they sent DoorDash selfies and licence photos, checked by Persona's software, which the court said collects, analyses and stores scans of drivers' face geometry. They say Persona did not publish a policy on how long it keeps that data. The court held Persona was not a beneficiary of DoorDash's driver contract and sent the case back.

People affected typically ask Anthropic to confirm whether their information was included, and which categories.

The verified route

What sits behind them

Anthropic anthropic.com What sits behind this company, from what is on file.

Works on its behalf

Persona Identity verification · processor

ID verification

Anthropic routes identity checks to:

Persona
withpersona.com pure verifier

Their stated retention Government ID and selfie data destroyed on completion of verification or within 3 years of the last interaction, per the client's instructions. IP addresses and device fingerprints also collected.

Provider terms from their published policies, read August 2026.

DÆTRAX is a personal data accountability ledger: a dated record of which companies hold your personal data, what you asked them to do about it, and what they claimed in reply.