What happens to a client file after it's pasted into a personal AI account
Follow one client email through someone's personal AI account, then your own business numbers. Who keeps it, who can read it, and what a business plan changes.
When a client file goes into someone's personal AI account, it can be kept anywhere from 30 days to five years, read by people who work for the AI company, or used to train their next model. It depends on the tool and the settings. It also stays with whoever owns the account, including after they leave. Moving the work onto a business plan keeps it under your control.
In August we wrote about AI tools, their tiers and the Privacy Act, which plan does what. This one's narrower. It follows one piece of client information through a personal AI account and asks the same question at every stop. Who's got it now?
A quick bit of background first. A personal account is one somebody signs up for as themselves, free or paid, like ChatGPT Plus or Claude Pro. A business account is one the company signs up for, usually called Team, Business or Enterprise. Same chat box. Very different paperwork.
Now the story. A client emails about a dispute with their landlord. Someone on your team pastes it into their personal AI account on a Tuesday afternoon to draft a reply faster. Nothing dramatic. It happens in offices every day.
This is general information, not legal advice. AI companies change these terms every few months. What follows is how things stood in October 2026.
At 2.14pm on Tuesday it leaves your building
The moment it's sent, it's sitting on the AI company's servers, almost certainly overseas. That part's allowed.
New Zealand's Privacy Act has 13 rules for handling information about people. Rule 12 covers sending it offshore. The Privacy Commissioner's guidance says using an overseas provider to store or process it is fine, as long as the provider isn't using it for its own purposes.
On a personal plan, your business hasn't signed anything that says they won't.
For the next 30 days it's kept, whatever the settings say
Most AI companies keep a copy of what you type for a while, even with the important settings switched off. On Claude's personal plans that's 30 days when the person hasn't agreed to training. Google still checks Gemini chats for safety with activity history turned off.
Somewhere in there, a person might read it
AI companies pay people to read samples of conversations, to check the answers are good and nothing harmful is going on. Google says a share of chats in its personal Gemini app are read this way, including by outside contractors. Those reviewed chats are kept for up to three years, and deleting your history doesn't remove them.
Your client didn't agree to that. Neither did your business. Your staff member did, when they clicked accept on a plan built for personal use.
For up to five years it might be training data
Training is how AI companies improve their models. They feed real conversations into the next version so it learns from them.
On ChatGPT's free plan and Plus, OpenAI can use what's typed for training unless the person has switched it off. On Claude's free plan, Pro and Max, each person chooses, and choosing yes keeps their chats for five years.
Deleting a chat stops it being used in future training. It doesn't undo training that's already happened.
The day they resign, it walks out the door
The account belongs to the staff member, and so does the history. The client email, the draft reply and everything else they pasted in over two years go with them. You can't see it, download it or delete it.
If that client later asks what's happened to their information, you won't have a full answer. That's an awkward conversation for any business, and a worse one if you're regulated.
We've seen the account problem at scale. When a business changes hands, the new owners often find systems still tied to someone who's gone. We spent part of this year untangling exactly that, one login at a time. A personal AI account is the same problem, with no admin screen to fix it from.
If something goes wrong, nobody has to tell you
On a personal plan your business isn't the AI company's customer. If they have a security incident, there's no contract obliging them to tell you. Under the Privacy Act, you'd still be the one answering for your client's information.
It isn't only client files
Run the same trip with your own business information and it ends up in the same places. The pricing review. The owners' drawings. Invoices that have been sitting unpaid too long. A staff performance issue. The pitch for a client you're trying to win off someone else.
Owners and managers are often the heaviest users of personal plans, because nobody tells them what to use. The Privacy Act protects information about people, so your own commercial numbers get no protection from it at all. Staff matters do, because they're about a person. Either way, the plan's settings are the only thing deciding who sees it and for how long.
The Privacy Commissioner's guidance also notes that some AI tools have leaked passwords and API keys, the codes software uses to log into other software, after they turned up in training data. Logins and screenshots of your systems don't belong anywhere near a personal plan.
Same tool, business plan
Put the same email into a business account and most of those stops change. That's because a business plan comes with commercial terms and a data processing agreement, usually called a DPA. The DPA is the contract that says the AI company handles your information on your instructions and for your purposes.
- The AI company processes it for you, under that DPA.
- It isn't used for training by default. OpenAI, Anthropic and Google all say so for business customers.
- The account and its history belong to the business.
- When someone leaves, you remove their access and the work stays put.
- How long it's kept, and what happens if something goes wrong, are written into a contract you hold.
There's still judgement involved in what goes in. The difference is you can explain the arrangement to a client, an auditor or the Privacy Commissioner without wincing.
We run our own client work in Claude on a Team plan. Anthropic's commercial terms rule out training on our content and include a DPA, which is the whole reason we pay for it.
Four things worth doing this month
- Start with the owners and managers. Check which account you use for the business's own numbers and plans.
- Find out which personal AI accounts are being used for client work. Ask rather than audit. People tell you more when they're not in trouble.
- Move client work and your own business information onto one business plan with a DPA, and stop using personal accounts for anything work related.
- Add AI accounts to your onboarding and offboarding, and say in your privacy statement which tools you use and how.
The plan by plan comparison is in our August post. Project Seven, our parent agency, wrote the business owner's version, what a personal AI plan puts at risk.
Not sure where your client files have been? Have a chat with us.