Interactive Comparison
AI Provider Security & Governance Matrix
Filter and compare AI vendors on data usage defaults, retention windows, EU data residency, DPA availability, and EU AI Act posture. Sourced directly from primary terms and trust portals.
| Provider | Default Training Use | Retention Window | EU Residency | DPA Terms | AI Act Status | Action |
|---|---|---|---|---|---|---|
| Anthropic | Consumer Claude.ai (Free/Pro/Max): yes, by default, unless the user opts out in account privacy settings. Commercial/API: no — Anthropic's Commercial Terms state it may not train models on customer content from the Services. | Consumer, training left on: 5 years (changed from a shorter default in an August 2025 policy update). Consumer, training opted off: 30 days. Standard API (non-Covered-Model, no Zero Data Retention or HIPAA arrangement): not retained by default beyond what's needed to serve the request. Covered Models (Claude Fable 5, Claude Mythos 5) via API: 30-day retention is mandatory and ZDR is unavailable. Content flagged for safety review: retained up to 2 years regardless of tier. Compliance API / Activity Feed: 6-year retention. | No EU/EEA storage residency is offered; Anthropic states data is stored in the US. Inference may route through the US, Europe, Asia or Australia by default, and the API exposes an inference_geo parameter for some control; Enterprise usage-based-billing customers can request US-only inference via support. No primary source found offering EU-only inference or EU storage. | Yes, automatic for commercial tiers on accepting the Commercial Terms of Service — Anthropic states the DPA is accepted at the same time. Scoped explicitly to commercial products (Claude for Work, the API); not offered for individual Claude.ai Free/Pro use. A specific DPA effective date circulating in secondary sources was not confirmed on Anthropic's own page — see verification note. | Code of Practice Signatory | View Dossier → |
| Consumer Gemini Apps, default ('Keep Activity' on): yes — Google states it uses activity 'to provide, develop, and improve its services (including training generative AI models).' Paid Gemini API / Vertex AI: no — Google states it does not use prompts or responses from paid use to improve its products. Free/unpaid Gemini API and AI Studio: yes — treated the same as consumer activity, used to improve Google's products. | Consumer Gemini Apps, Keep Activity on: auto-deletes after 18 months by default (adjustable to 3 or 36 months, or kept until manually deleted). Keep Activity off / temporary chats: 72 hours. Conversations selected for human review: kept up to 3 years regardless of the user's deletion. Paid Gemini API: prompts/responses logged for a limited, unstated period solely to detect abuse; Search-grounding and Maps-grounding data held on separate shorter schedules (30–90 days, or up to 6 months for chat history). | Vertex AI offers an EU multi-region endpoint that, per Google's documentation, keeps ML processing inside EU member states specifically (not the same as EEA — UK and Switzerland are excluded) when a jurisdictional endpoint is explicitly selected; the global endpoint gives no residency guarantee at all. No equivalent residency option was found for consumer Gemini Apps. Exact current wording not independently re-fetched in this pass — see verification note. | Yes, for Google Cloud and the paid Gemini API, self-serve via clickthrough acceptance (reportedly through Cloud Console account settings). Not offered for the free consumer Gemini Apps product, which is governed by the Gemini Apps Privacy Notice instead. | Code of Practice Signatory | View Dossier → | |
| Meta | Meta AI: yes, by default — public posts and comments, plus interactions with Meta's AI features, are used to train, on a legitimate-interests legal basis for EU/UK users. EU training was paused in 2024 pending regulatory clarity and resumed the week of 14 April 2025. Meta Model API, paid tier: no — content from Paid Services is contractually excluded from training. Meta Model API, unpaid tier: yes — users are warned not to submit sensitive, confidential or personal information to it. Llama open-weight models: not applicable — Meta has no visibility into or processing role over self-hosted use. | Meta AI: no fixed period — Meta states it keeps training data 'for as long as we need it on a case-by-case basis.' Meta Model API (paid and unpaid): same case-by-case pattern, retained as needed for service delivery, legal compliance and policy review. | Not offered for Meta AI — no data-residency commitment was found in its Terms of Service or Privacy Policy. For the Model API, residency is effectively moot in the EU's favor for the wrong reason: the Paid Services are stated to be available only within the United States, and the unpaid tier explicitly excludes EU end users entirely. | Not applicable to the free consumer Meta AI product — no processor relationship exists. For the Model API's Paid Services, yes: governed by Meta's standard 'Meta Global Processor Terms,' incorporated by reference, which also states Meta will not use Paid Services content to train its models. The Unpaid Services carry no DPA protection. Not applicable to Llama open-weight downloads, which involve no processing relationship with Meta at all. | Unverified / Non-signatory | View Dossier → |
| Mistral AI | Le Chat / Vibe (Free, Vibe Pro, Vibe Student): yes, by default, unless the user opts out — 'we do not use Your Data to train our...models except when you use Mistral AI Products under a free subscription, or are subscribed to Vibe Pro or Vibe Student, and you have not opted out of training.' La Plateforme (API): no by default for standard paid use; training does apply to free-tier API use and to explicitly opt-in 'Labs Models' unless zero data retention is active. | Le Chat / Vibe: inputs and outputs kept until the user deletes the conversation or the account. La Plateforme (standard API): 30 rolling days for abuse monitoring, unless zero data retention is activated. Account/identity data tied to KYC-type checks: retained 5 years after account termination. | EU providers are prioritized but not absolute or guaranteed across every data flow — Mistral's Privacy Policy states it prefers EU-based, GDPR-compliant providers but reserves the right to use non-EU providers 'in exceptional cases,' and its DPA permits transfers under EU-adequacy decisions or standard contractual clauses. Primary inference/compute is EU-based (CoreWeave EEA, Mistral Compute France) for all products, but some ancillary sub-processors (a Google US API endpoint, Blackforest Labs, Brave, Stripe) are US-based. Applies broadly to storage and processing; no separate inference-only residency claim was found. | Yes, published and self-serve with no login gate, incorporated by reference into the Commercial Terms of Service. Applies to commercial/API customers acting as controllers; not clearly applicable to individual Le Chat / Vibe consumer use, where Mistral itself is the controller. | Code of Practice Signatory | View Dossier → |
| Moonshot AI (Kimi) | Consumer Kimi Chat (Web/App): yes, processed for service improvement by default. Moonshot API: no, off by default for paid commercial API calls per platform terms. | Consumer: retained until deleted by user; API: 30 rolling days for abuse monitoring unless custom retention terms apply. | Mainland China data centers for domestic infrastructure; Singapore / cloud nodes for international API traffic | Unverified — standard GDPR Art. 28 DPA not published for self-serve consumer or API tiers | Unverified / Non-signatory | View Dossier → |
| OpenAI | Consumer ChatGPT (Free/Plus/Pro): yes, by default, via the 'Improve the model for everyone' setting. API, ChatGPT Business, Enterprise, Edu and Healthcare: no, off by default — OpenAI's Services Agreement states it will not use customer content to develop or improve its models unless the customer explicitly opts in. | Consumer: content kept until deleted; deleted data purged from systems within 30 days; Temporary Chats auto-delete after 30 days. Business/Enterprise/Edu/Healthcare: admin-controlled, deleted conversations purged within 30 days. API: inputs/outputs retained up to 30 days by default for abuse monitoring; Zero Data Retention (ZDR) available for eligible endpoints. | Yes. EEA data residency now covers in-region GPU inference as well as storage, for eligible ChatGPT Enterprise, Edu and Healthcare customers (expanded 16 Jan 2026 from a storage-only offering). API residency is sales-gated at project level, not retroactive to existing projects, and uses zero data retention for in-region requests. | Yes, self-serve for Business, Enterprise, API, and Edu/Healthcare (a separate Student Data Privacy Agreement variant applies to Edu/Teachers). Signed with OpenAI OpCo, LLC or OpenAI Ireland Ltd depending on customer location. Not applicable to individual consumer ChatGPT use. | Code of Practice Signatory | View Dossier → |