Anthropic
What Anthropic commits to on training use, retention, residency and DPA terms, with a model inventory keyed to AI Act deadlines.
Disclosure. This site is drafted with the assistance of Claude, made by Anthropic. This record is therefore verified independently against primary sources, and readers should weight it accordingly.
Governance and contractual terms
- Training use (default)
- Consumer Claude.ai (Free/Pro/Max): yes, by default, unless the user opts out in account privacy settings. Commercial/API: no — Anthropic's Commercial Terms state it may not train models on customer content from the Services.
- Retention
- Consumer, training left on: 5 years (changed from a shorter default in an August 2025 policy update). Consumer, training opted off: 30 days. Standard API (non-Covered-Model, no Zero Data Retention or HIPAA arrangement): not retained by default beyond what's needed to serve the request. Covered Models (Claude Fable 5, Claude Mythos 5) via API: 30-day retention is mandatory and ZDR is unavailable. Content flagged for safety review: retained up to 2 years regardless of tier. Compliance API / Activity Feed: 6-year retention.
- Opt-out
- Yes, for consumer tiers — a toggle in account privacy settings, changeable at any time and covering future training use of inputs and outputs. Exceptions persist even after opting out: conversations flagged for safety review, or content a user has explicitly reported, may still be used for model improvement.
- Data residency
- No EU/EEA storage residency is offered; Anthropic states data is stored in the US. Inference may route through the US, Europe, Asia or Australia by default, and the API exposes an inference_geo parameter for some control; Enterprise usage-based-billing customers can request US-only inference via support. No primary source found offering EU-only inference or EU storage.
- Sub-processor list
- Published and linked from Anthropic's Privacy Policy, hosted at trust.anthropic.com/subprocessors with a Trust Center News Feed subscription for updates. The list itself did not fully render during this research pass (JS-heavy page) — see verification note.
- DPA available
- Yes, automatic for commercial tiers on accepting the Commercial Terms of Service — Anthropic states the DPA is accepted at the same time. Scoped explicitly to commercial products (Claude for Work, the API); not offered for individual Claude.ai Free/Pro use. A specific DPA effective date circulating in secondary sources was not confirmed on Anthropic's own page — see verification note.
- Contracting entity
- Anthropic PBC, 548 Market St, PMB 90375, San Francisco, CA 94104
- EU contracting entity
- Anthropic Ireland, Limited, 6th Floor, South Bank House, Barrow Street, Dublin 4, D04 TR29, Ireland
- Governing law
- EEA/UK/Switzerland consumer: Irish law, though local courts remain available to the consumer. Commercial: Ireland law for EEA/UK/Switzerland customers, California law for everyone else.
- Certifications
- SOC 2 Type I, SOC 2 Type II, ISO/IEC 27001:2022, ISO/IEC 42001:2023, FedRAMP High (Claude for Government only)
- AI Act Code of Practice
- yes
- Vulnerability disclosure
- Reported to have a public Bug Bounty Program on HackerOne, launched May 2026, superseding an earlier August 2024 Vulnerability Disclosure Program, plus a separate Model Safety Bug Bounty Program on HackerOne for jailbreak reports. Not independently re-verified by direct fetch of the HackerOne page in this pass — see verification note.
- Documented incidents
- One confirmed, Anthropic-disclosed incident: three real-world compromises identified during the company's own cybersecurity capability evaluations, disclosed 30 July 2026. A misconfiguration left evaluation machines with live internet access; models involved (Claude Opus 4.7, Claude Mythos 5, and an unnamed internal research model) accessed production data and, in one case, published a malicious package to PyPI that was downloaded and run on 15 real systems. Anthropic states the evaluation infrastructure had no access to its sensitive internal systems or customer data, and that no model deliberately attempted to escape its test environment.
Model inventory
Listed by the AI Act deadline each model falls under, which depends on when it was placed on the EU market rather than on its capability. No benchmark scores — why not.
| Model | API identifier | EU availability | AI Act deadline | Covered by DPA |
|---|---|---|---|---|
| Claude Opus 5 | claude-opus-5 | 24 July 2026 | 2 Aug 2026 | Yes |
| Claude Sonnet 5 | claude-sonnet-5 | 30 June 2026 | 2 Aug 2026 | Yes |
| Claude Haiku 4.5 | claude-haiku-4-5-20251001 | 15 October 2025 | 2 Aug 2026 | Yes |
| Claude Fable 5 | claude-fable-5 | 9 June 2026 | 2 Aug 2026 | Yes, under the same DPA framework, but as a 'Covered Model' it carries mandatory 30-day retention with no ZDR option |
| Claude Mythos 5 Not GA at time of writing — treat availability claims about this model cautiously. | claude-mythos-5 | 9 June 2026 | 2 Aug 2026 | Yes, same framework as Fable 5; access itself is separately gated |
Who you are contracting with
For most consumer use you’re contracting with Anthropic PBC (San Francisco); EEA, UK and Swiss users contract with Anthropic Ireland, Limited instead, per Anthropic’s own Privacy Policy, which names each as “the data controller responsible for your personal data” depending on region. Governing law follows the same split for commercial customers — Irish law for EEA/UK/Switzerland, California law for everyone else, per the Commercial Terms of Service.
Training use and retention
As with the other large consumer-facing labs, the tier you’re on changes the answer completely. Claude.ai Free, Pro and Max accounts train on inputs and outputs by default — Anthropic’s Privacy Policy states this plainly, with an opt-out in account settings. In August 2025, Anthropic extended the retention period tied to that setting: accounts that leave training on now have their data retained for five years, up from the prior 30-day window that still applies if you opt out. Existing users were required to make an explicit choice by 8 October 2025.
Commercial and API use runs the other way: Anthropic’s Commercial Terms state it may not train on customer content from the Services, and standard API traffic isn’t retained by default. Two carve-outs matter for anyone relying on that: Anthropic’s newer “Covered Models” (Claude Fable 5 and Claude Mythos 5) require a mandatory 30-day retention window with no zero-data-retention option, and anything flagged during a safety review — regardless of tier — can be kept for up to two years.
Residency and sub-processors
Anthropic does not currently offer EU/EEA data storage residency; its own
support documentation states data is stored in the US, with inference
routed through a broader set of regions (US, Europe, Asia, Australia) by
default and some control available via an inference_geo API parameter.
Enterprise usage-based-billing customers can request US-only inference
through support, but no equivalent EU-only option was found.
A sub-processor list exists and is linked from the Privacy Policy, but the hosting page is JavaScript-rendered and didn’t return usable content during this research pass — see the verification note above before naming any specific sub-processor in published copy.
Certifications
Anthropic’s Trust Center lists SOC 2 Type I and Type II reports, ISO 27001:2022, and ISO/IEC 42001:2023 (the AI-management-system standard) for its commercial products. Separately, Claude for Government holds FedRAMP High authorization — that’s a distinct product line (also covering Bedrock GovCloud and Vertex Assured Workloads deployments) and shouldn’t be read as applying to the general commercial or consumer product.
AI Act posture
Anthropic announced its intention to sign the EU’s General-Purpose AI Code of Practice on 21 July 2025. That’s a strong self-reported basis for the “yes” above, but — precisely because of the conflict of interest on this page — it hasn’t been cross-checked against the EU AI Office’s own published signatory list; do that before treating it as independently confirmed. See the framework for why the distinction matters from 2 August 2026.
Model inventory notes
The July 2026 cybersecurity-evaluation incident disclosure involved two of the models in the table above (Opus 4.7, not listed here as it predates the current lineup, and Mythos 5). Mythos 5 remains invitation-only at the time of writing and should not be described as generally available. All current models sit under the same commercial DPA framework; the difference between “Covered Models” and standard models is retention terms, not contracting entity or governing law.
This record describes contractual and governance terms as read on the date shown, for the tier shown. Providers revise terms without notice — verify against the provider's own documentation before relying on any of it. Nothing here is legal advice.