What to Check Before You Trust Claude With Your Business

Time to read: about 8 minutes

Claude, Privacy, Security, and Safety: What to Worry About (and What Not To)

Somebody DM’d me on Instagram back in July after seeing something I’d built in Claude. Just one word: “whoa.”

Then, the next morning: “I just got Claude today. I have no clue where to start. How did you learn it — just trial and error?” There was a little photo attached of handwritten notes on a notepad, like she’d already started trying to figure it out on paper before she’d even opened the app.

I wrote back something like: “we have a couple of years of trial and error (sooooo freaking much of it) under our belt at this point, but the first thing you need to do is brief it on who you are.” Told her to set up a project, get it asking her questions, iterate on everything.

What I didn’t say — because she didn’t ask, and most people don’t ask until something spooks them — is anything about privacy or safety.

And that’s usually where the second DM comes in. Not “how do I use this,” but “wait, is this safe?” Sometimes it’s a client on a discovery call who’s already halfway through downloading it and stops. Sometimes it’s someone who read a Reddit thread at midnight and closed the tab.

In a nutshell

Your private Claude chats aren’t floating around the internet — the “leaked chats” stories you’ve read were people who generated public share links on purpose, not private conversations getting exposed. That part, you can relax about.

BUT. Since August 2025, Claude’s free, Pro, and Max plans train on your conversations by default unless you turn it off yourself (Settings → Privacy → “Help improve Claude”).

Turn it off and you’re back to a 30-day retention window with no training. Business, Team, and API accounts are excluded from default training regardless.

One more thing to know: skills you install from strangers on GitHub carry real risk — a recent security scan found roughly a third of publicly shared skills had at least one security flaw. Read before you install.

And the oldest rule still applies: don’t put anything in front of Claude — or any AI — you wouldn’t want read back to you by a lawyer in a courtroom.

What’s in this post

The fear that isn’t the real risk

Here’s the one that shows up most: “Is my chat going to leak?” Somebody’s client saw a headline about ChatGPT or Claude conversations showing up in a Google search, and now they’re picturing their whole client list sitting out in the open for anyone to stumble on.

Those stories are almost always about people who hit “share,” generated a public link, and that link got indexed somewhere. It still shouldn’t have happened the way it did — but it’s not a leak in the sense of “your private stuff got out.”

It’s closer to posting something on a public Instagram account and being surprised someone saw it. You don’t trip over that by accident. You do it on purpose, even if you didn’t realize what “share” meant when you clicked it.

So: your day-to-day chat with Claude isn’t sitting somewhere waiting to be found. That part isn’t the thing to lose sleep over.

The one you could worry about, if you wanted

Since August 2025, Claude’s consumer plans — Free, Pro, and Max — train on new conversations by default. Not “if you opt in.” By default, unless you go turn it off. It lives in Settings → Privacy → “Help improve Claude”.

Off means a 30-day retention window and nothing gets used for training. On means Anthropic can hang onto a de-identified version of your conversation for up to five years to help improve future models.

(Business, Team, and API accounts are excluded from that by default — good to know if you’re running a company account versus a personal one.) Anthropic’s own announcement is worded plainly if you want to read it straight from the source.

I’m not going to tell you which setting to pick — that’s a “you” decision, not a “me” one. But I will tell you: go check it. Right now, before you finish reading this, if you haven’t already. It takes about ten seconds.

To be clear, this isn’t a Claude-specific problem — it’s the industry standard now. Most consumer AI tools work this way. Claude’s version is at least easy to find and easy to turn off, which is more than I can say for some of the alternatives.

Giving Claude access to your computer

This is where it stops being “just a chat” and starts being a different conversation — Cowork, Claude Code, anything where you’re handing Claude access to files on your own machine instead of just talking to it in a browser tab.

It’s going to ask you to allow, allow, allow — over and over, every time it wants to touch something. Read those. I know it feels like the terms-and-conditions scroll you click through without looking, but this one’s asking you something specific each time, not just covering someone’s legal bases.

There’s a note sitting in my own content bank from exactly this: “Security tip — just really actually read the thing before you agree, especially in Cowork. You might not have to give all the permissions.” Scope it to the folder it needs, not your whole desktop.

I use an app called Little Bird that records everything I do on my computer. (I KNOW. GASP.) If I’m about to type in a credit card number, I hit pause. Do I know it paused? No. Not really.

That’s a risk I’m choosing to take, with my eyes open, because I’ve decided the trade-off makes sense for me. Same logic with anything you give folder or screen access to — the two-factor code that pops up on your iPhone also shows up on your Mac if they’re linked. That’s access you granted somewhere along the way, whether you clocked it at the time or not.

None of this means don’t use it. It means: know what you’re saying yes to when you click yes.

Skills from people you’ve never met

If you’ve gotten into building or installing skills (little instruction files that customize how Claude behaves for you), here’s the one that isn’t a maybe. If you download a skill from GitHub or some rando’s link with no idea who built it, there’s a real chance something malicious is baked in.

A security scan of publicly shared AI skills earlier this year found that just over a third had at least one security flaw — some as serious as credential theft — and that’s not a “maybe don’t” situation, that’s a “look before you install, every time” one.

What I do: I don’t install other people’s skills. I go read the actual file with my own eyes, figure out what it’s doing, and build my own version of the pieces I want. That’s partly because I’m a nerd about customizing things, but it’s also just the safer move.

If you don’t want to reverse-engineer your own version, fair. So here’s the shortcut. Paste this into Claude before you install anything from a source you don’t know:

“Read this skill file and tell me, in plain English, exactly what it’s set up to do — what it reads, what it writes, what it connects to outside itself. Flag anything that reaches further than what it claims to be for. Don’t soften it for me if something looks off.”

Takes thirty seconds. Beats finding out the hard way.

The line that never moves

For business use specifically — talking to clients, running your business through it — here’s the actual test I use, and it hasn’t changed since long before AI showed up: don’t put in anything you wouldn’t want read back to you by a lawyer in a courtroom. Financial numbers, anything truly confidential, that’s the stuff to keep out or keep vague.

My own marketing strategy, my voice, my plans? I’m loose about that. I don’t care if it’s public knowledge that I want to get rid of the watermarks on my countertop, or I’m looking for a better business bank account, or I’m researching used roof racks for my car, or that I want a dupe for the Air Pro black crystal air freshener you can’t get in Canada for some reason. If it came out that I want to grow to a certain size (which — for the record — isn’t even accurate), the world keeps turning.

There’s a version of this that’s oddly like talking to another person. You don’t get an ironclad guarantee of confidentiality there either — there actually isn’t, usually… unless it’s a therapist or your doctor, and with AI tools it’s closer to “massive amounts of data, and you are one very small part of it” than an actual promise.

You’re already using AI, for the record

I read an analogy recently that I loved: using an LLM well is like using a calculator for English. I can’t do long division anymore — I’m a homeschooling mom who just taught grade 3 math, so I could, technically, but the calculator does it faster and I don’t need to.

What I do need is to understand how it works underneath, well enough to know when it’s wrong. That’s the actual skill. Not “can you do the math,” but “do you understand the math enough to catch it when the answer’s off.”

And if you think you’re opting out of all this by not using Claude — you’re not, really. You’re already using AI in about five places without calling it that:

  • Spotify or Apple Music deciding what plays next
  • Your bank flagging a weird charge on your card
  • Autocorrect and predictive text
  • Google Maps recalculating your ETA
  • That little box under your Google search results where you can keep asking follow-up questions

That last one’s the big tell. Google’s rolling that out for everyone, and within six months, following up on a search is going to feel completely normal — which is, functionally, exactly what talking to an LLM looks like. So the honest question was never “should I use AI.” You already do.

FAQ

Is my Claude chat private, or can it show up somewhere public? Private chats stay private. The stories about leaked AI conversations are almost always about someone generating a public share link on purpose — not private chats being exposed without anyone’s knowledge.

Does Claude train on my conversations? By default, yes, on Free, Pro, and Max consumer plans, since August 2025. You can turn it off in Settings → Privacy → “Help improve Claude.” Off means 30-day retention and no training use. Business, Team, and API accounts are excluded from default training.

Is it safe to give Claude (or Cowork) access to my computer files? It’s safe if you scope it — give it access to the specific folder it needs, not your whole desktop, and read the permission prompts instead of clicking through them.

Are skills from GitHub or third-party sites safe to install? Not automatically. A recent scan of publicly shared AI skills found roughly a third had at least one security flaw. Read the file before installing, or ask Claude to summarize what it does first.

What should I never put into an AI chat for my business? Financial data, anything truly confidential, anything you wouldn’t want read aloud in a courtroom. Your marketing strategy or voice is a much lower-stakes call — that one’s up to how private you personally want to hold it.

The short version

Private chats aren’t leaking on their own — that fear’s overblown. The training setting really is opt-out by default, and that’s ten seconds of your time, go check it.

Cowork and Claude Code need folder-scoped access and permissions you read for real. Skills from strangers need a look before install, not blind trust. And the old rule holds: nothing goes in that you wouldn’t want read back by a lawyer.

Everything else — your voice, your strategy, your day-to-day — that’s a personal call.


Liked this? I send a short email every couple of weeks — a real story (recent lowlights include a golf cart incident I’m not fully ready to discuss) plus one useful thing about your website or marketing. Never longer than your coffee. Come hang out →

Doreen is the founder of Knap Creative, where she builds websites and custom Claude assistants for established service businesses. She is, by her own admission, a certified Claude Goblin.