All articles
Technology

AI assistants and your financial data: what happens to an upload

What happens to a document in a chatbot depends on the plan, not the model: consumer terms may keep and train on it, commercial terms usually exclude that.

By Valued6 min read
A paper capital account statement being fed into a small desktop document scanner on a home office desk in evening light.

What happens to a capital account statement after you upload it to a chatbot depends less on the model than on the plan you are using. Under consumer terms the provider may keep the conversation for years and use it to train future models unless you have switched that off. Under commercial terms, the kind that govern business plans and API access, training on customer content is normally excluded and retention is short. As of June 2026 the same model can sit behind both. Before a financial document goes into any assistant, the question to answer is which contract it travels under.

What do the large providers say today?

The terms change often, so treat this as a snapshot and read the current pages yourself.

Anthropic announced on 28 August 2025 that users of its Free, Pro and Max plans choose whether their conversations may be used to improve its models. If they allow it, the data is retained for five years; if not, the previous 30-day retention applies. A conversation the user deletes is not used for future training. The change does not apply to services under Anthropic's commercial terms, which include Claude for Work and the API.

OpenAI offers a comparable switch in ChatGPT's data controls, named "Improve the model for everyone". Turned off, conversations stay in the history and are not used for training. Temporary chats are not used for training and are deleted from OpenAI's systems after 30 days. For its business plans OpenAI states that it does not train on customer data by default.

The pattern is the same across providers. A consumer plan is a product you pay for partly with data unless you opt out. A business plan or an API contract is a processing agreement.

Does "delete" mean deleted?

Not always, and not by the provider's decision alone. On 13 May 2025 a US court in the copyright case brought by the New York Times ordered OpenAI to preserve output logs that would otherwise have been deleted. The order covered the consumer plans and API use without a zero-retention agreement, and not ChatGPT Enterprise. The obligation to keep new logs ended on 26 September 2025. For more than four months, a chat a user had deleted was still held because a court had said so.

That case is over. The lesson is general: a retention promise is a statement about normal operation. Litigation, abuse investigations and backups are exceptions most terms name. A document that must never surface should not be uploaded to a service whose retention you do not control.

What does a financial document give away?

More than the figure you want to ask about. A capital account statement carries your name, address, often a tax number and bank details, the size of your commitment and the fund's unpublished valuations. A cap table names every co-investor and what they hold. A loan agreement contains the property, the lender and the terms.

Two things follow that have nothing to do with artificial intelligence. Some of this is other people's personal data, and you are the one passing it on. And most fund agreements and shareholders' agreements contain a confidentiality clause. Whether uploading a quarterly report to a consumer chatbot breaches it depends on the wording, but "I gave it to a third party that may store it for five years and train on it" is a weak position in any reading. Sending the same report to a processor that is contractually bound to use it only for your purpose is the ordinary case the clause allows for, like sending it to your tax adviser.

Blacking out names before uploading helps less than it seems. Text under a black box often survives in the PDF, and a commitment amount next to a fund name identifies the investor to anyone who knows the fund.

What does the EU AI Act change for you?

Little, for this question. The AI Act regulates providers and certain uses of AI systems. It entered into force on 1 August 2024. Its prohibitions have applied since 2 February 2025 and the obligations for providers of general-purpose models since 2 August 2025. The general date of application is 2 August 2026.

The part that was due on that date for high-risk systems is being postponed. Council and Parliament reached a provisional agreement on 7 May 2026, and the European Parliament adopted it on 16 June 2026 by 423 votes to 57 with 174 abstentions. Under the agreed text the rules for stand-alone high-risk systems apply from 2 December 2027 and those for AI built into regulated products from 2 August 2028; the duty to mark AI-generated content in machine-readable form moves to 2 December 2026. The Council still has to adopt the text formally before it can be published.

None of these dates decides what happens to your document. That is governed by the General Data Protection Regulation and by contract: who is the controller, whether the provider acts as a processor under an agreement in the sense of Article 28, where the data is processed, and whether you can have it erased under Article 17. The AI Act will make models better documented. It does not turn a consumer chat into a confidential one.

Questions to ask any tool before you upload

  • Under which terms is the document processed: consumer terms, or a commercial agreement with a data processing addendum?
  • Is content used to train models? If there is a setting, what is its default, and what is it set to in your account today?
  • How long is the document kept after you delete it, and which exceptions are named?
  • Where is it stored and processed, and which sub-processors see it?
  • Can staff read conversations, and in which cases?
  • Can you export everything and delete the account yourself?
  • If the tool is built on someone else's model: which provider, and under which of that provider's terms?

A vendor that takes financial documents seriously answers these on a public page. If the answers need a sales call, that is an answer too.

Where an assistant is the right tool, and where it is not

A general assistant is good at explaining a clause, checking your reading of a waterfall or drafting a question to a fund manager. For that it rarely needs the document. Paste the paragraph, leave out the names, and use a temporary chat or a plan with training switched off.

It is the wrong tool for keeping a portfolio. A chat has no memory you can audit, and next month's answer may rest on a different reading of the same PDF. We described what models read reliably and where they fail earlier this year, and built Valued around that limit: documents are read by Anthropic's Claude models through the API, under commercial terms that exclude training on the content, and no figure is booked until you have approved it. The details are on our security page. Put the same questions from the list above to us.

The step for this week takes five minutes: open the privacy settings of each assistant you use, find the training switch, and check what it is set to.

More articles

Try it with your next document.

Create a free account, upload a capital call, a cap table or a loan agreement and see for yourself what Valued makes of it. Prefer a guided tour? We show you everything in 30 minutes, with your own documents if you like.