HomeFree Tools › AI Vendor Terms Compared

AI Vendor Terms Compared

What the major AI providers actually publish about training on your data, how long they keep it, how much notice you get before a price rise, and who you are really contracting with. Free, no login, and every table carries the date it was checked.

Last reviewed 18 September 2026

Most AI procurement reviews the rate card. Almost none reviews the terms sitting behind it — and those terms differ between providers far more than the prices do. Worse, they change when a vendor edits a web page, with no email and no announcement.

This page collects the published answers to the five questions that come up most often, side by side. Where a section number exists we cite it, so you can open the vendor's own document and check us.

What this page is, and what it is not. It reports what vendors publish in their own terms, pricing pages and documentation, with the date each item was read. It is not legal advice, not a recommendation about any specific agreement, and not a substitute for reading the contract in front of you. Terms change without notice — re-verify anything here before a live negotiation.
Question one

Does the vendor train on your data by default?

The answer most buyers assume is "no, obviously." It is not universal — two of the six below train by default unless you change a setting.

ProviderTrains on API data by defaultHow you obtain zero data retention
OpenAINoApproval, plus additional requirements
AnthropicNoThrough sales, enabled per organization
Google Gemini APINo on paid tiers. Free tier and AI Studio usage may be human-reviewedApplication per project; no published approval timeline
MistralYes — trains by default, with an opt-out. Commercial Terms §4.2 makes the default product-dependent without naming which products, so confirm for your agreement.Written request with a stated reason, and it can be denied
CohereNot stated — Cohere documents an opt-out Data Controls toggle but does not publish that it trains by default. Confirm for your agreement.Enterprise agreement only
AWS BedrockNoA mode setting — but only for models that permit it

⚠ Verified 8 September 2026 against each provider's own published documentation. Provider terms change without announcement — re-check before relying on this.

Question two

Is "zero data retention" a setting you can switch on?

No. At every provider checked, it is a contract term with a scope — and the scope has documented holes the marketing page does not describe.

A security questionnaire asks one question and offers a checkbox. The reality has four separate mechanisms, and answering for one while assuming it covers the others is how a confident answer becomes a wrong one.

MechanismWhy it gets missed
Training useEveryone assumes "no by default" is universal across providers. See the table above — it is not.
Abuse monitoringData held so the vendor can investigate misuse. This survives most zero-retention arrangements.
Operational loggingData a feature needs in order to function. Eligibility is decided per feature, not per account.
Sub-processor retentionWhat the vendor's own vendors keep. The weakest-documented leg across every provider — nobody publishes it.

Two things that catch people out. First, eligibility is per feature, not per account. Anthropic publishes, for example, that batch jobs retain 29 days, code-execution containers 30 days, and Files API content persists until deleted; Mistral's Privacy Policy names the Agents API and the Fine-Tuning API as stateful exceptions to its thirty-day rule. A customer with a signed arrangement who turns on an agent framework or moves a workload onto batch processing to cut cost has moved data outside it — without signing anything.

Second, some models are excluded entirely. Anthropic designates certain models as Covered Models, which are unavailable under zero data retention unless expressly authorised — even for a customer holding an organization-wide arrangement. Changing a model name in a config file therefore changes the contractual position, with nothing in code review or the API response to signal it.

⚠ Verified 8 September 2026 against each provider's published documentation.

Question three

What does abuse monitoring keep, and for how long?

Ask this one separately from everything else. It is the question most likely to produce a number that contradicts the trust page.

ProviderThe exclusion that matters most
AnthropicFlagged sessions held up to two years regardless of arrangement — including under zero data retention and including under a HIPAA business associate agreement. Covered Models are unavailable under ZDR unless expressly authorized by Anthropic. This is legitimate abuse monitoring, not misconduct — but it is a scope difference between the trust page and the contract.
OpenAISafety-retention override for severe-risk investigations; API inputs and outputs may be securely retained up to 30 days, except for certain endpoints and features listed in OpenAI's platform documentation.
Google Gemini APISearch and Maps grounding retain 30 days — Google states “There is no way to disable the storage of this information.”
MistralPrivacy Policy names Agents API and Fine-Tuning API as the stateful exceptions.
CohereUsage metadata is never covered.
AWS BedrockAWS states “you always control your retention policy” — an account set to no retention has the request blocked and the model shown unavailable rather than overridden. Review is “carried out by AWS within the AWS boundary — the model provider does not review your content.”

⚠ Verified 8 September 2026. This is legitimate abuse monitoring, not misconduct — but it is a gap between the trust page and the contract, and it is the reason a healthcare questionnaire answered "zero retention" may have been answered wrongly.

Question four

How much notice do you get before a price change?

Every procurement reviews the rate card. Almost none reviews the clause governing what the vendor must do before that rate card moves.

VendorWhere the clause livesStated notice
OpenAIServices Agreement §6.614 days after posting on the Pricing Page
AnthropicCommercial Terms §H.130 days after posting, or when the customer otherwise receives notice — whichever is earlier
GoogleGemini API Additional Terms30 days after posting; new paid services can take effect immediately

⚠ Clause text pulled 14 August 2026. Section numbers cited so you can check them yourself.

Withdrawn 18 September 2026 — DeepSeek. This table previously carried a row describing DeepSeek's price-change notice. We were unable to re-retrieve the source page to confirm it, so the row has been removed rather than left standing. It will return when the page has been read and captured.

Read the trigger carefully: "after they are posted." The clock does not start when the vendor tells you. It starts when the vendor edits a web page. If nobody on your side is watching that page, a full 30-day notice period can pass without a single person at your company seeing it.

The same structure governs model deprecation and rate limits at most providers. Three clause families, one root pattern: the vendor's obligation is discharged by publishing, not by communicating.

Question five

If you buy through a platform, who are you actually contracting with?

Not necessarily the platform. On some platforms the answer is set per model, on the same account.

Withdrawn 18 September 2026. This section previously set out, in a per-model table, which model families on one cloud platform are sold by the platform and which are sold by the model provider, quoting that platform's legal page directly. We could not re-retrieve that page to confirm the quotations, so the table has been removed rather than left standing on an unverified reading. It will return when the page has been read and captured. The general point below stands on its own and names no vendor.

The structural point, which is worth knowing whichever platform you use. Buying a model through a cloud marketplace does not automatically put the cloud provider between you and the model's maker. Depending on how the platform has papered each model, you may be agreeing to the model provider's own terms in full — its indemnification, its liability cap, its governing law — with the platform acting only as the storefront. Switching a workload from one model to another can therefore move your counterparty, and nothing in a code review will flag it.

Two questions are worth holding apart, because buyers routinely merge them. Who is my counterparty can be changed by contract language alone. Where does my data actually go changes only if the technical path changes. A contract can change who you sue. It cannot change what a vendor's systems do.

The question to put to any platform you buy models through: for each model we actually use, who is the seller of record, and whose terms govern — yours, or the model provider's? Ask it per model, and ask for it in writing.

Methodology

How this page is maintained

Primary sources only

Every entry comes from the vendor's own terms, pricing page or documentation — not from a summary, a review site or a press report. Section numbers cited where they exist.

Dated, not asserted

Each table carries the date it was read. Treat anything older than about sixty days as needing a re-check before a live negotiation.

Corrections published

When something here turns out to be wrong, the correction is published with a date on it. Nothing is quietly edited after the fact.

These change without an announcement

This page is a snapshot. Terms Watch is the weekly diff — what moved, and what it means for an agreement you have already signed. Free, one email a week.

Have us review a contract before you sign →