Monthly AI Privacy Policy Change Watch: Review for 4 September 2026

A dated review of published privacy-policy changes for OpenAI, Microsoft Copilot, Google Gemini, and Anthropic Claude, separating page dates, effective dates, account scope, product scope, and region.

Quick answer

For each monthly review, record four separate fields: page date, effective date, account or product and region in scope, and the practical change involving training, human review, retention, or connected apps. In the 4 September 2026 edition: OpenAI is updated 25 August 2026 and covers users outside the EEA, UK, and Switzerland; Microsoft is updated July 2026; Gemini conversation details concern Gemini Apps and Keep Activity; and Anthropic’s update was published 8 June 2026 and effective 8 July 2026, while the five-year rule dates to 28 September 2025.

These signals were reviewed on 4 September 2026. That date matters because privacy policies change, and “current” should not be read as a promise that wording will remain unchanged. This article does not label any service safe and does not provide an endorsement. Instead, it offers a monthly watch structure that separates four fields: the page date, the effective date, the account or product and region in scope, and the practical change involving training, human review, retention, or connected apps.

The review uses the policy and privacy-centre pages linked below. Where a general policy differs from a product-specific explanation, the distinction is stated. Any suggestion about how to organise the watch or reduce the data sent is this article’s editorial recommendation, not a sourced fact about how a service performs.

How to read a monthly change record

Start with the date shown on the page, rather than only the date when you found it. Then record an effective date if the source gives one. Next identify the account, product, and region covered by the text. Finally, describe the practical change in limited terms: does it concern model improvement, human review, retention, or connected apps? This separation reduces the risk of applying a consumer rule to a work account, or assigning an older retention rule to a newer update.

  1. Page date or last-updated date.
  2. Effective date, when it is separate.
  3. Eligible account, product, and region.
  4. Practical effect on training, review, retention, or connected apps.

These four fields are the monthly tracking template recommended by this article. OpenAI’s privacy policy supports the need to record scope and timing separately, but the template itself is an editorial structure, not a feature supplied by a provider. Source: OpenAI Privacy Policy

OpenAI: a dated version with a defined regional scope

OpenAI’s Privacy Policy shows an update date of 25 August 2026. This version applies to users outside the European Economic Area, the United Kingdom, and Switzerland. It can therefore be described as the version relevant to users in the United States, while preserving the source’s stated scope rather than turning it into a worldwide rule. Source: OpenAI Privacy Policy

The policy says that content from customers of business offerings, such as the API, is not covered by this policy and is instead covered by customer agreements. A paragraph about consumer content should therefore not be applied automatically to business-customer content or to the API. This account-and-product distinction is an editorial checkpoint to revisit each month. Source: OpenAI Privacy Policy

The page also states that user content may be used to improve services and train models, subject to available settings and opt-out choices. It says that Temporary Chat does not appear in history and is not used to improve models under the conditions described on the page. These details may change the “practical effect” field in a monthly record, but they do not support saying that a setting prevents data leakage. Source: OpenAI Privacy Policy

Microsoft and Copilot: do not generalise the consumer description

Microsoft’s Privacy Statement displays Last Updated: July 2026, not June 2026. Source: Microsoft Privacy Statement

In its artificial intelligence and Copilot section, the relevant description concerns the consumer Copilot experience when the user is signed in with a personal Microsoft account, and the Copilot website or app on the web, desktop, and mobile. The wording should not be generalised to work or school accounts or to organisational products, which are covered by different sections and terms. Source: Microsoft Privacy Statement

The page states that prompts and associated data may be used to provide and improve the service, and that conversation data may help train artificial-intelligence models in some markets unless the user opts out. The market and account should therefore be recorded before summarising the effect. The more accurate wording is not “all Copilot conversations are used for training,” but the narrower description supplied by the page: a consumer experience, a personal account, some markets, and an opt-out as described by Microsoft. Source: Microsoft Privacy Statement

Google and Gemini: separate the general policy from Gemini Apps

Google’s general Privacy Policy says that publicly available information may be used to help train Google’s models and build products such as Gemini Apps. That statement alone should not be presented as evidence about how Gemini conversations are used; the product-specific source is needed for that question. Source: Google Privacy Policy

The scope of Gemini conversations and the Keep Activity setting is described in the Gemini Apps Privacy Hub. When Keep Activity is on, conversations and activity are saved and used to provide, develop, and improve services, including training artificial-intelligence models. A sample of conversations may also be reviewed by humans. These details concern Gemini Apps, the relevant settings, and the relevant region; they should not automatically be extended to every Google service or every Gemini product. Source: Gemini Apps Privacy Hub

The page says that auto-delete can be set to 3, 18, or 36 months, or turned off. Conversations reviewed by human reviewers may be retained for up to 3 years. When Keep Activity is off, future conversations are not used to train Google’s models unless the user submits feedback, but they may be retained for up to 72 hours for service delivery, protection, and feedback processing. These choices should not be turned into a promise of no retention or a claim that they prevent data leakage. Source: Gemini Apps Privacy Hub

Anthropic and Claude: page date is not effective date

Anthropic’s policy-change page is dated 8 June 2026 and describes a consumer-policy update effective on 8 July 2026. The update applies only to Claude Free, Pro, and Max accounts. It does not apply to Team, Enterprise, Claude Developer Platform, or services covered by other commercial agreements. Source: Anthropic Privacy Policy Updates

The described changes clarify data handling for multi-step tasks and connected apps, age or identity verification data, participation in studies, and certain sharing practices and legal bases. A monthly record should keep these topics in the practical-change field and should not transfer them to plans or platforms excluded from the update. Source: Anthropic Privacy Policy Updates

This must be separated in time from the five-year retention rule. The change log attributes that rule to the update effective 28 September 2025, when use of user data to improve Claude was allowed; it is therefore not accurate to say that the five-year rule was added in the July 2026 update. Anthropic’s current retention page also explains that data may be retained in de-identified form for up to five years when users allow conversations or coding sessions to be used to improve Claude. Source for the rule’s date: Anthropic change log Source for retention details: Anthropic Privacy Center

A practical pre-publication checklist

The following is an editorial audit tool recommended by this article; it is not a guarantee that a review is complete or that any account setting has a particular result:

  • Fix the review date: 4 September 2026 for this edition.
  • Record the page date exactly as displayed, rather than replacing it with the discovery date.
  • Separate the effective date from the publication or update date.
  • Identify the account type, plan, product, and region.
  • Separate a general policy from the privacy hub for the specific product.
  • Record training, human review, retention, and connected apps as separate fields.
  • Check whether a retention rule predates the update being reviewed.
  • Remove any wording that calls a service “safe” or claims that a setting prevents data leakage.

Conclusion

In this review, the key difference is not between “good” and “bad” services, but between texts with different dates and scopes. The OpenAI version reviewed here is dated 25 August 2026 and has a defined regional scope. Microsoft’s statement is updated in July 2026, while the Copilot description concerns a consumer experience with a personal account. Google requires a separation between its general policy and the Gemini Apps Privacy Hub. Anthropic requires the page date of 8 June 2026, the effective date of 8 July 2026, and a separate record for the five-year rule tied to 28 September 2025. This article does not endorse any service and does not infer that a particular setting removes the risks of sharing data with a service or connected parties.

Monthly monitoring checklist

Sources

  1. Privacy policy | OpenAIPrimary source
  2. Microsoft Privacy StatementPrimary source
  3. Privacy Policy – Privacy & Terms – GooglePrimary source
  4. Gemini Apps Privacy HubPrimary source
  5. Updates to our Privacy Policy | Anthropic Privacy CenterPrimary source
  6. How long do you store my data? | Anthropic Privacy CenterPrimary source

How this article was made

This article was rewritten with AI assistance from the supplied research and sources, with checks for timeline and claim-scope consistency.

Was this guide useful?

Ask Mafate7

Send an article comment or question. Nothing appears before moderation; email is optional and never displayed.