Context
Founder pushback (2026-09-06 22:14 ET): "I'm not sure we should shackle the OpenAI and grok models like that. It should be able to read the vault. We do want these agents to have the same infrastructure you do. When we create a subagent they aren't limited."
Question asked back and answered directly: "What do you make of their privacy policies? How is it different than your own? Should I be giving any of this information to any of these companies?"
Scope: the account types actually in use, not the enterprise/API zero-data-retention tiers — Claude Max (this session), personal ChatGPT via auth_mode: chatgpt (Sol/codex CLI), personal X/xAI login (Grok CLI).
Findings
Anthropic — Claude Max + Claude Code
- Trains on consumer data by default since the Aug 28, 2025 Consumer Terms update (reversed prior no-training stance). Opt-out: claude.ai/settings/data-privacy-controls → "Help improve Claude" → off.
- Retention: 5 years if training on, 30 days if off.
- Claude Code has its own opt-in-by-action channels (
/feedback,/bug,/share) —/feedbackuploads don't redact source code. - Controversy: Reddit lawsuit (unauthorized scraping incl. deleted posts, in mediation); $1.5B author/publisher copyright settlement.
- Sources: anthropic.com/news/updates-to-our-consumer-terms · code.claude.com/docs/en/data-usage
OpenAI — personal ChatGPT + Codex CLI (Sol)
auth_mode: chatgpt= personal plan (Free/Plus/Pro), not API/Enterprise. Training on by default.- TWO independent opt-out toggles: ChatGPT-wide (Data Controls) and Codex-specific (Codex Settings, "full environments" training) — turning off one does not turn off the other.
- Retention: ≤30 days for abuse monitoring normally. BUT: a May 2025 federal court preservation order (NYT v. OpenAI) forced indefinite retention of all ChatGPT/API logs, overriding user deletion, upheld on appeal June 2025, reportedly lifted ~Sept 26 2025. Real demonstration that policy retention promises don't survive litigation.
- No specific carve-out found for health/financial/minors' data beyond general privacy policy.
- Sources: help.openai.com articles 11369540, 5722486, 20001275, 7730893 · openai.com/index/response-to-nyt-data-demands · terms.law analysis
xAI — personal Grok account + Grok CLI ("Grok Build")
- Training-by-default status unclear/conflicting in secondary sources (some say off-by-default now); could not load x.ai/legal/privacy-policy directly (403 to fetch) to resolve from primary source.
- Independently verified concrete finding: security researcher (Cereblab) intercepted Grok Build v0.2.93 CLI traffic via mitmproxy — the CLI uploads full repo contents including unredacted .env files with API keys/DB passwords to an undisclosed Google Cloud Storage bucket (
grok-code-session-traces), ~27,800x more data than the immediate task needed (5.10GB uploaded vs ~192KB actually processed, across 82 requests on a 12GB test repo). This occurred independent of privacy toggle state. - Regulatory: Irish DPC formal inquiry, EU DSA/UK ICO/Ofcom/Canada/Brazil/France actions, FTC 6(b) order (Sept 2025).
- Litigation: March 2026 class action (N.D. Cal.) alleging Grok trained on CSAM using real victims' photos; March 2026 Amsterdam injunction against non-consensual sexualized deepfakes with €100k/day fines.
- Source for the CLI finding: developersdigest.tech/blog/grok-cli-wire-level-analysis (primary technical writeup)
Verdict delivered to founder
Grok CLI: categorical no on vault access — documented credential-exfiltration behavior independent of settings, not a policy-language concern.
Sol (Codex/ChatGPT): stay cautious — workable only with both training toggles off, and even then the 2025 court-order precedent shows retention promises aren't absolute once litigation hits.
Same-vendor trust extended to Claude subagents doesn't transfer to Sol/Grok — the reasoning isn't about intent, it's about independently observed behavior (Grok) and structural risk (both).
Open: awaiting founder's actual decision on whether/how to adjust the ask-model.sh sandbox. No sandbox change made as of this writing.