Q16 Frontier Watch

AI Model Privacy Ratings

The frontier labs’ own consumer apps (ChatGPT, Claude, Gemini, Grok, and others), scored on the six-dimension privacy rubric. Higher is more private. Methodology →

15.3
Anthropic — Claude
Policy-based

Consumer-facing policy with a default opt-out training model, a no-sale commitment, and SCCs for EU transfers, but retention periods are vague, safety-flag exceptions to opt-out are broad, and no zero-retention tier exists.

D1 5.0D2 3.0D3 5.0D4 5.0D5 7.0D6 10.0
24.9
Google — Gemini
Policy-based

Broad, structured consumer policy covering data use, sharing limits, and rich user controls; silent in this excerpt on Gemini-specific training use, fixed retention periods, and explicit "no sale" language.

D1 4.5D2 4.0D3 5.0D4 3.8D5 5.0D6 9.0
34.8
OpenAI — ChatGPT
Policy-based

Opt-out training model with an in-account toggle; 30-day deletion window with broad exceptions; US-based, legally valid transfer mechanisms; data shared with unnamed vendors and marketing partners; no explicit "do not sell" statement in excerpted text; prior version linked but no detailed changelog. ⚠ CHANGE 2026-07-13: added an "Ads data" collection category for Free/Go users (ad history + interests, for advertising) — new since last scored; rescore D4/D1 accordingly.

D1 4.0D2 5.0D3 5.0D4 1.5D5 7.0D6 9.0
44.1
Alibaba — Qwen
Policy-based

Singapore-incorporated Alibaba entity; data stored in Singapore and Mainland China; training on de-identified content by default with no opt-out; retention is indefinite/need-based; no named sub-processors and no explicit no-sale commitment.

D1 2.5D2 3.5D3 5.0D4 4.0D5 7.0D6 5.0
53.9
DeepSeek
Policy-based

Chinese-controlled consumer AI with default training on user inputs (opt-out available), indefinite retention tied to account, all data stored in China, no data sales, but notable gaps: no fixed retention windows, no named sub-processors, and Chinese government-access exposure.

D1 5.0D2 0.0D3 5.0D4 4.0D5 5.0D6 5.0
63.8
xAI — Grok
Policy-based

Consumer-facing policy for xAI/Grok; training use of inputs/outputs is default with limited opt-out mechanisms; no explicit data-sale prohibition stated; retention periods vague except for two 30-day windows; API/enterprise carved out entirely.

D1 2.0D2 2.0D3 3.0D4 5.0D5 5.0D6 10.0
73.1
Meta — Meta AI
Policy-based

A broad consumer policy covering Facebook, Instagram, Messenger, and Meta AI; explicitly uses data for product improvement including AI training with limited opt-out signals; silent on concrete retention periods, no-sale commitment, and data-export rights in the extracted text.

D1 1.0D2 1.0D3 5.0D4 4.0D5 5.0D6 5.0
82.8
Moonshot — Kimi
Policy-based

Singapore-based controller; broadly consumer-facing with a no-sale pledge. Key gap: no explicit opt-out for model training — consumer data used by default under "legitimate interests" unless local law requires consent.

D1 0.0D2 0.0D3 5.0D4 5.0D5 5.0D6 5.0
91.4
Zhipu — GLM / Z.ai
Policy-based

Singapore-based consumer policy; inputs are used for model training under "legitimate interests" with no consumer opt-out; retention is account-lifetime with no fixed window; no explicit data-sale prohibition stated.

D1 0.0D2 0.0D3 1.0D4 0.0D5 7.0D6 5.0
101.2
MiniMax — Chat / Hailuo
Policy-based

Consumer-facing policy by Singapore entity Nanonoble; notable for complete silence on AI training use of inputs/outputs and on data retention periods, and for listing no named sub-processors.

D1 0.0D2 0.0D3 0.0D4 0.0D5 3.5D6 8.0

Ratings reflect each lab’s consumerproduct policy. The same labs’ API/enterprise terms are rated separately (and are typically far more protective). Confidence labels: Verified = contract/DPA · Policy-based = published policy · Inferred = deduced · Unverified = not yet assessed.