Q16 Frontier Watch
AI Model Privacy Ratings
The frontier labs’ own consumer apps (ChatGPT, Claude, Gemini, Grok, and others), scored on the six-dimension privacy rubric. Higher is more private. Methodology →
Consumer-facing policy with a default opt-out training model, a no-sale commitment, and SCCs for EU transfers, but retention periods are vague, safety-flag exceptions to opt-out are broad, and no zero-retention tier exists.
Broad, structured consumer policy covering data use, sharing limits, and rich user controls; silent in this excerpt on Gemini-specific training use, fixed retention periods, and explicit "no sale" language.
Opt-out training model with an in-account toggle; 30-day deletion window with broad exceptions; US-based, legally valid transfer mechanisms; data shared with unnamed vendors and marketing partners; no explicit "do not sell" statement in excerpted text; prior version linked but no detailed changelog. ⚠ CHANGE 2026-07-13: added an "Ads data" collection category for Free/Go users (ad history + interests, for advertising) — new since last scored; rescore D4/D1 accordingly.
Singapore-incorporated Alibaba entity; data stored in Singapore and Mainland China; training on de-identified content by default with no opt-out; retention is indefinite/need-based; no named sub-processors and no explicit no-sale commitment.
Chinese-controlled consumer AI with default training on user inputs (opt-out available), indefinite retention tied to account, all data stored in China, no data sales, but notable gaps: no fixed retention windows, no named sub-processors, and Chinese government-access exposure.
Consumer-facing policy for xAI/Grok; training use of inputs/outputs is default with limited opt-out mechanisms; no explicit data-sale prohibition stated; retention periods vague except for two 30-day windows; API/enterprise carved out entirely.
A broad consumer policy covering Facebook, Instagram, Messenger, and Meta AI; explicitly uses data for product improvement including AI training with limited opt-out signals; silent on concrete retention periods, no-sale commitment, and data-export rights in the extracted text.
Singapore-based controller; broadly consumer-facing with a no-sale pledge. Key gap: no explicit opt-out for model training — consumer data used by default under "legitimate interests" unless local law requires consent.
Singapore-based consumer policy; inputs are used for model training under "legitimate interests" with no consumer opt-out; retention is account-lifetime with no fixed window; no explicit data-sale prohibition stated.
Consumer-facing policy by Singapore entity Nanonoble; notable for complete silence on AI training use of inputs/outputs and on data retention periods, and for listing no named sub-processors.
Ratings reflect each lab’s consumerproduct policy. The same labs’ API/enterprise terms are rated separately (and are typically far more protective). Confidence labels: Verified = contract/DPA · Policy-based = published policy · Inferred = deduced · Unverified = not yet assessed.