Early-stage founders routinely paste raw customer contracts, runway projections, hiring budgets, and cap tables into artificial intelligence interfaces. While general-purpose language models accelerate daily execution, using them without explicit operational boundaries creates two distinct data risks: upstream ingestion into public training datasets and lateral context leakage across internal projects.
Protecting proprietary business data does not require banning modern AI tooling across your startup. Instead, it demands configuring foundational settings across your existing commercial subscriptions, establishing strict project boundaries, and understanding where generalist assistants leave context unshielded.
The Dual Exposure: Model Training Versus Workspace Memory Leakage
Founders often conflate two separate data governance vectors when discussing AI confidentiality:
- Upstream training ingestion: The AI provider logs user inputs and outputs to fine-tune future foundation models, potentially exposing operational snippets or proprietary phrasing to outside prompts.
- Workspace memory leakage: The AI assistant stores conversational artifacts across sessions to provide continuous context, accidentally pulling confidential financial metrics or client identities into completely unrelated operational chats.
A non-disclosure agreement or an ad-hoc prompt instruction such as "keep this confidential" does not alter the underlying data ingestion pipeline. Technical boundaries must be enforced directly in workspace settings.
Model Training Opt-Outs: Tier Policies and the Feedback Loop Trap
Default data ingestion rules depend heavily on whether a startup operates on consumer tiers or enterprise workspaces.
According to an official privacy update published on August 19, 2026, Anthropic commercial product documentation confirms that inputs and outputs from commercial offerings such as Claude for Work, the Anthropic API, and Claude Gov are not used to train models by default. However, submitting explicit feedback via thumbs up or thumbs down buttons overrides this protection: when feedback is sent, Anthropic stores the entire related conversation in secured back-end systems for up to 5 years, and that conversation may be used to train future models.
OpenAI enforces a similar distinction across account tiers. As detailed in the OpenAI model performance documentation, consumer-facing services such as individual ChatGPT and Codex accounts may use submitted content for model training unless users manually toggle training off. In contrast, OpenAI does not use inputs or outputs from ChatGPT Business, ChatGPT Enterprise, ChatGPT Edu, or its developer API to improve models by default. Temporary chats are also excluded from training while they remain temporary. Yet a critical exception mirrors Anthropic: even if an individual user has opted out of training, choosing to provide response feedback through thumbs up or thumbs down allows OpenAI to use the entire associated conversation for model training.
For founders, the operational takeaway is straightforward:
- Upgrading to commercial team or enterprise plans provides immediate default protection against model training across both providers.
- If individual team members remain on personal consumer tiers, they must manually disable model training in their account settings.
- Team members must strictly avoid using thumbs up or thumbs down feedback buttons on chats containing sensitive financial statements, strategic board material, or customer records.
Project Memory Boundaries: Isolating Context Across Workflows
Even when model training is disabled, local memory can cause severe cross-contamination. If an assistant remembers sensitive customer terms from a morning session, that context can bleed into an afternoon pitch deck or a shared draft. Both major providers have introduced dedicated memory controls to address this.
Claude Memory and Sensitive Topics Controls
In an official release note dated August 25, 2026, Anthropic release notes announced that memory spans across chat and Cowork in the cloud. User memory is organized under editable and deletable topics located in workspace settings. Furthermore, personal domains such as health or beliefs are automatically kept out of memory unless the explicit setting to include sensitive topics is turned on. Crucially for administrative oversight, memory is turned on by default for Free, Pro, and Max plans, but remains turned off by default for Team and Enterprise organizations.
ChatGPT Project-Only Memory and the Privacy Center
OpenAI has structured similar controls around workspace projects. According to the ChatGPT release notes, an update on August 14, 2026 introduced the ability to switch eligible unshared projects between default memory and project-only memory without recreating the project. Under project-only memory, ChatGPT references context solely from conversations within that specific project. Information recorded inside that project is strictly isolated from outside chats, preventing sensitive operational metrics from leaking into broader conversations. Changes to these settings may take a few hours to take effect. Shared projects remain permanently locked to project-only memory, while ChatGPT Work is disabled within projects utilizing project-only memory.
Additionally, on September 21, 2026, OpenAI rolled out a centralized Privacy Center for Free, Go, Plus, and Pro tiers, consolidating settings for memory, personalization, data usage, account security, and connected tools in a single interface.
| Governance Dimension | Claude Commercial Tiers | Claude Consumer Tiers | ChatGPT Enterprise and Business | ChatGPT Consumer Tiers |
|---|---|---|---|---|
| Default model training | Disabled by default | Governed by separate consumer rules | Disabled by default | Enabled by default unless opted out |
| Response feedback impact | Entire conversation stored up to 5 years | Entire conversation stored up to 5 years | May train models on explicit feedback | Entire conversation may train models |
| Default memory state | Disabled by default for Team and Enterprise | Enabled by default for Free Pro Max | Configurable across projects | Enabled by default with Privacy Center |
| Context isolation mechanism | Editable topics in Settings Memory | Editable topics in Settings Memory | Project-only memory settings | Project-only memory or temporary chats |
Understanding these boundaries allows founders to prevent context spills while consulting the Knowledge guides for founders on broader operational governance.
Structuring Multi-Project Workflows Without Data Bleed
Early-stage founders handle distinct operational tracks simultaneously: customer discovery transcripts, pricing negotiations, runway scenarios, and technical hiring plans. Applying uniform settings across all tracks creates friction. A practical security architecture separates workflows by data sensitivity:
1. General Exploration and Ideation
For market research, copywriting, public competitive mapping, or general brainstorming, standard foundation models on consumer or business tiers are entirely adequate. Opting out of training remains good hygiene, but cross-conversation memory in these spaces rarely poses legal liability.
2. Commercial Pipeline and Client Records
Customer contracts and call records carry strict third-party confidentiality clauses. Beyond platform memory settings, automated meeting bots and transcript scrapers pose distinct surveillance and consent risks. Founders structuring outbound sales must review compliance boundaries, as explored in how AI meeting bots create wiretap liabilities for sales.
3. Core Corporate Governance and Financial Planning
Financial modeling, board updates, and cap table changes require absolute compartmentalization. When evaluating raw traction, such as validating product-market fit and genuine organic pull, founders cannot afford to have burn rates or equity splits surface in a customer-facing sales pitch draft.
For these high-stakes decisions, founders benefit from purpose-built environments. Within Ember, the Second Brain module acts as an isolated decision layer designed specifically for strategic execution. Rather than dumping sensitive files into a global conversational pool, founders can organize work into personal folders. Each folder supports up to 20 files with a limit of 50 MB per file, maintaining its own dedicated founder instructions and document sources. For sensitive one-off checks, an incognito conversation mode leaves no traces in history or the internal library and permanently deletes upon closing.
When deep calculation is required, such as building a profit and loss statement or reconciling accounts, Ember surfaces missing figures and source attributions directly, ensuring sensitive operational numbers remain grounded, verifiable, and strictly contained within the intended workspace.
Deciding Your Workspace Policy Today
Founders do not need complex enterprise compliance suites to secure their startups. You can implement robust operational protection immediately with four concrete rules:
- Verify commercial defaults: If your team uses Claude or ChatGPT, transition anyone handling internal financial or legal data to commercial accounts where training on inputs and outputs is disabled by default.
- Turn on project-only memory: Set sensitive customer engagements and investor material into isolated project spaces with project-only memory enabled to stop context bleed.
- Establish a strict feedback rule: Ban the use of thumbs up or thumbs down buttons on chats containing sensitive proprietary spreadsheets, investor decks, or customer records.
- Isolate governance and finance: For company-defining judgment calls, move away from generalist chat feeds and run your strategic calculations inside structured, compartmentalized tools. Founders seeking grounded operational clarity can explore how the Ember Second Brain separates context, sources, and strategic execution.
Sources
- Conversations et entraînement des modèles : ce que disent Anthropic (offres commerciales, 19 août 2026) et OpenAI (ChatGPT grand public et offres professionnelles) : source S1
- Conversations et entraînement des modèles : ce que disent Anthropic (offres commerciales, 19 août 2026) et OpenAI (ChatGPT grand public et offres professionnelles) : source S2
- ChatGPT : mémoire modifiable par projet (14 août 2026) et Centre de confidentialité (21 septembre 2026) : source S1
- Claude : la mémoire couvre désormais les discussions et Cowork, avec sujets modifiables et réglage des sujets sensibles (25 août 2026) : source S1
- Page publique du Second Cerveau : reçu S11
FAQ
Second Brain
Decide with project context
Ask a question and connect the answer to decisions already made in Ember.
