Confidentiality in Claude Cowork
By Max Krueger
A solo lawyer or small firm can test Claude Cowork without giving it confidential client information. The harder decision comes later, when you want to use it on a live matter.
The natural question is, “Is Claude Cowork safe for client files?” This guide shows you how to choose the lowest available retention settings and identifies the questions to answer before confidential information enters a Cowork workflow.
This article provides general information, not legal, ethics, privacy, or cybersecurity advice. Apply the rules, client commitments, and guidance that govern your firm and jurisdiction.
If you are new to the product, read What is Claude Cowork?.
The short answer
Do not upload confidential client information to Claude Cowork until you have confirmed that the account, retention rules, permissions, and matter restrictions allow it.
Cowork tasks run remotely on Anthropic’s servers, and sessions and files are saved to the user’s Claude account. Cowork does not currently have a setting that provides zero data retention. Anthropic says deleting a task removes it from visible history immediately and from its back end within 30 days, subject to its retention rules.
Anthropic says Team and Enterprise content is not used for model training by default. Pro and Max accounts have a separate model-improvement setting. Not used for training does not mean not retained.
The confidentiality decision remains yours. You need to know what Cowork can access, what it can change or send, whether client consent or other approval is required, and who will review the result.
Where confidential information can enter Cowork
Confidential information can enter Anthropic’s systems through more than a file upload. Cowork runs remotely, so information it uses to complete a task may be processed on Anthropic’s servers.
- Instructions and messages: Anything you type or paste into the task, including names, facts, excerpts, corrections, and follow-up instructions.
- Uploaded files: Documents added to a Cowork session or project, along with any instructions or project knowledge saved with them.
- Local folders: The desktop app can give a remote Cowork session access to approved folders on your computer. Anthropic says files Cowork opens through that access are processed on its servers rather than remaining only on your device. See Use Claude Cowork safely.
- Connected services: Cowork can retrieve information from services such as email, cloud storage, calendars, and other connected tools. Connectors inherit your permissions in the source service, so broad access can expose more than one document or matter. See Anthropic’s connector guidance.
- Browser activity: If Claude in Chrome is enabled for a task, Cowork can read page content, enter information into forms, navigate websites, and download files. See Get started with Claude in Chrome.
- Generated files and results: Cowork saves sessions and files to the user’s Claude account. Copies may also be downloaded to a computer or saved to another connected service.
- Feedback and bug reports: Information submitted through feedback may follow a different retention period. Anthropic says data associated with feedback can be retained for five years.
Processing is not the same as model training. Turning off model improvement, or using a plan that does not train on customer content by default, does not stop Cowork from processing information needed to perform the task. It also does not determine how long every copy is retained.
How to use the lowest available data-retention settings
The correct steps depend on your plan. First, open Claude and check whether you use an individual Pro or Max account, a Team account, or an Enterprise account.
Three separate controls are easy to confuse:
- Model improvement decides whether Anthropic can use eligible content to improve future models.
- Task deletion removes a Cowork task that you no longer need.
- Automatic retention sets how long an organization keeps content before it is deleted.
Changing one does not automatically change the others.
If you use an individual Pro or Max account
- Select your name in Claude.
- Open Settings.
- Select Privacy.
- Under Help Improve Claude, turn the setting off.
Anthropic says this stops new chats and coding sessions from being used for future model training. It also says previously stored chats will not be used in future training runs, although it cannot remove data that has already entered a training process or trained model. Safety systems may still retain or review content that is flagged for a possible policy violation. See Anthropic’s model-improvement setting instructions.
Anthropic’s setting page does not specifically name Cowork. Treat this as the lowest available model-improvement setting on an individual account, not as a Cowork-specific retention promise.
When you finish a Cowork task, delete it. Select the three-dot menu next to the task and choose Delete, or open the Tasks list and select the trash icon. Anthropic’s Cowork guide says the task disappears from visible history immediately and is deleted from its back end within 30 days, subject to its retention rules.
Do not send thumbs-up or thumbs-down feedback on a confidential task unless that has been approved. Anthropic’s consumer retention policy says feedback data may be retained for five years.
Pro and Max do not have the Enterprise organization-retention control described below. Turning off model improvement is useful, but it is not the same as setting a shorter storage period or using a firm-managed commercial account.
If your firm uses Team
Anthropic says Team content is not used for model training by default. Its published custom organization-retention control is an Enterprise feature, not a Team setting.
Delete each completed Cowork task using the task menu or Tasks list. Anthropic says deleted content is removed from the back end within 30 days, subject to its stated exceptions. Ask your admin to confirm that the firm has not joined an optional data-sharing program and to disable any connectors the firm does not need.
If your firm uses Enterprise
Ask your admin to set the shortest period that meets the firm’s duties. If you are the admin, you can do this yourself:
- Open Organization settings.
- Select Data and Privacy.
- Set the retention period to 30 days, if that period is appropriate for the firm.
- Save the change.
Anthropic’s Enterprise retention instructions describe 30 days as the minimum for this control. They also say the default is indefinite if an admin has not set a custom period. The period runs from the last activity, so reopening an older item may reset its deletion date.
Continue to delete completed Cowork tasks. A retention policy sets an outside schedule; deletion removes a task you no longer need from active history.
What does Anthropic currently say about Cowork data?
Anthropic’s documentation changes as Cowork develops. The facts below reflect its published guidance as of August 15, 2026. You should verify the current documentation and your own agreement before approving a workflow.
| Question | What Anthropic currently documents | What you still need to decide |
|---|---|---|
| Is customer content used for training? | Team and Enterprise content is not used for model training by default. Pro and Max users have a separate model-improvement privacy setting. | Which account you use, whether optional sharing is enabled, and how your firm handles feedback. |
| Where does Cowork run? | Current Cowork tasks run remotely. The desktop app can give Cowork access to local files and browser tools that the user approves. | Which files and tools the task needs, and whether the matter permits remote processing. |
| How long is data retained? | Deleted Cowork tasks are removed from visible history immediately and from the back end within 30 days, subject to stated exceptions. Enterprise admins can set a custom organization period with a 30-day minimum. | What your duties require, when tasks will be deleted, and which exceptions or model-specific rules apply. |
| What can Cowork access? | Team and Enterprise admins have controls for Cowork and connectors. Individual users also choose task permissions. | The minimum files, systems, network access, and actions needed for the task. |
Anthropic’s commercial data guidance says Team and Enterprise customers control the data they submit and Anthropic acts as the processor. Pro and Max accounts use separate terms and controls. Do not assume that a personal paid account is equivalent to a firm-managed Team or Enterprise account.
Three questions to answer before using client information
1. Which Claude plan are you using?
Check whether the account is Pro, Max, Team, or Enterprise. This determines which terms, training rules, and retention controls apply.
Pro and Max are individual accounts. Team and Enterprise can be managed by a firm. Before adding client information, confirm the terms for your exact plan and make sure you know whether optional data sharing has been enabled. If you cannot confirm this, do not add the client information.
2. What information will Cowork be able to see?
Only give Cowork access to what the task requires. If the task needs three documents, place those documents in a separate folder. Do not connect an entire client drive or a broad email account.
Check every folder, project, plugin, and connector available to the task. A connector may expose more information than the document you intended to use. Cowork sessions run remotely, including when the source files are stored on your computer.
3. What can Cowork change or send?
Use Manual permission mode for legal work. This makes Cowork ask before it takes an external action. Read each request before you approve it.
For an early workflow, do not let Cowork send email, change source documents, or delete files without your approval. Grant only the access needed for the current task.
Documents, websites, and emails can contain hidden or misleading instructions. Anthropic calls this prompt injection and says the risk is not zero. Its Cowork guidance for organizations recommends limiting access to sensitive files and watching for unexpected actions.
Frequently asked questions
Does Anthropic train Claude on law-firm data?
It depends on the plan and settings. Anthropic does not treat “law-firm data” as a separate category. The rules follow the account used to submit it.
Team and Enterprise: Anthropic says it does not use customer inputs or outputs to train its models by default. The main exceptions are when the organization chooses to share data, such as through the Development Partner Program, or when a user submits feedback or a bug report. Anthropic says feedback can include the entire related conversation and may be used for model training. A Team or Enterprise admin can disable the thumbs-up and thumbs-down feedback buttons under Organization settings → Data and Privacy → Rate chats. See Anthropic’s commercial training policy.
Pro and Max: These are consumer accounts. Under Settings → Privacy, turn off Help Improve our AI models. Anthropic says it will then stop using new chats and coding sessions for future model training and stop using previously stored sessions in future training runs. Data already included in training that has started, or in a trained model, cannot be removed through this setting. Anthropic’s privacy-setting instructions do not name Cowork specifically, so do not treat the toggle as a Cowork-specific contractual guarantee.
Safety exception: Anthropic says conversations flagged by its safety systems may still be used to improve internal trust and safety models, detect harmful content, enforce policies, or support safety research.
Model training is separate from processing and retention. Even when customer content is not used to train future models, Cowork still processes the information needed to perform the task and may retain the session under the rules described above.
Does Cowork run locally on my computer?
Current Cowork sessions run remotely on Anthropic’s servers. The desktop app can give Cowork access to local folders and browser tools you approve, but that does not make the session local. Consider both the remote processing and any source or output files kept on your device.
Does an Enterprise account make client-data use acceptable?
An Enterprise account can provide admin, retention, access, and monitoring controls that are useful to a firm. It does not approve every workflow, preserve privilege by itself, or remove the lawyer’s duties. You still need to review the matter, data, permissions, and process.
How do I get zero data retention?
You cannot get zero data retention in Claude Cowork. Anthropic currently lists Cowork as a standard-retention product and does not offer a Cowork setting for zero data retention.
The shortest documented Cowork retention period is 30 days on Enterprise. Deleting a task removes it from your visible history, but Anthropic says deletion from its back-end systems can take up to 30 days. Neither option is zero data retention.
Anthropic offers zero data retention only to approved commercial organizations using eligible Claude API or Claude Code configurations. If your firm requires it, contact Anthropic Sales and identify the exact organization, product, endpoint, and models you plan to use. Ask Anthropic to confirm the approved scope and any exceptions in writing before you send client information.
Under Anthropic’s zero-data-retention terms, it does not store prompts or outputs except where required by law or needed to address misuse or harm. Anthropic still retains its User Safety classifier results. Some models require 30-day retention and cannot be used in a zero-retention workspace.
If the work must remain in Cowork, zero data retention is not available. Your options are to use Cowork’s standard retention controls or move the work to an approved API or Claude Code configuration.
Does redacting a file solve the confidentiality problem?
No. Redaction can reduce the amount of sensitive information, but you must still evaluate the account, retention, permissions, connectors, working copies, output, and professional duties.
Let’s work together
Backland Labs helps small firms choose a useful workflow, set clear boundaries, and build a working Claude Cowork pilot.
Our sessions are hands-on. We focus on one real process, the files and permissions it needs, and the review step that keeps a person responsible for the result.
Talk with us about a Cowork pilot
Sources and citations
This article relies on primary product, privacy, and professional-responsibility sources. Online sources were accessed on August 15, 2026.
- Anthropic. “Get started with Claude Cowork.” Claude Help Center.
- Anthropic. “How do I change my model improvement privacy settings?.” Anthropic Privacy Center.
- Anthropic. “How long do you store my data?.” Anthropic Privacy Center.
- Anthropic. “How long do you store my organization’s data?.” Anthropic Privacy Center.
- Anthropic. “Configure custom data retention controls for Enterprise plans.” Claude Help Center.
- Anthropic. “Use Claude Cowork on Team and Enterprise plans.” Claude Help Center.
- Anthropic. “Does Anthropic act as a data processor or controller?.” Claude Help Center.
- Anthropic. “Using Claude for Legal Work: Privilege, Confidentiality, and How to Think About Configuration.” Claude Help Center.
- Anthropic. “Covered Models under a Business Associate Agreement.” Claude Help Center.
- American Bar Association. “Formal Opinion 512: Generative Artificial Intelligence Tools.” Standing Committee on Ethics and Professional Responsibility.
- Anthropic. “Use Claude Cowork safely.” Claude Help Center.
- Anthropic. “Use Claude Cowork on web, desktop, and mobile.” Claude Help Center.
- Anthropic. “Use connectors to extend Claude’s capabilities.” Claude Help Center.
- Anthropic. “Get started with Claude in Chrome.” Claude Help Center.
- Anthropic. “Is my data used for model training?.” Anthropic Privacy Center.
- Anthropic. “I have a zero data retention agreement with Anthropic. What products does it apply to?.” Anthropic Privacy Center.