I Checked 20 AI Tools' Training Defaults. Every One That Trains You by Default Exempts Its Enterprise Tier.
Aug 15, 2026 · 6 min read · by Jordan Kwan
TL;DR: On August 15, 2026 I read the published policies of 20 AI developer and productivity tools to answer one question: does this vendor train models on my work unless I stop it? Thirteen gave a clear answer on their own pages. Seven of those thirteen train by default or forced a choice at a deadline, and six of those seven explicitly exempt their business and enterprise tiers. Median notice before a documented default flip was 30 days. Two flips landed this spring: GitHub published on March 25, 2026 and enforced on April 24, and Vercel published on March 17 with an opt-out deadline of March 31.
Nothing here was hidden. Both spring changes were announced on the vendor's own blog, on the record, with a date on them. They are also structured identically, and the structure is the finding: the tier paying the least becomes the training corpus, and the tier paying the most gets a written carve-out.
What actually flipped this spring?
GitHub's changelog entry is dated March 25, 2026. From April 24, interaction data ("inputs, outputs, code snippets, and associated context") from Copilot Free, Pro and Pro+ trains GitHub's models unless you turn it off in settings. The same post states that "Copilot Business and Copilot Enterprise users are not affected by this update."
Vercel's is dated March 17, 2026, with a hard cutoff of "March 31st 2026 11:59:59 PST." Covered data includes code and Vercel agent chats, build and deployment telemetry, and aggregate traffic stats. Hobby accounts, including trial Pro, were opted in by default. Paid Pro was opted out by default. Enterprise was opted out of any AI model training, full stop. Three tiers, three different answers, one product.
How did I run the count?
I named 20 tools first and then went looking, so the sample could not drift toward whichever vendors made the story better: GitHub, Vercel, OpenAI, Anthropic, Cursor, Replit, Notion, Slack, Figma, Canva, Grammarly, Zoom, Atlassian, Dropbox, Microsoft, JetBrains, Sourcegraph, Linear, Perplexity and Windsurf. For each I looked for a first-party statement of the default, not a summary of one.
The archive method I planned did not survive contact. The Wayback CDX API answers, but its digest column is useless as a revision counter here: it returns 2,032 distinct captures of GitHub's privacy statement across 18 months, because these pages carry nonces and rotating markup, not because the policy changed 2,032 times. The follow-up pass, pulling one snapshot per month and reading the printed effective date, got rate-limited into connection failures. So I built the count from vendors' own dated changelogs and policy pages instead.
That turned out better for GitHub specifically, because GitHub versions its own policy in public. The privacy statement lives in the github/docs repo, and since January 2025 it has taken nine commits. Eight are housekeeping: a missing full stop, a broken VS Code link, an arbitration link, frontmatter, a layout conversion. One is commit 301baf10d6, "Terms and Privacy Statement updates for data collection and model training policies," which rewrote the terms of service by 102 added lines against 49 deleted. That is a real diff against real policy text, not a banner I mistook for a page.
Which tools train on your work by default?
Of the 13 that answered, six train on customer content by default and offer an opt-out: GitHub, Vercel (Hobby and trial Pro), OpenAI for "services for individuals such as ChatGPT and Codex," Figma for Starter and Professional teams, Cognition's Windsurf and Devin, and Canva, which says it may analyze your activity, content and uploads "to train our algorithms, models and AI products."
One forced a dated choice rather than a silent default: Anthropic told Free, Pro and Max users on August 28, 2025 to pick a training setting by October 8 to keep using Claude.
Five say they do not train on your content at all. Notion: "By default, Notion and its AI Subprocessors do not use Customer Data to train any models." Slack: "Slack will not use Customer Data to train generative AI models unless Customer provides affirmative opt-in consent," though its older global ML models are opt-out only by emailing support with a specific subject line. Atlassian says Rovo inputs and outputs are not shared with third-party LLM providers to train their services. Amp, Sourcegraph's agent, is opt-in only and states that on an Enterprise workspace "training can never be enabled." Microsoft 365 Copilot says prompts and responses "aren't used to train foundation LLMs."
One documents the control but not the default. Cursor's security page says Privacy Mode "is available to anyone (free or Pro)" and that team admins can enforce it, and does not state what happens if nobody touches it.
Seven never answered from a first-party page I could reach: Replit, Grammarly, Zoom, Dropbox, JetBrains, Linear and Perplexity. That is the real denominator. 13 of 20.
Does your training default depend on what you pay?
For six of the seven tools with a training default, yes, explicitly. GitHub exempts Business and Enterprise. Vercel exempts paid Pro and Enterprise. OpenAI's individual services train, its business products do not. Anthropic's change excludes Claude for Work, Government, Education and the API. Figma sets training on for Starter and Professional and off for Organization and Enterprise. Cognition's page is the bluntest: training is on by default, and "if you're on a paid plan, you can opt out." Free users are not offered the switch. Canva is the seventh, and publishes no tier split.
The GitHub diff shows the mechanism in one line. The pre-release license terms previously read "GitHub will not use your inputs or the outputs generated to train AI language models." The April commit narrowed that to "GitHub will not use Copilot Business or Copilot Enterprise Inputs or the Outputs." A blanket promise became a promise to two paid tiers. The new Section J says it outright: the training provisions "apply only to individual licenses."
How much notice did anyone get?
Three flips have a published announcement date and a published enforcement date. Vercel: 14 days. GitHub: 30 days. Anthropic: 41 days. Median 30. For scale, that is less notice than most annual subscriptions give before auto-renewing, and it is the window in which a default about your source code changes. GitHub's own policy commit landed on April 27, three days after the change took effect.
What does this not prove?
It does not prove anyone acted in bad faith. Every change here was published, dated, and reversible from a settings page, which is more than most data practices get. Opt-out is a legitimate design choice, and the enterprise carve-outs mostly exist because enterprise contracts already forbid training, not because anyone sorted users by worthiness. Seven of my 20 stayed unresolved, and a different seven could move the ratio.
One number did not survive. A widely repeated figure claims GitHub's own FAQ discussion drew 59 downvotes against 3 upvotes. I opened the discussion myself. The page renders upvote counts and no downvote tally at all, so the figure could not be reproduced from the source it supposedly came from. It is cut rather than hedged.
The practical move is not outrage, it is a calendar entry. If you evaluate coding tools by feature comparison, add one column for the training default at your actual tier, and recheck it quarterly, because six of these thirteen answers are only true until the next changelog. The same column belongs on anything that records other people: nine of 13 meeting-AI products make the customer solely responsible for obtaining consent. The same tiering logic now runs through what you pay for the AI itself, and it is worth remembering that vendor-run evidence has a track record here, as the AI coding productivity studies showed.
Written by Jordan Kwan, founder of Reachium.
I build Reachium, the LinkedIn outreach platform behind the tactics you just read. Same brain, live product.
See what Reachium does ↗