What each vendor says, and when they said it
Training data is the text a model learns from. When a vendor says it trains on your conversations, it means what you paste could shape future answers to other people, and in rare cases could be reproduced. When a vendor says it does not, your data is still stored and processed to give you an answer, but it stays out of the model.
OpenAI's help article on how your data is used to improve model performance, as it read on 3 August 2026, says content from ChatGPT Free, Plus and Pro may be used to improve models unless you switch that off in Data Controls. The same article, together with OpenAI's enterprise privacy page, says content from ChatGPT Business, ChatGPT Enterprise and the API is not used to train models by default, and that those three carry SOC 2 Type 2 reports.
Anthropic's privacy article on whether your data is used for model training, checked the same week, says data from its commercial products is not used for training by default. That covers the API and the business plans for Claude.
Intuit, whose QuickBooks connector for ChatGPT and Claude went live on 28 and 29 July 2026, said in its release that customer data is never used to train foundation models. That statement covers what Intuit does. It does not change what OpenAI or Anthropic do with the conversation on their end, which still follows the account you are signed into.
Policies move. We cannot tell you what any of these pages will say next spring. The honest advice is to reread them once a year and any time a vendor emails you about terms.
What is in a P&L, and what is in a ledger export
A profit and loss statement is a summary. Revenue by category, cost of goods, expenses by account, net income. Forty lines, give or take.
A general ledger export is every transaction behind those forty lines: the date, the account, the name, the amount and the memo field.
The difference is the whole question. The owner of a commercial cleaning company with 27 staff has two files she could paste. Her year-to-date P&L is 42 lines and shows revenue of $3,184,000 and net income of $214,600. A competitor who saw it would learn her margin, which is roughly what he already assumed. Her general ledger export for the same period is 9,640 rows. It has every payroll run with 27 names and what each person earned, 340 customer names with what they paid and when, every vendor and its terms, the monthly payment to the bank that reveals the loan size, and the memo field where the bookkeeper wrote "Dave late again" next to a customer's name. If that file trains a model or leaks, the P&L was never the problem.
Most advice on this says never paste financial data into an AI. We think that overstates the risk for a summary statement and understates it for anything at transaction level, and the blanket rule mostly means owners ignore it. The useful rule is about what is in the file, not what the file is called.
SOC 2 in one paragraph
SOC 2 is an audit standard under which an independent accounting firm tests a vendor's controls over security, availability and confidentiality. A Type 1 report says the controls existed on a given day, and a Type 2 report says they operated over a period, usually six to twelve months, which is the one worth asking for. OpenAI's enterprise privacy page lists SOC 2 Type 2 for its Enterprise, Business and API products. None of this is a guarantee. A SOC 2 report means someone outside the company checked how they protect your data, and wrote down what they found.
The practical rules
The first rule is the account. If anyone in the business is going to ask an AI about the numbers, pay for a business tier. It removes the training question by default, gives you an administrator who can see who has connected what, and gives you a SOC 2 report to hand to your bank or your insurer if they ask. The consumer tier is fine for a one-off question about a summary, provided model improvement is switched off first, and provided the person doing it is you and not a bookkeeper on their personal login.
The second rule is what to strip. Before a P&L or balance sheet goes anywhere, take out the company name in the header, the bank account numbers on the balance sheet, and any customer or employee names that appear as account names. That takes two minutes in a spreadsheet and turns a document about your business into a document about a business.
The third rule is what never gets pasted. Payroll registers, customer lists with balances, bank statements, loan agreements and the general ledger export. If a question needs that level of detail, it needs a tool that reads the books in place with a permission you control, which is a different thing from an upload.
Upload, read-only connection, or write-capable connector
Since late July there are three ways for an AI to see your QuickBooks numbers, and they carry different risk.
| Method | What the AI sees | What it can change | Where the data goes |
|---|---|---|---|
| Upload a PDF or spreadsheet | Whatever is in the file | Nothing | A copy leaves your control |
| Read-only connection | Reports and, depending on the tool, transactions | Nothing | Read in place, under a permission you set |
| Write-capable connector | Reports and transactions | Invoices, estimates, customers, items, ledger imports | Read and written in place, under the connecting user's role |
The Intuit connector for ChatGPT and Claude is the third kind. Intuit's release lists creating, updating, sending and deleting invoices and importing transactions into the general ledger among its abilities, and says only destructive actions ask for confirmation. Connected as the owner, it can do anything the owner can. How to make it behave like the second kind, by connecting through a reports-only user, is in the ChatGPT and Claude QuickBooks connectors and how to keep them read-only.
Navigator is the second kind. It connects to QuickBooks Online read-only, in two clicks, with no password shared, and cannot post anything to your books. There is nothing to paste, so the question of which file is safe to upload does not come up; each answer cites the transaction it came from, and the owner sees which company and which entry.
What owners actually worry about
The worry is real and it is the right one. Intuit's 2026 AI Impact Report, published on 13 May 2026 with the University of Chicago from more than 34,000 responses, found that the top barrier to using AI in a small business was privacy and security, with fear of errors second. BILL's 2025 State of Financial Automation survey of 750 financial decision-makers at companies with 10 to 500 employees found 73 percent already using AI, and named information security and incorrect or misleading information as the two main drawbacks.
Those two worries belong together. The upload question is about the first. The second is about whether the answer you get back is right, and whether it will be the same tomorrow, which is a separate problem we take up in why ChatGPT gives different answers to the same question. Getting the privacy setting right and then trusting a wrong number is not a good trade.
One more figure worth knowing. QuickBooks' 2026 Business Owner Report, from 1,305 owners, found 37 percent trust a human expert over AI alone, 20 percent the reverse, and 34 percent trust both equally. Most owners, in other words, are not asking whether to use these tools. They are asking how to use them without getting hurt, and that comes down to which account, which file, and which permission.
Questions owners ask
Does ChatGPT train on uploaded files?
On consumer ChatGPT (Free, Plus and Pro) it can, unless you turn off model improvement under Data Controls; that is what OpenAI's own help article said when we checked it on 3 August 2026. On ChatGPT Business, Enterprise and the API, OpenAI says your content is not used for training by default.
Is Claude safe for business financial data?
Anthropic's privacy article says data from its commercial products is not used to train models by default. That is the same footing as ChatGPT Business. Whether it is safe for your data still depends on what you paste: a summary P&L carries little risk, a ledger export with names and pay does.
Should I use a business account for financial questions?
Yes. The business tiers from both vendors do not train on your content by default, hold SOC 2 Type 2 reports, and let an administrator see who has connected what. The consumer tiers put the training choice on you and cannot be managed for staff. The price difference is small next to a leaked payroll.
What is SOC 2 and does it matter for a small business?
SOC 2 is an audit standard under which an outside firm tests a company's security controls. A Type 2 report covers a period, usually six to twelve months, rather than a single day. It does not prove the vendor will never lose data. It does mean someone independent checked, which is more than most small vendors can say.
Is it safer to connect QuickBooks or upload a PDF?
A read-only connection is safer than an upload, because nothing leaves your control as a file and the tool sees only what its permission allows. A write-capable connection, like the July 2026 QuickBooks link to ChatGPT and Claude, is the least safe of the three unless you connect it through a reports-only user.
Related
If you have already connected QuickBooks to a chatbot, read what the ChatGPT and Claude connectors can change and how to keep them read-only before you ask it anything else. For the other half of the worry, whether the answer is right, see why ChatGPT gives different answers to the same question. And for how the choices stack up in dollars against a bookkeeper or a fractional CFO, there is AI CFO, fractional CFO or bookkeeper.
If you would rather ask questions of your books without pasting anything anywhere, the free trial connects read-only in about fifteen minutes and needs no card: navigatorhq.ai.
Published . Last updated . Reviewed by a CFO on the Navigator team.