232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE

Which design tools train AI on your data?

Of the 23 design tools on file, 19 are graded: 17 train on your data by default and 2 don't. The other 4 have a policy that doesn't say either way. The best graded is Synthesia (B) and the worst is Udio (F).

23 APPS TRACKED IN THIS CATEGORY · WORST FIRST

Do they train on your designs, your prompts and your face?

Every story about generative AI and creative work is about what the models learned before you arrived. The apps here hold your design files, your prompts, the images and video you generate and sometimes a recording of your face and voice. They’re graded on a narrower question: does what you make there train the next model, and how hard is it to stop. Read together, they divide by what their own documents say. No way out, or a way out that’s sold. A switch or an address. Training only when you ask for it, or not at all. Or nothing that reaches the question.

No way out, or a way out that is sold

Leonardo.Ai may analyse “your Content and related data in your account” to improve the Service “and to train our algorithms, models, and AI products and services using machine learning”. For an image generator that’s what you made and, often, what you uploaded to make it from. No setting, no email route and no plan on which this doesn’t happen, which is what an F is.

Suno never writes the words artificial intelligence or machine learning in its policy, only “models”. What it says is plain once found: Submissions, chat and other Content are used “to train and enhance the models that power our Services”, on a legitimate-interest basis. There’s no setting and no plan on which it stops.

Recraft states the training use and the control in one sentence: you “may disallow such use of your information by opting out in your account profile settings”. No plan is named. Recraft’s support reply, printed on the verdict, adds what the policy lacks: “Training opt-out is not available on the Free plan.” A control described in the document and reachable only by paying is the privacy paywall an E marks.

Midjourney answered on two pages its privacy policy never mentions. Its AI Act training summary asks whether data from user interactions with the model, “e.g. user input and prompts”, was used to train it, and ticks yes for text and image. Its California disclosure lists “data our users provide through use of the Midjourney service” among the training sources. Nothing you can switch off: stealth mode controls who sees your images, not what trains on them. F, and Midjourney publishes no address that a letter can reach.

A switch, or an address to write to

Figma’s privacy policy makes training conditional on a “Content Training” toggle and never says which way it ships. Its AI approach page does, per plan: on Starter and Professional the setting is on and “admins can opt out”. It’s a team setting held by an admin, so a member of someone else’s team can’t turn it off for their own work.

Canva trains “our algorithms, models and AI products and services using machine learning” on your content, and the same paragraph names the control: “the privacy controls page under your privacy settings”. What it never says is which way the switch starts. The one flat exclusion is for students: “We will not use User Content of Canva Education for AI training.”

What HeyGen holds is video and voice of real people, and its clause says what they’re for: “to make our avatar creation models more accurate”. The way out is real, and it’s an email address, not a setting. HeyGen’s reply goes further than its policy does. The grade follows what is published.

The ones that ask first, or say no

Synthesia answers the question for your face and voice. The purposes for Biometric Data are a closed list, and the sentence after it limits them: the data is used “only until it is no longer needed for the achievement of the above listed purposes”, then destroyed. Training happens on the sample you record, to build the avatar you asked for. Opt-in is what a B is. Scripts and finished videos are deferred to an agreement your employer signed.

Webflow’s privacy policy never mentions training. Its trust centre does: “We do not use customer data to train generative AI models - whether proprietary or third-party.” That covers its own models and its vendors’. The scope word is “generative”. B and not A because this is an undertaking, revocable by editing the page it sits on.

The ones that never reach the question

D-ID’s only training statement covers data at rest: “While in the storage, awaiting processing or deletion, the Applicative Data is not accessed for any purpose, including not accessed for model training.” That’s before and after the job, not during it. Asked, D-ID answered, and the sentence isn’t in the policy.

Murf sells synthetic voice. Its privacy policy never mentions training, machine learning or artificial intelligence, and never uses the word voice. It says what it holds, “Any photos, videos, audio or text content provided by you when creating Content”, and nothing about what is built from it. For a product that is a model of how a person sounds, the missing word is the finding.

Every quotation above is the company’s own words, read from a dated, archived copy of its document or, where the entry says so, from its reply. The date and the copy are on each verdict, and every grade here is the one on the company’s own entry. UNCLEAR is a finding about the document, never an accusation about the company. Where a company answered by email, the reply is printed on its verdict and, Recraft apart, the grade reads the document. How grades are set · Right of reply

Side by side

7 pairs of design tools people choose between, with both verdicts on one page.