232 APPS TRACKED · 227 CLAUSES ON FILE · 38 WITH NO CLAUSE TO QUOTE

Which workplace tools train AI on your data?

Of the 28 workplace tools on file, 21 are graded: 7 train on your data by default and 14 don't. The other 7 have a policy that doesn't say either way. The best graded is Docusign (B) and the worst is Freshworks (F).

28 APPS TRACKED IN THIS CATEGORY · WORST FIRST

Do they train on what your colleagues, customers and prospects say?

A work app holds words that are rarely the account holder’s own: what a team says to each other, what a customer says to support. The account belongs to an organisation, so where a document offers a choice, it is usually the organisation’s to make. Read together, these divide by what the company’s own documents say. Training with no way out, training with an exit that belongs to somebody else, a no with a qualifier, or nothing that answers the question.

The ones that train, and who can stop it

Atlassian uses what you send through its support channels “including for development, training, or fine-tuning of machine learning and artificial intelligence models”. Product content is processed under a separate customer agreement, which routes the question onward. Outside the EU and UK no opt-out is stated. Where an objection right exists, the policy warns it “may mean no longer using the Services”.

Freshworks records the calls its users make through it, with the consent of both parties, and the recording “will be used for product improvement, including to train our applications to better recognize human speech”. Consent to being recorded isn’t consent to being training data. The control in the next sentence, “You will have the option to opt out of analytics or tracking certain events”, is for something else.

Zendesk’s AI addendum binds its LLM providers, who may use Service Data for no purpose “other than to provide and secure the AI Services”. On Zendesk’s own models it is silent. Asked, Zendesk replied that paid accounts can opt out through their Account Manager, that the opt-out is not published on any page, and that a standalone free trial can’t opt out at all. The reply is printed on the verdict. An exit sold with a paid plan is what an E is.

HubSpot may process personal data “to train our AI models and similar products and services that rely on machine learning”. The way out is the statutory objection right, filed on a request form, in a rights list that opens “Depending on your location and applicable laws”. In a CRM, that personal data is largely other people’s.

Slack makes two promises and only one is a no. It doesn’t build generative models on Customer Data. Its predictive models analyse Customer Data, messages, content and files, and “you can opt out”, by an email from an Org or Workspace Owner quoting a set subject line. A member can’t do it alone, and none of this is in the privacy policy.

The ones that say no, and who the no is made to

Airtable “will not use, or permit the Third-Party AI Providers or others to use, Input, Output, or any other Customer Data to train generative artificial intelligence models”. It binds the providers Airtable AI runs on, not only Airtable. It’s scoped to generative models, and it lives in the AI Terms, not the privacy policy, whose only uses of “training” are partners offering training services.

Docusign designs its systems “to avoid training models using personal information that customers may enter into our Services”, with the exception in brackets: “except when we have consent from a customer to do so”. The customer is the organisation with the account. The person who signs a document is the subject of the content and has no part in that consent.

Workday’s Innovation Services addendum never uses the word train; the administrator guide does. A customer contributes data by opting in, service by service, and “Customer has no obligation to contribute IS Data”. Opt-in is what a B is. The customer is your employer, and an employee has no switch of their own.

Clay answered the question on a page its privacy policy never points to. The trust-centre FAQ asks “Will Clay use our data for any AI training purposes?” and answers about third parties. The “AI in Clay” page answers for Clay: “Customer data is never used to train Clay’s AI models or those of our AI providers.” B, not A, for two reasons. The FAQ’s next answer keeps a door open, saying Clay “would provide a mechanism for customers to opt out” if it ever used customer tables for training. And the terms keep aggregated performance data for improving the product.

The ones that never answer the question

Gong records sales conversations, and its policy lists improving the Services “through the utilization and optimization of Artificial Intelligence and Machine Learning capabilities” as a purpose. Optimising a capability is what training does, but the document doesn’t say the two are the same. Its one use of “train” is Gong training its customers and staff.

Outreach’s single sentence is narrow: “Google Workspace Data is not used to develop, improve, or train AI and/or ML models.” That covers data reached through Google’s APIs. The prospect emails and call notes it holds directly aren’t mentioned either way.

Abridge transcribes medical consultations, and its privacy policy “does not apply to the content that our customers (e.g., hospitals, healthcare systems) and their authorized users upload and store in our services”. Those consultations are governed by hospital contracts and each provider’s own notice, documents this site can’t read. The absence is by design, which is a different finding from silence.

Every quotation above is the company’s own words, read from a dated, archived copy of its document. The check date and the archived copy are on each verdict, and every grade on this page is the one on the company’s own entry. UNCLEAR is a finding about the document, never an accusation about the company. A policy that comes to answer the question is re-read against it. How grades are set · Right of reply