DeepL, ChatGPT and Otter. What each vendor's own documentation states about training, retention, disclosure and third-party attestation, sourced line by line. No scoring, no verdict, no vendor rankings. What the documents say, and where they say nothing.
Verified September 2026 · Facts only — no scoring, no verdict
| DeepL | |
|---|---|
| Does it train on your data? | Free: yes. Pro: no. The privacy policy is clear about this. Free: "We process the content you upload and their translations or improvements for a limited period of time to train and improve our neural networks and algorithms." Pro: "your texts will not be used to improve the quality of our services," and submitted texts "will not be permanently stored and will only be kept temporarily to the extent necessary for the production and transmission of the translation." |
| Where it gets easy to misread | DeepL's data security page states, with no tier qualification on the sentence itself, that "Texts are never stored or used for model training without your consent." Read on its own that sounds like a statement about DeepL. It sits on the Pro page, so Pro is presumably the intended scope. But the security page is the one a buyer or reviewer is most likely to be sent. |
| The part that matters for a firm | DeepL's terms state the free service should not be used for confidential or personal data. Free is also what someone reaches for when they need one paragraph translated before a call, and it never appears in procurement because no one bought it. |
| Third-party attestation | SOC 2 Type II (security, availability, confidentiality), GDPR, regular internal and external penetration testing. |
| ChatGPT (all tiers) | |
|---|---|
| Can the deployer see what was submitted? | Not on consumer tiersFree, Go, Plus and Pro accounts are individual, not workspace-managed. There is no admin log, no audit trail, and no path for the firm to see what an associate typed into a personal account. Business and Enterprise have admin retention and workspace controls. |
| Does it train on your data? | Consumer tiers: yes, by default. The opt-out is in the privacy portal and applies only to new conversations, so it is forward-only. Content submitted before the opt-out is not reached by it. Business and Enterprise: no, not by default. |
| What survives deletion? | The data-usage help article does not state what happens to content already used in training. |
| Third-party attestation and its scope | SOC 2 Type 2 is stated for the business products. It is not stated for consumer tiers on the enterprise privacy page. |
There is no longer any "Team" or "Teams" tier. Current tiers are Free, Go, Plus and Pro (individual) and Business and Enterprise (organization).
| Otter.ai | |
|---|---|
| Does it train on your data? | Yesand the wording is worth reading closely. Otter's privacy policy states it trains its proprietary AI technology on "de-identified audio recordings and on transcriptions (which may contain Personal Information)." The audio is de-identified. The transcriptions are qualified only as may contain personal information. Those are two different standards in one sentence. |
| Does a signed agreement change that? | Not statedA separate Otter article offers HIPAA compliance on the Enterprise plan with a signed BAA. Neither document states whether executing one excludes that customer's recordings and transcripts from training. For depositions, client calls and internal matter discussions, that is an unresolved question rather than a settled one. |
| What survives deletion? | Enterprise offers customer-defined retention policies, and Otter deletes data on contract termination at customer request. |
| Third-party attestation and its scope | SOC 2 Type 2, per Otter's privacy and security page. The same page describes its ISO position as "created based on the ISO 27001/2 framework," which is a different claim from certification. |
It reports what vendors publish. It does not score them, rank them, or tell you whether to use one.
It also cannot tell you whether your firm has a problem. That depends on your tier, your executed contract, and what your people are actually putting into these tools, and none of that is in a vendor's public documentation.
Running something other than these three?
Email the tool name to adil@shadowaiforensics.com and I'll tell you what its documentation says. No charge.
Adil Ali, Shadow AI Forensics · shadowaiforensics.com
Verified September 2026
This brief reports what vendors publish. It deliberately doesn't score them or give a verdict. The AI Vendor Risk Assessment does: one vendor, your regulatory context, three industry gates and nine scored criteria, a Go / Conditional Go / No-Go in 48 hours, plus the exact question to put to the vendor in writing.
$997. No call, no access to your systems.
See what's in it →Want the full picture?
This covers 3 tools. The full AI Vendor Compliance Quick-Reference covers all 13, side by side, same sourcing standard.
See all 13 tools, 22 tiers →