privacy.claude.com privacy policy — score 30/100 (high risk)

Last analyzed

Run a new analysis on another policy

Anthropic · anthropic.com

Report details

high risk

This is only a navigation page for Anthropic's Privacy Center — no actual privacy policy text was provided, so a meaningful compliance assessment is impossible.

The submitted content is a site navigation/menu for Anthropic's Privacy Center, listing categories (Commercial Customers, Consumers) and links to policies (Privacy Policy, Terms of Service, Usage Policy, etc.), but contains zero substantive privacy policy language. Without the actual policy text, no determination can be made about data practices, user rights, transfers, or AI training safeguards.

Last analyzed
SourceURL
Length671 chars

Category Assessment

Breakdown of the policy across key compliance areas. Good = strong, fair = mixed, poor = concerning.

Data Minimizationpoor

No policy text provided to evaluate whether collection is limited to what is necessary.

Transparencypoor

The navigation page lists policy categories but contains no substantive disclosures about data handling.

Third-party Sharingpoor

No information about subprocessors, sharing practices, or third-party categories is present.

International Transferspoor

No mention of data residency, transfer mechanisms, or safeguards for EU data subjects.

AI/Model Trainingpoor

No language about whether user data is used for model training or whether opt-out is available.

User Rightspoor

No description of GDPR rights (access, deletion, portability, objection) found in this content.

Key Findings

Notable clauses, issues, or positive practices discovered (critical first)

Critical

No substantive privacy policy text provided

The entire submitted content is a navigation/menu page for the Anthropic Privacy Center. It lists article categories and policy links but contains no actual privacy policy language, making a genuine compliance assessment impossible.

Critical

No evidence of GDPR-specific provisions

There is no language about lawful bases for processing, data subject rights, DPO contact information, supervisory authority references, or standard contractual clauses — all critical for EU compliance assessment.

Warning

Compliance page referenced but content missing

A 'Compliance' link is listed in the navigation, which could contain SOC 2 reports, GDPR documentation, or DPA information, but none of that content was provided for analysis.

Info

Separate consumer and commercial policy tracks indicated

The navigation distinguishes between 'Consumers' (Claude Free, Pro & Max plans) and 'Commercial Customers' (API, Console, Team & Enterprise plans), suggesting different terms apply. This separation is a positive structural signal but the actual terms are absent.

Consumer Takeaway

You cannot evaluate Anthropic's privacy practices from this page alone — you must follow the links to the actual Privacy Policy and Terms of Service.

Compliance Posture

Indeterminate — the navigation structure suggests separate consumer and commercial tracks, which is a positive signal for clarity, but no substantive claims can be verified from this content alone.

EU Transfers

Unknown — no information about data residency, transfer mechanisms, or adequacy decisions is present in this navigation page.

Evidence Snippets

Direct quotes from the policy supporting these findings

Commercial Customers API, Console, Team & Enterprise plans 30 articles

Consumers Claude Free, Pro & Max plans 26 articles

Privacy Policy

Compliance

Missing or Unclear

  • No actual privacy policy text was provided — only a navigation page
  • No information on categories of personal data collected
  • No information on lawful bases for processing under GDPR Article 6
  • No information on international data transfers or safeguards
  • No information on whether user data is used for AI model training
  • No information on data subject rights or how to exercise them
  • No information on data retention periods
  • No information on subprocessors or third-party sharing
  • No DPA (Data Processing Agreement) content
  • No contact details for Data Protection Officer or EU representative

Questions to Ask

  • Can you provide the actual Privacy Policy text linked from this Privacy Center page?
  • Does Anthropic offer a Data Processing Agreement (DPA) for EU commercial customers, and if so, what are its terms?
  • Is user input (prompts, conversations) used to train Anthropic's models, and is there an opt-out mechanism?
  • Where is EU user data stored and processed, and what transfer mechanisms (SCCs, adequacy decisions) are in place?
  • What are the specific categories of personal data collected for consumer vs. commercial users?
  • How can EU data subjects exercise their GDPR rights (access, erasure, portability, objection)?
This analysis is generated by AI and is not legal advice. Always consult a qualified legal professional for compliance decisions.

Share this analysis

Anyone with this link can view the result above.

Built by DentroChat

100% European AI chat for everyone

Chat with AI, work with files, generate images, and search the web. Data stays in Europe.

EU-hosted infrastructureText, files, images & web searchFast, Thinking & Creative modesPrivacy-first by defaultNo data leaves Europe
Try free →