An independent magazine about AI at work in construction. Every story starts on a real job site, with the people who used the technology and the results they will answer for.
Where the Bid Set Goes After an AI Vendor Promises Not to Train on It | ConstructionMagazine.ai
Where the Bid Set Goes After an AI Vendor Promises Not to Train on It
Business AI plans can keep company files out of model training and still retain prompts, uploads, or application state. Contractors need the exact rule for each product, feature, and data class before a project file enters the chat.
A superintendent photographs a marked-up detail. An estimator uploads the bid set. A project executive pastes an owner letter into a chatbot and asks for a cleaner draft. Each action can send project information into a different product with a different retention rule, even when the screens carry the same vendor name.
The sentence most buyers hear is reassuring: the provider does not train its models on business data by default. That answers one question. It does not say whether the provider stores the prompt for abuse monitoring, keeps the uploaded file so the user can find it later, preserves a conversation history, sends content through a connector, or makes it available for a legal hold.
For construction companies, those are procurement questions. The useful unit of review is the whole path taken by a particular file: account type, feature, endpoint, region, storage period, deletion behavior, and every system connected to it.
Each upload path can end in a product with a different retention rule. AI-assisted illustration.
Start with the document, then choose the tool
AI policy often starts with a list of approved products. A data-classification rule is harder to misread in the field. It tells an employee what may enter any system before the employee has to interpret a vendor's privacy page.
A contractor could begin with four working classes:
Class — Construction examples — Default handling
Public — Published code guidance, public bid notices, released product data — Approved business AI may be acceptable, subject to normal review
Internal — Blank company templates, general procedures, non-project training material — Approved company workspace only; no personal accounts
Confidential — Estimates, unit pricing, subcontractor quotes, schedules, contracts, RFIs, daily reports, employee or client information — Approved workflow with a documented retention period and access controls; minimize the input
Restricted — Owner-controlled drawings, BIM or CAD files, export-controlled or government information, privileged legal material, credentials, sensitive security plans — Do not upload unless the contract owner, security lead, and counsel have approved the exact deployment and data path
The labels will differ by company and contract. The important work is mapping them to actual project records. A PDF can contain public specifications on one page and a confidential alternates schedule on the next. A coordination model can expose building geometry, trade methods, personnel names, and embedded links. File-level labels alone may be too coarse.
Classification also needs an owner. Estimators should not have to decide whether an airport drawing is controlled information by reading a software pop-up at 10:30 on bid day. Preconstruction, operations, IT/security, and legal need one escalation path with a response time that fits project work.
Four product categories, four different answers
Consumer chat, business chat, an API, and an API under zero data retention are separate procurement categories. A paid individual subscription does not become a company-controlled workspace because the employee expenses it.
Consumer products commonly give the user a training control. The setting matters, but it is only the training setting. Chat history may remain until the user deletes it. Deletion may start a back-end removal window rather than erase every copy at the moment of the click. Feedback, safety flags, legal duties, saved files, memory, or third-party actions can follow different rules. Temporary or private chat modes can reduce storage or training use, but they do not turn a personal account into an administrated construction records system.
Business and enterprise chat products usually begin from a stronger position. OpenAI says it does not train on ChatGPT Business or Enterprise data by default. Anthropic says the same for its commercial products, and xAI advertises no training for Grok Business and Enterprise. Those commitments still sit beside product retention. A workspace may keep conversation history because the product is designed to let users return to it. An enterprise administrator may be able to set a custom window. Files, connectors, search, feedback, and beta features may carry their own terms.
An API gives the contractor more control over the interface and the record flow. It does not automatically mean that prompts disappear after inference. OpenAI's API does not use inputs and outputs for training by default, while its standard abuse-monitoring logs can retain customer content for up to 30 days. xAI says its API defaults to 30-day encrypted storage for audit purposes and no training unless the customer gives permission. The application built around either API can also store its own request logs, traces, uploaded files, vector indexes, database rows, and backups. A vendor's short retention period has little value if the contractor's integration copies the full prompt into an observability service for a year.
Zero data retention, or ZDR, is a narrower control. On eligible API traffic it removes prompts and responses from provider storage after processing. Eligibility and exclusions matter. OpenAI requires approval and lists ZDR support by endpoint. Endpoints that hold application state, such as conversations, assistants, threads, and vector stores, are not eligible. OpenAI also offers a second approved control, Modified Abuse Monitoring, which drops customer content from abuse logs without forcing stateless calls. Anthropic says ZDR applies only to approved customers on eligible APIs, on products used with a commercial API key, and on Claude Code for Enterprise, and that it still keeps safety classifier results. Since 9 June 2026 Anthropic also retains prompts and outputs from its covered models, the Mythos-class models, for 30 days on every platform, ZDR accounts included. xAI applies ZDR at the team level and disables the stateful features: per-key request logging, the stateful Responses API, files, collections, batches, deferred completions, stored image and video outputs, and voice-agent history.
ZDR does not mean that no data exists anywhere. Account details, billing records, usage metadata, safety classifier results, or legally required records may remain, depending on the provider and agreement. The contractor's own systems may retain full copies. A connected search service or project platform may receive a query. Procurement should ask what the term covers, then test the configured deployment.
The route matters as much as the vendor. Anthropic's September 2026 Fable 5.1 release says eligible customers can use the model with zero data retention until its Enterprise Frontier Safeguards program ships this fall. Anthropic publishes no eligibility criteria. Access follows an existing approved ZDR agreement on Anthropic's own platform or a cloud partner. Fable 5.1 shares its model with Mythos 5.1, so the 30-day covered-model retention applies unless the ZDR-until-EFS arrangement covers the account. Ask which one you have. On 1 September 2026 the Vercel AI Gateway's public model list showed the same model with zero data retention set to none and no-training set to all. A contractor that reaches a model through a gateway, a reseller, or a construction platform gets that intermediary's retention terms, not the model vendor's.
Put the feature name in the contract review
"We use ChatGPT" or "we use Claude" is not enough for a project risk register. The review should identify the plan and the feature. Uploading a PDF to a saved library is different from sending extracted text to an eligible stateless endpoint. A connector that searches SharePoint introduces different access and retention questions than a standalone prompt. Web search can disclose part of a query to a third party. Prompt caching intentionally keeps material available for reuse.
Ask the vendor or integrator to answer these questions in writing:
Is this a consumer account, a company workspace, or an API organization? Who administers it?
Are inputs and outputs used for training by default, by opt-in, through feedback, or after a safety review?
What customer content is retained for abuse monitoring, product history, files, caches, or application state? For how long?
Does ZDR apply to this model, endpoint, region, and feature? What is excluded?
Which people can access content, under what trigger, and with what audit record?
Which subprocessors, connectors, plug-ins, web-search providers, logging tools, and cloud services receive the data?
What happens when a user deletes a chat, removes a file, leaves the company, or closes the workspace?
Can the company enforce retention, sharing, connector access, and model availability for every user?
Where is content processed and stored? Can the deployment meet project-specific residency requirements?
Can the vendor preserve or produce records for litigation, an owner audit, a public-records request, or a regulator, and does that conflict with the project's record policy?
The answers belong in the procurement file with the order form, data-processing addendum, security review, and approved-use matrix. A marketing page can describe the default. The signed agreement and live configuration govern the deployment the contractor actually has.
Construction records create two risks at once
Some AI conversations are transitory work product. Others become evidence of how a bid, change, safety decision, or owner communication was developed. A blanket rule to delete everything can conflict with contract recordkeeping, insurance requirements, litigation holds, or public procurement. Keeping every prompt forever creates a different exposure.
The records team should decide which AI outputs enter the project record and where the official copy lives. If a project manager uses a model to organize an RFI draft, the approved RFI in the project management system may be the record. The chat may be disposable after a defined period. If the prompt includes an engineer's analysis or documents a disputed schedule decision, counsel may reach another conclusion. The AI tool should not become an accidental system of record.
Bid information needs the same discipline. Unit prices and subcontractor quotes are commercially sensitive even when they contain no personal data. An estimator can reduce exposure by sending only the relevant specification sections, removing company and project names, and asking for structure or comparison rather than uploading the complete bid room. Data minimization is useful even under a strong contract because access mistakes and integration logs can occur inside the contractor's own environment.
Plans demand more care. Owner licenses and confidentiality clauses may limit where drawings can be copied or processed. Government work may add controlled-information rules. A provider's general security certifications do not decide whether a particular upload satisfies those obligations. The project contract, the deployment boundary, and the company's written approval do.
A practical first month
Start by finding where files already went. Ask preconstruction, project management, VDC, accounting, and business development which personal and company AI accounts they use, what they upload, and whether browser extensions or meeting bots are involved. Frame the exercise as an inventory. Employees hide the useful details if the first message threatens discipline.
Then choose a small approved set of workflows. Public research and blank-template work can run in a controlled business workspace. Confidential text tasks may use a company API application with a documented retention window, input redaction, and logging that omits content. Restricted plans can stay out until the company has approved an architecture for that project. Local or self-hosted models may be part of that architecture, but the same questions apply to telemetry, backups, access, updates, and the software wrapped around the model.
Finally, verify rather than assume. Export the workspace settings. Check whether ZDR is active for the project or team. Confirm that request logs omit content. Upload a test file and follow its deletion path. Review the configuration again when a model, connector, endpoint, or contract changes.
The sentence "we don't train on your data" is useful. A construction company still needs to know where the bid set goes.
· Anthropic
1 September 2026. ZDR on Fable 5 and 5.1 for eligible customers until EFS.