gd AI mate← Good thinking

Good thinking

Where your data actually lives

The contract already walls off your data. Where it physically sits keeps you out of court.

Since the first of March 2023, anything a business sends OpenAI through the API, or the Enterprise, Team and Business tiers, is walled off from training. That's the default. Written into the contract, not a toggle you go digging through settings to find. Most people who are scared of AI dont know that, and i get why. The fear got set by the free consumer version, where the rules are looser, and thats exactly the gap that burns small businesses. Same logo on the door, completely different agreement behind it.

Anthropic, the mob behind Claude, works the same way. Their commercial products dont train on your inputs by default and never have. On the 28th of August 2025 they moved their consumer tiers to opt-out, train-by-default, so a punter using the free Claude app has to actively switch it off. The commercial side they left alone. So when you hear "they changed the rules and now they train on everything," check which door they walked through. The business door didnt move.

Heres how it actually runs when we build for a client. G'dai Mate pushes your tokens through those same commercial agreements. Your data isnt ours to keep and it isnt theirs to learn from. We sit on the business side of the contract on purpose, because thats the side with the wall.

Now the bit almost nobody talks about, and its the one that keeps you out of court. Where the data physically sits.

You can run this stuff onshore. Azure OpenAI gives you a contractual no-training term same as the rest, and if you set up a Regional deployment in Australia East, the processing and the storage stay in the country. Claude runs on Amazon's Bedrock out of the Sydney region, ap-southeast-2, and that setup has been assessed to IRAP PROTECTED, the grade government uses for sensitive material. So your customer data never has to leave Australian soil. One catch worth knowing. You have to pin it to Sydney. Leave cross-region routing on and it can quietly send your prompts somewhere else to get processed, and now your data's offshore without you deciding it.

Why does onshore matter so much when the no-training promise already holds? Because of who wears it when something goes wrong.

The Privacy Act 1988 has a piece called Australian Privacy Principle 8, backed by section 16C, and it does something a lot of owners have never had spelled out to them. If you hand personal information to an overseas provider and that provider mishandles it, you're still on the hook. Not them. You. The liability follows your data across the border and stays stapled to your business. So the American vendor has a breach, and the Australian regulator comes knocking on your door in Toowoomba or wherever you are, because in the eyes of the law it was your information and you sent it overseas.

Thats the whole reason onshore is worth paying for. Its a liability feature. Keep the data in an Australian data centre and the liability has nowhere foreign to travel to. You know exactly which law applies and exactly who answers for it, and its the same jurisdiction you already live and trade in.

I ran a cafe for years before this. You wouldnt store your cash in a safe you'd never seen, in a building you couldnt point to. Same instinct, same money, just information now instead of notes. Ask where it lives. Then ask who's contractually barred from touching it, and what happens to you personally if it leaks. Get those answers in writing and a business can be genuinely, properly secure. Most just never think to ask.

What this leans on

Book a call