HomeResources › Keeping bid content private

Keeping bid content private with AI

The short version: on Claude's individual plans, one toggle decides whether your work can be used to train future models, and it is not off until you turn it on. Somebody already answered it when the account was set up. Check Settings > Privacy, turn Help Improve Claude off, and retention drops from up to five years to the standard 30 days. Commercial plans are not used for training by default. After that it is habits rather than settings: give the tool one tender folder rather than a drive, keep unrelated material out of it, and stay close to anything heading for a live submission.

Bid folders are among the most sensitive things a small company holds. A single tender project can contain a commissioner's draft specification under an explicit confidentiality clause, your own pricing model, staff names and CVs, TUPE information, safeguarding case detail, and the evidence library that took you years to build. Nobody wants to explain to a client how any of that ended up somewhere it should not be.

So the question we get asked most often is a fair one. If I put my bid through an AI tool, where does it go, and could it come back out in somebody else's answer?

It is also a question the buyer side has already formed a view on. The Cabinet Office's PPN 017, Improving transparency of AI use in procurement, tells contracting authorities to put in place proportionate controls so that suppliers do not use confidential contracting authority information, or information not already in the public domain, as training data for AI systems. Its own worked example is a supplier using confidential government tender documents to train a model to write future tender responses. That is the exact risk this paper is about, written down in the government's own guidance, and it is a good reason to be able to say plainly what your settings are.

The honest answer is that it depends on which account you are using and on one setting inside it, and that the rest is ordinary professional discipline rather than anything exotic. Here is how we handle it, using Claude as the worked example, with the principles that carry over to any tool you might use instead.

1. Know which plan you are on

This is the fork in the road, and a surprising number of people do not know which side of it they are standing on.

Claude's individual plans, meaning Free, Pro and Max, come with a choice about model improvement. If you allow it, your chats and coding sessions can be used to help train future models, and Anthropic may keep that data in a de-identified form in its training pipelines for up to five years. If you do not allow it, new sessions are not used for training and the standard retention period applies, which is 30 days.

Claude's commercial plans are different. Claude for Work, Team, Enterprise, Claude for Government and Claude for Education, along with API use, sit under Anthropic's commercial terms, and by default inputs and outputs on those plans are not used to train models. The consumer toggle does not appear because there is nothing to choose. The one thing to know is that the default is not absolute: if someone submits feedback through the thumbs up or thumbs down button, or otherwise opts in, that conversation can be used. Team and Enterprise owners can switch the feedback button off for their organisation under organisation settings.

Most bid teams we work with run on Claude Pro, which is an individual plan. That means the setting in the next section matters to you.

The principle that travels: before you paste anything confidential into any AI tool, find out whether you are using it under consumer terms or business terms. Free and personal tiers are usually where training on your content is permitted, and business tiers are usually where it is not. Read the terms for the plan you are actually on, not the reassuring line on the product's front page.

2. Switch off Help Improve Claude

Start by putting aside the idea that this is off until you turn it on. It is not a dormant setting waiting to be discovered. Anthropic made it a required choice: new users pick their preference during signup, and existing users were given an in-app pop-up and a deadline of 8 October 2025, after which a selection had to be made to carry on using Claude. So whoever set up your account has already answered this question, on your behalf, at some point.

Whether they meant to is another matter. The pop-up led with a large accept button and, as reported at the time, the sharing toggle beneath it was already switched on. Clicking through a consent dialogue at speed is the most ordinary thing in the world. That is precisely why this is worth two minutes of your attention rather than an assumption.

Go and look at what your account actually says. On an individual plan:

  1. Select your name at the bottom-left of Claude, then Settings.
  2. Select Privacy.
  3. Under Help Improve Claude, turn the toggle off.

Three things are worth understanding about what that does.

It applies from the moment you switch it. Turning the setting off means new and resumed chats will not be used for future training, and Anthropic stops drawing on previously stored sessions for future training runs. What it cannot do is reach into a training run already in progress, or a model already trained. That is precisely why it is a setting to check on day one rather than after your first tender.

Safety review is a carve-out. If a conversation gets flagged by Anthropic's safety classifiers it may still be used to improve trust and safety systems and enforce the usage policy, whatever your setting says. For ordinary bid work this is not something you will meet, but it is part of an honest answer.

Deleting a conversation removes it. A deleted conversation goes from your history immediately, is removed from back-end storage within 30 days, and is not used to train future models.

The thumbs up and thumbs down button runs on a separate track, and this one catches people out. Turning off Help Improve Claude does not remove the rating buttons, and rating a response is treated as its own act of sharing: it sends the entire related conversation to Anthropic, where it is kept for up to five years and may be used to analyse the service, conduct research and train models. Anthropic de-links feedback from your user ID and does not combine it with your other conversations, but the content still goes.

It is not that feedback overrides your setting, exactly. The setting governs the general flow of your chats; the button is you volunteering one specific conversation on top of that. The effect, though, is the one that matters to a bid team: a conversation you thought was excluded can be sent by a single click on a thumbs-down. Note also that the same applies on the commercial plans, where the default of no training holds until someone submits feedback.

There is no individual-plan switch to hide the buttons. Team and Enterprise owners can turn them off for their whole organisation through the Rate chats setting under organisation settings, and Console admins have the equivalent. On Pro, the control is your own restraint. Rate freely on ordinary work, and think twice before rating a conversation full of a client's commercially sensitive material. If a tool gets something badly wrong on a live bid and you want it fixed, describe the problem separately rather than submitting the bid conversation itself.

One nuance that matters for bid work. Anthropic's wording excludes raw content pulled in through connectors and MCP servers from training data, but includes anything that is copied into the conversation itself. In practice, when a drafting tool reads a case study out of your evidence folder and quotes a figure from it into a response, that text is in the conversation. Treat your support files as in scope and switch the setting off. It costs nothing and removes the question.

3. Scope what the tool can see

Settings deal with training. Scope deals with everything else, and it is the part people skip.

Anthropic's own safety guidance for Cowork recommends creating a dedicated working folder rather than granting broad access to a drive. Bidwin was built to work that way from the start. Each tender gets its own project and its own root folder, holding that tender's pack and the evidence relevant to it, and nothing else. Claude sees that folder. It does not see your Documents folder, your accounts, or the shared drive with every client you have ever had.

A few habits go with it:

4. Match your oversight to the stakes

Agentic tools can work through a task without stopping to check with you, which is exactly what you want for a long overnight drafting run and exactly what you do not want when the work touches a live submission.

Use the tighter approval mode when a task involves a document from an unfamiliar source, a tool or plugin you have not used before, or anything that would be awkward to undo. Save the run-without-asking setting for routine work you are supervising in real time.

There is a specific reason this matters in procurement. Tender packs arrive from third parties, get downloaded from portals, and pass through hands you do not control. Text hidden inside a document can be crafted to steer an AI tool into doing something you did not ask for, which is known as prompt injection. Anthropic screens for it, but no screening is perfect. The practical defence is the same one that protects you from a bad clause in an ITT, which is a human who is actually reading the thing. If a tool starts reading files you never mentioned or drifting well beyond the task you set, stop it and look at why.

The same caution applies to scheduled and unattended runs. Start them on low-risk work such as summarising or compiling, review the output after each run, and pause anything you are not actively using.

5. Habits that outlast any one setting

Product menus get rearranged and policies get updated. These hold regardless.

Assume everything you paste is stored somewhere. Not necessarily used for training, but stored, for some period, under someone's terms. Decide what you are comfortable with on that basis rather than on the assumption that it evaporates.

Check the tender's own confidentiality clause. Procurement documents commonly restrict disclosure of the pack, and PPN 017 points contracting authorities towards controls on exactly this. Whether a given cloud AI service counts as disclosure to a third party is a question for your organisation and, if the value warrants it, your legal adviser. It is not a question a settings toggle answers.

Keep a light record of what you used. Which tool, on which plan, with training off, checked by which named person. It takes a line in your bid log and it is the difference between a confident answer and an awkward one if a buyer asks.

Review it once a year, or when you change plan. Moving from a personal subscription to a business one, or bringing in a new person on their own account, is exactly when a carefully configured setup quietly stops being configured.

What to tell a buyer who asks about AI

AI disclosure questions are now a standard part of the toolkit. PPN 017 gives contracting authorities model wording to drop into an invitation to tender, and while the PPN formally applies to central government departments, their executive agencies and non-departmental public bodies, it invites other public sector authorities to take the same approach. Expect to meet the question.

The instinct to say as little as possible is usually the wrong one, and the PPN's own framing is the reason why. It states plainly that suppliers' use of AI is not prohibited, and compares it to engaging a bid writer. The example questions in Annex B ask whether AI or machine learning tools were used in any part of the submission, ask for details, and then ask you to confirm that anything AI helped generate has been checked and verified for accuracy. A separate question asks whether AI features in the service you are proposing to deliver.

Two things follow. First, the accuracy confirmation is the heart of it, which puts the emphasis exactly where a serious bid team would want it: on whether a human checked the claims. Second, the Annex B questions are for information only and should not be scored or taken into account when assessing a tender. That is a genuine protection, though not an unlimited one, because authorities remain free to ask and evaluate other AI-related questions of their own, provided they say up front whether those will be scored.

So answer the question the tender actually asks, plainly. A team that can name its tools, show that every claim traces to a piece of its own evidence, and confirm that a named person checked the response before it went in is answering from a position of strength. A team that avoids the subject is not. How the wider Procurement Act regime bears on AI-assisted bidding is a paper of its own, and it is coming.

Where Bidwin sits in this

Worth being clear, because it is a reasonable thing to ask of any supplier. Bidwin does not receive your bid content. It is a set of instructions, templates and checks that you install into your own Claude account, so your tender pack, your evidence and your drafts stay in your own folders under your own subscription, governed by your agreement with Anthropic rather than by us. We do not hold your bid library, and we cannot read your drafts.

Bidwin also checks the practical things before a run starts, including whether your files are properly downloaded rather than cloud placeholders, and it works one scoped tender folder at a time by design. The setting in section 2 is yours to switch, on your own account, and nobody else can do it for you. Our Getting Started guide puts it in front of clients before step one, because the sensible moment to do this is before the first tender, not after it.

Frequently asked questions

Is my bid content used to train AI models?

On Claude's individual plans it depends on one setting. If Help Improve Claude is switched on, new and resumed sessions may be used for model training and kept in a de-identified form for up to five years. Switch it off and new sessions are not used for training, and the standard 30-day retention applies. Commercial plans such as Claude for Work, Team and Enterprise are not used for model training by default, though submitting feedback through the thumbs up or thumbs down button sends that conversation regardless of plan.

Is Help Improve Claude off by default?

No, and it is safer to assume nothing. Anthropic made it a required choice rather than a silent default: new users select a preference during signup, and existing users had to make a selection by 8 October 2025 to keep using Claude. The pop-up put a prominent accept button above a sharing toggle that was already switched on, so accepting without registering it was easy to do. Check Settings, then Privacy, and see what your account actually says.

Does the thumbs up or thumbs down button still send my chat if model training is off?

Yes. Rating a response is a separate act of sharing. It sends the entire related conversation to Anthropic regardless of your model improvement setting, where it is kept for up to five years, de-linked from your user ID, and may be used for research and model training. There is no individual-plan switch to hide the buttons; Team and Enterprise owners can disable them organisation-wide through the Rate chats setting. Avoid rating conversations that contain confidential bid material.

How do I stop Claude training on my data?

Select your name in the bottom-left of the app, choose Settings, then Privacy, and turn off the toggle under Help Improve Claude. Do it before you load confidential material, because the setting applies only from that point and cannot undo a training run already in progress.

Can I put a confidential tender pack into an AI tool?

That is a judgement for your organisation rather than a setting. Check the confidentiality clause in the tender documents and your own client agreements first. Where it is permitted, switch model training off, keep the working folder scoped to that one tender, and keep a record of the tools used in case a buyer asks.

Does Bidwin-AI see my bid content?

No. Bidwin installs into your own Claude account. Your tender pack, evidence and drafts stay in your own folders under your own subscription, governed by your agreement with Anthropic rather than by us.

What should I tell a buyer if they ask whether we used AI?

Answer the question the tender actually asks, honestly and briefly. The Cabinet Office's PPN 017 says suppliers' use of AI is not prohibited, and its example disclosure questions ask whether AI tools were used in the submission, for details, and for confirmation that anything AI helped generate was checked and verified for accuracy. Those Annex B questions are for information only and should not be scored, though authorities may ask and evaluate other AI questions of their own. Being able to name your tools, trace every claim to your own evidence and point to a named human check puts you in a stronger position than avoiding the subject.

Sources and currency. The Claude details here were checked against Anthropic's privacy centre (privacy.claude.com) and help centre (support.claude.com) on 25 July 2026. The procurement guidance is PPN 017 (Cabinet Office, 17 February 2025), which replaced PPN 02/24 for procurements commenced on or after 24 February 2025, and which contains Crown copyright material licensed under the Open Government Licence v3.0. Product settings and policy notes both change, so check the current position at those sources. This paper is practical guidance from a bid professional, not legal advice, and it makes no certification claims on anyone's behalf. Last reviewed 25 July 2026.

Draft with your own evidence, in your own account

Bidwin Core produces evidence-cited first responses in hours, inside your own Claude subscription. Founding members get Bidwin Watch free.

Get Bidwin →

← Back to all resources