Ask a supplier in this category whether your clients’ mail will train its AI, and a careful one will not answer no. It answers in two sentences rather than one, with an adjective in the middle carrying most of the load. That is the correct answer. A firm reading it as evasion goes looking for a flat denial instead, and eventually finds one from somebody who should not have offered it.
- The fear underneath the question is about persistence, not contact. A model read your mail this morning, because that is the product. What matters is whether anything of it survives inside something strangers query.
- Every honest commitment here says generalized models, and the word is the clause. What sits outside it is the supplier making the product better for you, which is most of what actually happens to your mail.
- Nobody can train on a copy that was not kept. Retention sits upstream of training and answers more, and the training sentence says nothing at all about how long anything lives.
- The commitment has an exception written into it, and the exception is yours to give. The route from a practice into a training corpus runs through somebody in your office far more often than through your supplier.
What the fear is actually about
The picture in a partner’s head is specific, and it is worth saying out loud rather than treating as vague anxiety. A client’s figure, or their identifying number, or the sentence they wrote about their marriage, comes back out of somebody else’s chatbot in another year. Nobody has been hacked. The information simply became part of a thing that other people ask questions of.
That fear earns its own section, because training has two properties nothing else in your data handling has.
It is not reversible. Every other exposure has a remedy with a mechanism behind it: delete the record, close the account, rotate the credential, ask for the export back. A message absorbed into a model’s weights is not a record any more. There is no row to delete, and the deletion clause you negotiated does not reach it.
And it is not local. Every other failure in a practice surfaces somewhere you have a relationship: a client, a colleague, a supplier, an insurer. This one surfaces in a system belonging to a company you never contracted with, in front of a person you will never meet, and you will not know it happened.
Now set beside that what is not training. A model reads your correspondence to rank it, to summarize it, to answer a question about an attachment, to write a draft. That contact is constant, it is the entire reason you bought the software, and no commitment on any page removes it. What happens to that message afterwards is the whole question. Under sound terms it is processed, an answer comes back, and the copy is governed by a retention clause. Under a consumer product’s terms it may be kept and used to build the next model.
So the precise question is not whether AI sees client data. You settled that when you connected the mailbox. The question is whether anything of it persists inside something other people use, and everything that follows is a way of getting at that one.
The adjective is the clause
Here is a real commitment, from a document you can go and read rather than a paraphrase of the genre. Point’s privacy policy, at section 6.5:
Point does not use Customer Content to train generalized third-party large language models or generalized foundation models unless you expressly authorize it. Point may use Customer Content to provide and improve the Services for you or your organization, including improving user-facing features, safety, security, reliability, and quality.
(Privacy policy, version 1.0, effective 7 July 2026, checked 19 August 2026.)
Two sentences, because there are two facts, and a single sweeping one would have to drop one of them. The first names a category of model: generalized, foundation, third-party. Not every model, and not the supplier’s own tuning of the product you are paying for. The second says your content may be used to make that product better.
Firms read the first sentence and skip the second, which is exactly backwards, because the second sentence is where nearly all of your mail actually goes.
Then it is worth knowing what improving the service consists of in a product like this, because the word sounds like a euphemism for training and mostly is not. Ranking that adjusts to which senders you actually open. A search index that becomes more useful as it fills with your own correspondence. Prompts and routing rewritten after somebody watched where the software got a thread wrong. A set of real failures kept as a test, so the next change can be checked against them before it ships. Every one of those uses your mail. None of them is a foundation model being retrained, and a supplier that promised to do none of them would be promising you a product that never gets better at your work.
Which means the two of you are using one word for different sets of activities, and neither party is being slippery about it. Training has no agreed boundary between a firm’s vocabulary and a vendor’s.
So stop asking about the verb and ask about artifacts and lifespans instead. What does the software make from my mail, where does each of those things live, and does any of it outlast my account. Those have factual answers. “Do you train on my data” has a definitional one, and how to read the answer you get back is a discipline of its own.
The copy has to exist first
Nothing can be trained on data nobody kept. That sounds too obvious to write down, and it reorders your diligence when you take it seriously: a training clause governs one use of a copy, and a retention clause governs whether the copy is there to be used. If you could only get one of the two in writing, the second covers more ground.
So count the copies, because in this category there are more than firms expect.
Your supplier holds the mail, and it holds what it made from the mail. Search indexes, embeddings, summaries, the tasks lifted out of a thread. Point’s subprocessor list itemizes those beside the content they came from, which is the shape worth wanting, and the reason it matters here is narrow: a list that names the derived material is a list you can ask a deletion question about. Does deletion reach the index and the embeddings, or does it reach the messages and leave behind everything computed from them. A summary can easily outlive the correspondence it summarized.
Then there is a copy on the model provider’s side, and this is the one the training conversation hides. Point’s data processing addendum states it plainly rather than leaving it to be discovered:
Customer acknowledges that AI providers and other Subprocessors may process prompts, requests, outputs, metadata, logs, and telemetry for safety, abuse prevention, fraud prevention, security, operational reliability, and legal compliance, subject to applicable provider terms and controls.
(Terms, data processing addendum section 7.2, checked 19 August 2026.)
None of that is training. All of it is a copy of an excerpt of your client’s correspondence sitting on a third party’s infrastructure for a period set by that third party’s terms rather than by yours. A firm that took a no-training answer and stopped has not asked how long that copy lives, and it is the copy furthest from anything the firm controls.
Last, the copies you make yourself, which is the exposure nobody counts. A thread forwarded to your own personal address so you could look at it at home. A statement dropped into a spreadsheet tool to get a total out of it. Those leave your supplier’s terms entirely and land under somebody else’s.
How long any of it is kept, and what survives in backups afterwards, belongs in the terms rather than on a security page, and the conditions hung off that clause are worth more of your attention than the number in it.
The link you have no contract with
Your agreement is with the company selling you the mail client. The models are somebody else’s, and this is where a training commitment stops being a promise about outcomes and becomes a promise about conduct.
Read what the commitment actually says at that boundary. Point’s addendum:
Where the Services use third-party large language models or AI services, Point will use configurations intended to prevent Customer Personal Data from being used to train or improve generalized third-party models, consistent with applicable provider controls and terms.
(Terms, data processing addendum section 7.1, checked 19 August 2026.)
The subprocessor list carries the same shape beside each AI provider: used under business terms with no-training controls where available. Configurations intended to prevent. Consistent with applicable provider controls. Where available.
That is a supplier undertaking to use the switch wherever there is one. It is not a warranty about what another company does inside its own systems, and no supplier in this category can give you one, because none of them own the model. Read the conditionals as competence rather than hedging. The alternative drafting, a flat guarantee about a third party’s internal behaviour, is a sentence written by somebody who has not thought about who would be liable for it.
There is a second clause that decides how long your answer stays true. Point’s terms, at section 6.7, reserve the ability to select, route, replace, or change AI models, embedding models, model providers, infrastructure providers, and processing methods at any time. Every serious product in this category holds that right, and it has to, because the models change every few months and a product frozen to one provider would be a worse product within the year.
So the answer you were given in August describes a routing decision, and the routing can change without anything visible changing in the software. The durable half of the answer is the conduct commitment, which survives the swap. The half about which company holds the model is a fact with a shelf life, and the reason a dated, versioned subprocessor list is worth more than any paragraph of assurance is that it makes the swap something you can notice.
The exception is on your side
Both of Point’s sentences carry the same escape, and so does every equivalent clause you will read: unless you expressly authorize it. That is not a loophole. It is how the option stays yours rather than being decided for you. But look where it puts the risk.
The path from a practice’s mailbox into a training corpus that anybody has actually walked does not begin with a supplier breaking a contract. It begins with a person agreeing to something.
The shapes are ordinary and none of them feel like a decision at the time. A research or early-access program with a consent screen nobody reads to the bottom. A toggle offering to help improve the product, in some other tool entirely, defaulted on. A feedback button that submits the thread along with the complaint about the thread. And the one that actually happens in March: a preparer with a K-1 they cannot make sense of at eleven at night, and a free summarizer whose consumer terms say the opposite of everything your supplier’s say.
Which inverts the picture most firms carry. The product you spent a fortnight interrogating is the safest surface in your practice, because it is the only one anybody looked at. Your exposure is concentrated in the tools nobody bought, nobody diligenced and nobody wrote down, and a firm holding an excellent vendor answer and nothing else has bought a good response to a question it is not being asked.
The instruction that belongs to this page is a single line, and the rest is a policy question for another day. Authorizing this is not something one person should be able to do on a Tuesday without anybody else knowing. Decide who at your firm may accept terms on behalf of the practice, and make an offer to improve somebody’s model an item they have to bring to that person.
What to say when a client asks
This is now a question clients ask, and firms want to answer it in one word. The one word is the problem: no is the most reassuring sentence available and the one most likely to be wrong, and it fails in the worst possible way, because the client discovers the exception rather than being told about it.
Three sentences hold up, and they run in this order for a reason.
A model does read your correspondence, because that is how the software works. Lead with the concession. A client who later learns this will remember which of the two things you told them, and everything after it is believed because of it.
Under our agreement it is not used to build the general AI models other people use, and the AI providers are used with training turned off wherever that control exists. That is the actual commitment, stated at its actual width, and it is stronger than a slogan because you can hand over the document it comes from.
It is used to run and improve the service for us, it is kept for this long, and here is the list of companies that touch it. The part firms leave out, and the part that makes the answer sound like a professional’s rather than a brochure’s.
What not to write anywhere near a client is that their data is never seen by AI. It is false about a product you bought precisely because it is not, and a sentence like that in a document with your firm’s name at the top is worse than saying nothing. Where any of this belongs, whether it is notice or something the client must sign, and why the format matters for a 1040 client, is a different question with its own answer.
Where does Point fit?
Every question above can be put to Point, and what is worth setting out here is which document holds each answer rather than a paragraph telling you the answers are good.
- The commitment exists in two documents, and the terms tell you which one counts. Section 6.5 of the privacy policy and section 6.8 of the terms carry the same position, and the terms state that the privacy policy is not a contractual term unless expressly incorporated. The contractual version is also slightly wider in its second sentence, adding the development of aggregated or de-identified information that does not identify you, your users or individuals. Read the one inside the agreement, then compare.
- The model providers are named rather than described, and the wording is honest about its limit. Subprocessors carries a version and an effective date, lists AWS for hosting, Anthropic and OpenAI for the AI processing, and Google for text embeddings, and says of the AI providers that they are used under business terms with no-training controls where those exist. That is the conduct commitment above, in a document you can diff against the copy you kept.
- What Point makes from your mail is itemized beside your mail. Indexes, embeddings, summaries, points and outputs are listed as things processed, not left to be inferred from a promise about email, which is what makes it possible to ask whether deletion reaches them.
- The providers and the models can change at any time, and the terms say so at 6.7. Take that as the reason to watch the dated list rather than as a reason to distrust the answer. A product that could never change model would be a worse product by next spring.
- A mailbox carrying return information sits outside what the standard service covers. Tax-return data is one of the named regulated categories, and nothing but an executed supplement brings it inside. Raise it while you are still deciding rather than once a season has been run on it.
- A message locked end to end is the one place the question dissolves. Point cannot read it, so there is no excerpt, no derived index entry and no copy on a provider’s infrastructure to have an opinion about. The cost is stated rather than buried: nothing sealed that way is ranked, summarized or turned into a task. It is a lane for a few messages a year, not a way to run a practice.
Every capability, written out rather than summarized, is on the benefits page. Point for accountants reads it back in a practice’s terms, and Point is the shortest version there is.
Common questions
Can I tell clients their data is never used to train AI?
Not in those words, because the commitment you are relying on is narrower than the sentence and has an exception in it that belongs to you. What you can say is the true version, and it is more convincing: a model does read the correspondence, under the agreement it is not used to build the general models other people query, and it is used to run and improve the service for your firm. Lead with the concession rather than burying it, because that is the sentence a client will later find out about on their own.
Is a no-training promise worth anything if I cannot test it?
It is worth something and it is worth less than the answers you can test, so treat it as a different class of item. There is no export to request and no ticket to raise, because you cannot inspect a model for a client’s data, which leaves you two levers rather than three. Get the sentence into the document that binds rather than the one that describes, and shrink the population it applies to by asking how long copies are kept and by whom, which is the question that actually has evidence behind it.
Does “improve the service” mean they are training on my mail after all?
Usually not, and the honest answer is that the phrase covers a set of things your firm and your supplier would not describe with the same word. Most improvement in a product like this is ranking that adapts to your senders, an index that fills up, prompts rewritten after a failure, and a test set built from real mistakes. Ask about artifacts and lifespans instead of about the verb: what does the software make from my mail, where does each of those live, and does any of it outlast my account.
Our supplier says the AI providers have training switched off. Is that a guarantee?
It is a commitment about their conduct, which is the strongest thing anybody in this category can give you, because they do not own the models. The drafting to look for says the supplier will use no-training configurations where the provider’s controls allow, and the conditionals are the mark of somebody who has thought about who would answer for the sentence. Pair it with the clause letting them change providers, and you can see why the dated subprocessor list matters more than the assurance.
What is the biggest training risk in a small practice?
Almost certainly not the product you interrogated. The commitment in your supplier’s terms is conditional on your own express authorization, so the realistic route into a training corpus is a person in your office agreeing to something: a research programme with a consent screen, a helpful toggle left on in some unrelated tool, or a free summarizer used on a K-1 at eleven at night in March. Decide who at your firm can accept terms on the practice’s behalf, and the vendor work you already did starts covering the surface you thought it covered.
The short version
- The fear is about persistence, not contact. A model reads your mail because that is the product you bought. Training is the case where something survives inside a system other people query, which is the one exposure with no deletion route and no local symptom.
- The commitment is two sentences and the adjective is the clause. Generalized third-party and foundation models sit inside it. The supplier improving the product for you sits outside it, and that is where nearly all of your mail actually goes.
- Nobody trains on a copy that was not kept, so retention answers more than training does. Count the copies: the supplier’s store, everything derived from your mail, an excerpt on the model provider’s infrastructure under its own terms, and the ones your own people make.
- Your contract is with the mail client, not the model. A promise to use no-training configurations where the provider allows them is a commitment about conduct, and it is the honest shape, since the routing underneath can change at any time.
- The exception is customer-side. The realistic path into a training set starts with somebody in your office agreeing to something, which makes who may accept terms on your firm’s behalf a more useful decision than any further reading of a vendor’s policy.
The wider question of whether to connect a practice mailbox at all is in the client data guide, and what an AI email client is defines the category. What changes inside a firm once reading becomes cheap is in using an AI inbox without breaking confidentiality, and how far you let the software go, which sets your exposure more than any clause, is in is it safe to use AI with client financial data.