← Blog
· 10 min read

Privacy in 2026: You Are Paying, and They Are Still Training on You

For twenty years the deal was simple enough to fit on a bumper sticker: if the product is free, you are the product. In 2026 that sticker is out of date. You pay for the product, and you are still the product. The subscription buys the features. It does not buy your way out of the training set.

This is an overview, not an exposΓ©. It does not need one. The practices described here are, for the most part, written down by the companies themselves, in the terms of service and privacy policies you accepted. The scandal of 2026 is not that anyone is hiding what they do with your data. It is that they stopped bothering to.

A laptop at night showing a plain checkout panel with a violet button. A hand holds a blank card toward it, while a faint stream of translucent photos and documents drifts out of the back of the screen into the dark.
You pay at the front. The data leaves out the back.

Where privacy stands in 2026

Three things are true at once, and holding all three is the whole picture.

The law is stronger than it has ever been. Europe has the GDPR and the AI Act. Most US states now have a consumer privacy law, and several treat biometric data as a special category with its own rules. Regulators in the EU, the UK and Brazil have all forced large platforms to pause or change how they train on user content. On paper, you have more rights over your data than at any point in history.

The demand for data is greater than it has ever been. Every company with a product now believes it needs a model, and every model needs something to learn from. The public web has been scraped several times over. The valuable material left is what sits inside products: your documents, your photos, your messages, your recordings, your face. That is where the pressure now falls.

And the gap between the two is where you live. Rights exist, but they are exercised by opt-out, one product at a time, against defaults that are set to yes. The law says you may refuse. The product is designed so that you will not.

The deal changed and nobody told you

The free-product bargain was at least legible. You used a service without paying, and in return your attention was sold to advertisers. You could dislike it, but you understood it, and paying was the way out. Premium tiers were sold on exactly that promise for a decade: no ads, no tracking, you are the customer now.

Training changed the economics underneath that promise. Advertising needs your attention, which a paying customer withholds. Training needs your content, which a paying customer produces in greater volume and higher quality than anyone else. The people who pay for a writing tool write the most. The people who pay for a photo service upload the most. The people who pay for a meeting recorder talk the most. From a model’s point of view, subscribers are the best data on the platform.

The quiet inversion: under the advertising model, paying made you less valuable as raw material. Under the training model, paying makes you more valuable. Nothing in the price reflects that, and nothing in the checkout tells you.

How paying customers end up as training data

It almost never happens through a dramatic policy change. It happens through language that was already there, or that arrived quietly, and that reads as harmless until you ask what it permits.

The phrases to know are “to improve our services,” “to develop new features,” and “to train and improve our models.” In 2026 all three mean the same thing. A clause saying the company may use “your content” for those purposes is a clause saying your content is training data. A separate clause promising not to sell your data is true and irrelevant: nobody needs to sell what they can use.

Over the past two years this has played out in public more than once. A design-software company’s updated terms were read by its own paying customers as permission to train on their work, and the company spent weeks clarifying. A video-conferencing service’s terms appeared to allow training on meeting content and were rewritten after an outcry. A workplace messaging tool turned out to be using customer data for its models by default, with an opt-out that required emailing support. A professional network switched on a training toggle for its members and told them afterwards. A social platform announced it would train on public posts from adults and, in Europe, had to offer an objection form under regulatory pressure. In each case the pattern was the same: the setting was already on, and the company’s position was that you had agreed.

None of those companies were hacked. None of them broke a law they could not argue their way around. That is the point. This is the system working as designed.

The playbook, step by step

Once you have seen it a few times, the sequence is recognisable anywhere.

1. Default to yes

Training on user content is enabled for everyone. Consent is treated as having been given by using the product, or by not having turned it off. The company can say, truthfully, that every user has a choice.

2. Put the choice where it will not be found

The toggle exists. It lives under Settings, then Privacy, then Data, then Advanced, then a heading with a name that does not say “training.” On some products it is per-workspace and only an administrator can reach it. On others it is an email address.

Close-up of a phone showing a very long list of grey toggle switches. Deep in the list, one switch is on and glowing violet, with a thumb hovering over it.
The setting is real. It is also on, and you had to know to look.

3. Make the opt-out forward-looking only

Turning training off stops new content going in. It does not remove what was already used. A model trained on your data last year keeps whatever it learned; the opt-out is a promise about the future, not a correction of the past. The policies are careful to say this, in the passive voice.

4. Price the privacy tier above the premium tier

Where a no-training guarantee is offered at all, it increasingly sits on the enterprise plan, sold to companies with legal departments. The individual who pays for Pro is, in the taxonomy of the pricing page, not the customer who was promised privacy.

5. Update the terms, notify by banner, move on

“We have updated our terms” is now the most ignored sentence on the internet, and the companies know it. Continued use is acceptance. The change is effective in thirty days. The banner is gone in one.

Why they no longer hide it

A few years ago a company caught training on customer content would have denied it. Today many state it plainly, and the reason is not courage. It is that three things they used to fear have stopped biting.

Backlash fades. Each of the incidents above produced a week of anger, a clarification, sometimes a revised toggle, and then a return to the default. Almost nobody left. The lesson companies drew was that the cost of being caught is a blog post.

Competitors are doing it. When every product in a category trains on its users, refusing to is a handicap, not a virtue. The company that abstains ships a worse model. The incentives run one way.

The law punishes lying, not taking. Regulators have fined companies for saying one thing and doing another. They have been far slower to act against companies that say exactly what they are doing in paragraph fourteen. Disclosure became the defence. Hence the shamelessness: it is not that the practice is defensible, it is that describing it is.

Data you can rotate, and data you cannot

Here is the distinction that should shape where you spend your effort, and it is the one most privacy writing misses.

Most of what gets trained on is replaceable. A document, a message, a voice memo, a photo of your lunch. It is unpleasant that a model has it, but the harm is bounded, and the next document is a new document. If a service turns out to be training on your files, you can move the files. If a password leaks, you change the password.

A small amount of what gets trained on is permanent. Your face is the clearest case. It is in the training sets, it is in the search indexes, it is the key that links every other piece of data about you, and it is the one identifier you will carry unchanged for the rest of your life. There is no rotating it. A company that has learned your face has learned something you cannot revoke by switching providers, and a search engine that has indexed it has made you findable by anyone with a photo, indefinitely.

The practical rule: for replaceable data, choose better providers and turn off the toggles. For your face, the provider is the whole public web, and the only lever is getting the indexes to let go. That is a different job with different tools.

We wrote about that job in detail in why removing a biometric is nothing like deleting a file, and about who is buying access to those indexes in the face-search subscription business.

What to do

Not a manifesto. A short list, ordered by how much it protects per minute spent.

Find the toggle in everything you pay for. Search each product’s settings for “improve,” “train,” and “model.” If there is no toggle, search the help centre; the opt-out may be a form. Do this once a quarter, because settings get reset by redesigns more often than anyone admits.

Read the pricing page for the word “training.” If a no-training promise exists only on the enterprise tier, you now know what the company thinks of individual subscribers. Decide accordingly.

Treat “we do not sell your data” as saying nothing. It is true of almost every company that trains on you. The sentence you want is “we do not use your content to train models,” without a qualifier.

Assume the opt-out is not retroactive. Anything you put into a product before you found the switch is already in. That is a reason to find the switch early on the next product, not a reason to give up on this one.

Deal with your face separately. It is the one item on this list that no settings menu covers. The face-search engines hold it, they re-crawl for it, and they have opt-out processes that work but need repeating. Handle that as its own task, either by hand or with a service that files and re-files for you.

Privacy in 2026 is not lost, and it is not free. It is a set of defaults you did not choose, most of which you can flip, and one identifier you cannot change, which you can only ask the world to stop indexing. The companies are counting on you doing neither. Do both.

Your face is the one thing you cannot rotate.

FacePrivacy files opt-out and removal requests with the major face-search engines on your behalf and re-files them monthly, so the identifier you cannot change stops being a search result.

See how the removal tool works →