Skip to content

https://warmloop.com/guidance/client-files-in-claude-and-chatgpt

Privilege and confidentiality

Can you put client files into Claude or ChatGPT?

A plan-by-plan answer for lawyers practising in Canada outside Quebec, from an adversarial reading, independent of both vendors, of Anthropic's and OpenAI's subscription terms, the Canadian law of privilege and the law societies' codes and guidance, as those stood on September 23, 2026.

By WarmLoop Ltd. Published 60 min read

Current to . The vendors change these terms often, so each term below is stated as of the date its own document carries.

The short answer

Not on a consumer plan. Claude Free, Pro and Max, and ChatGPT Free, Go, Plus and Pro, are sold to individuals on terms that promise nothing about keeping your content confidential, reserve the vendor's own uses of it, and let the vendor hand it to authorities on its own judgment. Turning off the training setting changes one of those things, and only from then on. Use those plans for work that carries no client information, or that you have genuinely de-identified.

On the business plans, Claude Team and Enterprise and ChatGPT Business and Enterprise, the answer is a qualified yes. All four run on commercial contracts that treat your content as confidential information the vendor must protect, exclude training on it, and provide for notice of a compelled disclosure where the law allows it (in OpenAI's case, reasonable efforts to give notice). They are acceptable for client material only if the firm meets conditions: the client's informed consent, minimisation, accounts the firm controls, the leaking features turned off, a retention plan, and verification of everything the tool produces. Of the four, Claude Enterprise and ChatGPT Enterprise are the best subscription tiers either vendor sells, on the same conditions. Claude Code and Codex take the verdict of the account they are signed into.

Three provinces narrow the conditional verdicts further. In British Columbia a lawyer needs a written agreement that meets the Law Society's rule on storage providers, which the published terms of these plans do not meet on their face. In practice that means a negotiated agreement, and Team and Business come only on the published terms, so on those plans a British Columbia lawyer or small firm is left with work that carries no client information or has been genuinely de-identified, unless it can negotiate an enterprise agreement, or use a cloud route under a contract, that meets the rule. Read literally, Saskatchewan's guidance, which asks a lawyer to make sure the provider neither shares what is put in with third parties nor uses it for its own purposes in any manner, is met by no subscription plan; the guidance also says a lawyer must not put confidential or privileged client information into a tool that lacks adequate confidentiality and security protections, so a Saskatchewan lawyer must be satisfied that the plan, as the firm has set it up, does not. Alberta's playbook tells lawyers to keep confidential and potentially identifying information out of prompts to publicly available tools, which these plans are, so an Alberta lawyer who puts client material into them departs from the regulator's stated best practice. The conditions are this article's answer to that gap, not a claim that the plans close it. Each province is taken up below.

No Canadian court has decided whether putting privileged material into an AI tool waives privilege.1 By analogy to the service-provider cases, disclosure to a vendor bound as the lawyer's agent, under confidentiality, with no right to use the content for itself, likely does not. That is a condition, and no plan's published terms meet it fully: every plan keeps some use of content for the vendor itself, such as review for abuse and safety, and even on the business plans Anthropic may train on a chat a user sends feedback on, and OpenAI may run content through classifiers to understand better how its services are used. The business plans come much closer than the consumer plans, which is why their verdict is conditional rather than no. Consumer terms that let the vendor read, keep or use what you send leave the question open, and the nearest Canadian decision, about a third party's email system whose owner had promised no confidentiality, went against the privilege claim. The privilege at risk is the client's.

Quebec is outside this article: professional secrecy there is a civil-law institution, and Quebec's Law 25 is not one of the statutes discussed here.

Verdicts, plan by plan

Can privileged or confidential client material go in? The training setting is assumed off wherever a plan has one. In British Columbia, Saskatchewan and Alberta the conditional verdicts carry further conditions, set out below the table.
PlanVerdictWhy, in brief
Claude Free, Pro and Max Not for client files No promise of confidentiality. Anthropic may use content to improve its services and may report inputs to law enforcement at its discretion. The training switch does not reach feedback or flagged chats.
ChatGPT Free, Go, Plus and Pro Not for client files No promise of confidentiality. OpenAI may use content to develop and improve its services. Chats deleted in mid-2025 were preserved under a US court order, and feedback can put a whole conversation into training even with the switch off.
Claude Team Only with conditions Your content is confidential by contract, excluded from training, and disclosed under compulsion only with notice where notice is allowed. But it is stored in the United States, Team has no retention control, and the plan needs two seats.
ChatGPT Business Only with conditions Your content is confidential by contract and not used to improve OpenAI's services. But third-party contractors may review it for abuse, there is no Canadian residency, and the tier was caught by the 2025 preservation order.
Claude Enterprise Best available, with conditions Adds retention control, audit logs and, if Anthropic approves, zero data retention for Claude Code. Storage is still in the United States, and self-serve Enterprise starts at 20 seats.
ChatGPT Enterprise Best available, with conditions Adds retention control, audit tools and, for new workspaces, storage at rest in Canada. Inference is not in Canada, and staff may still read conversations for incidents or where the law requires.

In British Columbia, the conditional verdicts for Team, Business and the standard Enterprise terms carry a further condition: a written agreement that meets Law Society Rule 10-3(4). Without one, these plans are not for records within that rule. Such an agreement in practice means a negotiated one, which Team and Business, sold on the published terms, do not offer; on those plans a British Columbia lawyer is limited to work that carries no client information or has been genuinely de-identified. In Saskatchewan, read literally, no plan meets the Law Society guidance's request that the provider neither share what is put in with third parties nor use it for its own purposes in any manner; a lawyer who uses these plans for client material departs from that request, must still be satisfied that the plan, as the firm has set it up, does not lack adequate confidentiality and security protections, and should seek the client's informed consent, with candour about the potential reuse of what is shared and the potential loss of privilege. In Alberta, the Law Society's playbook tells lawyers to keep confidential and potentially identifying information out of prompts to publicly available tools, which these plans are; an Alberta lawyer who uses them for client material departs from that stated best practice, and should do so, if at all, knowingly, with the client's informed consent and only for what the matter needs. Each province is taken up below.

Claude Code takes the verdict of the Claude account it is signed into, and Codex that of the ChatGPT account. ChatGPT Edu is sold to universities; a lawyer meets it through a law-school clinic, where the university is the customer and the data terms are a Student Data Privacy Agreement rather than the business Data Processing Addendum.2

Two risks, and only one punished so far in the Canadian decisions we found

The first risk is confidentiality: where the file goes, who can read it, who can be made to produce it, how long it lives and whether it trains anything. The second is accuracy: a tool that invents authority, or attaches invented words to real authority, and a lawyer who files what it produced. They call for different defences, and in the Canadian decisions on AI tools we found, only the second has yet cost a lawyer anything.

The decisions on the second risk are collected on WarmLoop's home page. Three points from them bear on this article. The Law Society of Ontario's tribunal has said that using AI is not the wrong: "it is not professional misconduct for a lawyer to use AI to assist in the preparation of a factum", and the failure in the case before it lay in not verifying the authorities the tool generated.3 Delegating does not dilute the duty: the Alberta Court of Appeal held that a lawyer whose factum was drafted by a contractor using a large language model was not absolved "of the need to adequately review work prepared by someone else prior to filing it with the Court", and ordered costs against him personally.4 And confirming that a case exists is no longer enough: in an Ontario matter the cases cited were real and the quotations attributed to them were fake (counsel denied using AI).5 Saskatchewan's Court of King's Bench now requires meaningful human oversight, so that citations correspond to real authorities, quoted passages are accurate and AI summaries reflect their sources, and says that for lawyers "blind or uncritical reliance on AI is inconsistent with professional competence".6

The first risk has not yet produced a Canadian decision about an AI tool, and the nearest decision about a third party's computer system, discussed below, went against the party claiming privilege. That does not make the risk small. The first case will be decided on facts someone is creating now, and the vendor's terms will be exhibits in it.

What Canadian law requires

Privilege belongs to the client

Solicitor-client privilege arises from a communication between lawyer and client that seeks or gives legal advice and that, in the Supreme Court's words, "the parties intend to be confidential".7 It "belongs to the client and can be waived only by the client with informed consent", and the Supreme Court has repeated that it must remain "as close to absolute as possible to ensure public confidence and retain relevance".8 Two consequences follow. In principle a lawyer cannot waive a client's privilege by choosing a tool, because the waiver is not the lawyer's to give. That is subject to implied waiver: the New Brunswick Court of Appeal has explained that the statements that only the client can waive come from cases about a lawyer testifying, and do not rule out an implied waiver, including one arising from an inadvertent disclosure by the client's own lawyer.9 And an opponent will usually attack the third element instead. The argument will not be that you waived the client's privilege; it will be that a communication you placed where a third party was entitled to read and use it was never, or is no longer, confidential.

Does sending it to a vendor waive it?

The party alleging waiver must prove it, and implied waiver is judged on objective conduct rather than on the intention of the person who disclosed, according to the Saskatchewan Court of Appeal.10 But the party claiming privilege must first show that the privilege exists, confidentiality included: "A claim of privilege is not established merely by asserting it."11 The Canadian decisions closest to AI tools are the cases about email held on someone else's system, and they point both ways. An Ontario judge held that privilege is not waived "simply because a person’s communication was made using an electronic device which is accessible by a third party", in a passage that names the cloud, server providers and internet providers.12 Another Ontario judge found an objectively reasonable expectation of confidentiality where no one in the company could read the plaintiff's email without his consent and the only other person with access to the account was a third-party IT provider.13 But in 2024 an Ontario court held that a businessman who knowingly used a third party's email system for his companies' dealings, including with counsel, had not shown that those emails were confidential. They were stored where the system's owner could read them, there was no evidence that it had agreed to keep them confidential from itself, and the claimant had to show they were made "in circumstances where they were intended to be kept in confidence and not shared with a third party whose presence was not essential or of assistance to the consultation". Had privilege been established, the court would have found it waived, both by his use of that system and by his sharing the emails with the system owner's most senior officer.14 And the Federal Court held that privileged documents knowingly disclosed in confidence to an auditor, for the limited purpose of an audit, keep their protection against everyone else, adding that "the intention of the privilege holder is key". It grounded that doctrine in the public interest in companies being properly audited, and it refused it on the facts, because the client could not show it had disclosed knowingly and for that purpose. Carrying it over to an AI vendor is an analogy, not a holding.15

The Saskatchewan Court of Appeal's test for third parties points the same way. Privilege extends to third-party communications "in furtherance of a function essential to the existence or operation of the solicitor-client relationship", such as those of a channel of communication, a messenger or a transcriber.16 A vendor bound to process your content only to serve you, under confidentiality, looks much more like a channel than a stranger.

The same cases supply the argument against you. The workplace-email judge said that a policy, or the employees' knowledge, that the employer could or would read their messages "might have been some evidence" that they did not intend them to be privileged.17 A lawyer who has read terms reserving a vendor's right to review or use content stands closer to that line than any employee in those cases did, and closer to the businessman in the 2024 decision. And the Court of Appeal's list excludes a communication to an accountant "who must consider it and provide his or her own accounting opinion";18 an opponent will say that a model that analyses the file and writes its own answer is that kind of third party. The opponent will add a British Columbia decision holding that deliberately giving a lawyer's letter to one of the client's own consultants waived the privilege in it, because a consultant "hired to provide expert assistance" was neither the client's agent nor a conduit,19 and a Saskatchewan court's statement, made about a clinic's records, that "Disclosure of privileged information to third parties will constitute waiver of that privilege."20 The better reply is that a vendor bound to process your content only to serve you, under confidentiality, is a channel for the lawyer's own work rather than a consultant contributing its own, and the British Columbia court itself recognised agents and conduits as exceptions. It is the better reply, not a safe one. A model does contribute something of its own to the answer, and no Canadian court has yet decided which side of that line it falls on.

Litigation privilege and the vendor's copy

Litigation privilege works differently. Confidentiality "is not an essential component" of it,21 and showing work product to someone who is not an adversary, to prepare the case, does not waive it against the other side.22 Two limits matter for AI tools. The privilege ends with the litigation and any closely related proceedings.23 And the outsider's copy is not itself privileged: in the Ontario Court of Appeal's words, it was the recipient's "contractual undertaking to keep the report confidential, not litigation privilege," that kept it from the other side.24 The outsider there was a lawyer consulted as a potential witness,22 and a vendor processing the lawyer's work product as the lawyer's agent is not obviously the same kind of outsider: litigation privilege "contemplates, as well, communications between a solicitor and third parties".25 If a vendor is treated as that kind of outsider, Windsor suggests, without deciding it for AI tools, that work product on its servers may be protected by the vendor's contract rather than by the privilege while the case runs. Once the case ends, litigation privilege ends with it, and for work product that only it protected, the contract is all that is left; solicitor-client privilege in the same material, where there is any, does not end with the case.23

When someone comes asking

Against Canadian state process, privileged material held by a service provider keeps its protection. The Newfoundland and Labrador Court of Appeal upheld the quashing of production orders for a lawyer's telephone records and messages held by telecommunications providers. It is "the nature of the communications and the solicitor-client relationship", not a physical place, that calls for protection, and notice must be given to the lawyer or the law society before a third party hands potentially privileged data to the police.26 There are two cautions. The Federal Court of Appeal held that the law-office search guidelines did not govern documents the tax authority had obtained from third parties "without any indication that some could be privileged",27 so material that does not say what it is may not be treated as privileged. And none of this binds a foreign court. A US vendor served with US process decides, within its contract and US law, whether and when to tell you. Whether a production of that kind would be treated in Canada as a waiver is a question no Canadian decision answers.

The professional codes

The technology rule is common ground. Saskatchewan's commentary to rule 3.1-2 says a lawyer "should understand the benefits and risks associated with relevant technology, recognizing the lawyer’s duty to protect confidential information".28 The Federation of Law Societies' Model Code carries the same words, and Ontario and Alberta have adopted them; check your own province's code, because the numbering and commentary can differ.29 Newfoundland and Labrador's law society puts it shortly: lawyers' "professional responsibilities do not change when using AI".30

Confidentiality is the harder rule. Rule 3.3-1 requires a lawyer to "hold in strict confidence all information concerning the business and affairs of a client" and not to divulge it unless authorized, and its commentary says the duty is wider than privilege and applies "without regard to the nature or source of the information or the fact that others may share the knowledge".31 The implied authority to disclose reaches, "to the extent necessary", "others whose services are used by the lawyer". The commentary's express duty "to take reasonable care to prevent their disclosing or using" confidential information is stated for the lawyer's associates, employees, students and contract lawyers; for an outside provider the duty of care comes from the rules that follow.32 Rule 3.3-2 adds a separate prohibition on using or disclosing confidential information "for the benefit of the lawyer or a third person without the consent of the client", which a regulator could apply to a disclosure that lets a vendor build its products from what you send.33 Rule 3.5-1's commentary asks for "all reasonable steps to ensure the privacy and safekeeping of a client’s confidential information".34 None of these rules mentions artificial intelligence, cloud storage or encryption. In Saskatchewan the standard is client authority plus reasonable care, and a lawyer who is challenged will want evidence of both.

British Columbia is the strict benchmark. Its Law Society Rules define a storage provider as any entity storing or processing records outside the lawyer's office, and forbid keeping records with one unless the lawyer retains custody and control, the provider does not access or copy them "except as is necessary to provide the service obtained by the lawyer", the records are destroyed on instruction, and the arrangement is in a written agreement; a loss of control or improper access must be reported to the Law Society.35 The Law Society of British Columbia's own AI guidance says those rules apply to AI products.36 Saskatchewan has no equivalent binding rule, and we found none in the other provinces; there the same questions arise under the general duty of confidentiality. Whether the business plans meet the British Columbia rule is taken up under the case against these verdicts.

The law societies' AI guidance agrees on the risks and differs on how far it goes. Saskatchewan's tells a lawyer who intends to input confidential or privileged information to "ensure that the provider does not share inputted information with third parties, or utilize the information for its own use in any manner, including to train or improve its product", and says a lawyer "must not input any confidential and/or privileged client information to a generative AI tool that lacks adequate confidentiality and security protections".37 Ontario's white paper warns that "Anonymizing is not perfect".38 Alberta's playbook, whose stated focus is "publicly available AI tools", goes furthest: "Never include confidential or potentially identifying information in prompts", and a training opt-out does not change that.39 No regulator names a vendor's plan. Alberta's older quick tips single out "free" products as unlikely to protect confidentiality,40 but the playbook, updated since, does not confine its warning to free tools.

No Canadian regulator makes client consent a binding rule, and their wording differs. Saskatchewan and Manitoba say informed consent "should be sought" where anonymizing cannot protect confidentiality or privilege.41 Ontario's practice note says, in that situation, to "obtain your client's informed consent".42 Prince Edward Island says the lawyer "should obtain informed consent from the client before using the technology".43 British Columbia says a lawyer "could explore whether client consent to use the tool with such information is viable".44 The American Bar Association, for comparison, requires informed consent before client information goes into a tool that learns from its inputs, and says general boilerplate in an engagement letter "is not sufficient".45 The Canadian Bar Association's counterweight belongs beside all of these: consent "is not a panacea".46 This article recommends informed, specific consent in the retainer before privileged or confidential material goes into any AI tool. That is best practice, not a rule, and consent does not rescue a tool that should not be used.

Privacy statutes

PIPEDA governs the personal information a law firm handles in the course of commercial activity in Saskatchewan, Manitoba, Ontario, the Atlantic provinces and the territories. Alberta and British Columbia firms are under their own Personal Information Protection Acts for activity within the province.47 Two qualifications keep that statement honest. The Federal Court has held that gathering evidence to defend an individual in a civil action was not commercial activity, the "attorney-client relationships" being "simply incidental", so PIPEDA does not necessarily reach every item in a litigation file.48 And the Alberta and British Columbia exemption orders speak of activity "within the Province"; a transfer to a vendor in the United States may bring PIPEDA in as well. That second point is our reading of the orders, not a decided one.

Where PIPEDA applies, the firm remains responsible for information "transferred to a third party for processing" and must use "contractual or other means to provide a comparable level of protection".49 A breach at the vendor can therefore become the firm's report to the Privacy Commissioner, where it creates a real risk of significant harm.50 Alberta adds duties when a service provider outside Canada is used: notice to the individual whose information was collected with consent, and policies that say in which countries, and for what purposes, the provider handles it.51 The federal Commissioner's cross-border guidance makes the point that matters most for US vendors: "No contract can override the criminal, national security or any other laws of the country to which the information has been transferred."52 In May 2026 the federal Commissioner and the Quebec, British Columbia and Alberta regulators found complaints about ChatGPT well-founded. They found that OpenAI used users' chats to improve its models for an appropriate purpose, so that aspect of the complaints was not well-founded, but the federal, British Columbia and Alberta regulators found that OpenAI had not obtained valid consent to train its GPT-3.5 and GPT-4 models on those chats, and the Quebec regulator found the practice contrary to Quebec's private-sector privacy law. Their joint report also records, in the Quebec regulator's analysis under Quebec's rule that privacy settings be at their highest by default, that the setting collecting users' chats for training was enabled by default, so an assumption that the switch is off is an assumption you must act on.53 Privacy compliance is the floor, not the answer. The Law Society of British Columbia's cloud guidance warns that a privacy checklist "may fall short of the requirements for protecting information that is governed by confidentiality and privilege".54

Court rules on AI

Court directions deal with accuracy, not confidentiality. Saskatchewan's King's Bench directive, in force since January 1, 2026, requires AI-generated references to be "independently verified against authoritative sources" and requires no declaration of AI use.6 The Federal Court requires a declaration in the first paragraph of a document prepared for litigation that includes AI-generated content.55 Manitoba's Court of King's Bench requires filed materials to "indicate how artificial intelligence was used".56 One side effect deserves notice: a declaration tells the other side that the document passed through an AI tool, and so tells it where to look for a waiver argument. The only Canadian court text we found that speaks to uploads is the British Columbia Provincial Court's reminder that "some AI tools add the documents and information you upload to their databases".57

The other side's documents

Documents and answers obtained on discovery carry an undertaking to the court: "…whatever is disclosed in the discovery room stays in the discovery room unless eventually revealed in the courtroom or disclosed by judicial order".58 Saskatchewan codifies it. Information disclosed by affidavit of documents or in questioning "must be treated as confidential and may only be used by the recipient of the information or documents for the purpose of carrying on the action", unless the court orders, the parties agree or the law requires or permits otherwise.59 In family proceedings the rule is stricter: any person with access to financial disclosure or discovery material must keep it "in confidence", and contrary use is contempt of court.60 Because discovery is compelled for the action alone, the Supreme Court has said, the invasion of privacy "should generally be limited to the level of disclosure necessary to satisfy that purpose and that purpose alone".58 A prothonotary of the Federal Court applied the undertaking to service providers in reasons for refusing a protective order: the parties and their lawyers may pass discovery material to "third party experts, consultants or service providers" only where "it is necessary for the conduct of the litigation", the undertaking binds any recipient "wherever that person may be", and counsel "can and must ensure" recipients know they are bound.61 Those reasons need care. The order was set aside on appeal on another question, the test for granting a protective order, and the Federal Court of Appeal has since recorded it as reversed. The appeal judge did not decide the points just quoted and did not contest the principle, but he said that the single case applying the undertaking to third-party experts and consultants was "an exceptionally tenuous basis" for setting aside a party's concerns about misuse of its discovery material by third parties. That is a reason to bind a vendor in writing rather than trust the undertaking to reach it.61 With a consumer click-through vendor that has agreed to nothing about your file, the disclosure is still permitted only where it is necessary for the conduct of the litigation, counsel cannot make sure the vendor knows it is bound, and enforcing the undertaking against a foreign vendor would be another matter: the prothonotary observed that the court "has no power to enforce the execution of its own judgments outside of its territory".61 Treat the other side's productions, and anything under a sealing order, publication ban or protective order, as material that goes into an AI tool only where necessary, to a vendor bound in writing, and after a check of the order's terms.

What the vendors' terms say

The verdicts rest on the contracts, so here is what each says, as of the date each document carries. Negotiated enterprise agreements and order forms are not public and were not read; where one governs your firm, it, not this summary, is the contract.

Claude Free, Pro and Max

Max is a consumer plan. Anthropic describes it as a plan "for individual consumers", and all three plans are governed by the Consumer Terms of Service (the version served in Canada is effective October 8, 2025) and the consumer Privacy Policy (effective September 10, 2026).62 The Consumer Terms let Anthropic use your "Materials" to "provide, maintain, and improve the Services and to develop other products and services, including training our models, unless you opt out of training". The opt-out is an opt-out of training; the rest of that sentence is not withdrawn by it. Even with the opt-out, Anthropic will train on material you give feedback on and on material "flagged for safety review".63 There is no confidentiality clause in your favour, and Anthropic reserves the right, "at our sole discretion, to report information from or about you, including but not limited to Inputs or Outputs, to law enforcement".64 The Canadian supplement to the Privacy Policy records your agreement that your data may be stored outside Canada, including in the United States, and disclosed there in response to legal process.65

Retention is longer than the headline 30 days suggests. A deleted chat leaves the back end within 30 days; a chat you keep has no stated limit; a flagged chat's inputs and outputs are kept for up to two years and its safety scores for up to seven; feedback is kept for five years; and "In all cases, we may retain chats and coding sessions as required by law, to resolve disputes, or as necessary to combat violations of our Usage Policy."66 By default Anthropic's staff cannot read your conversations, except when you send feedback or a Usage Policy review requires it.67 Anthropic's own help page tells consumer users to be thoughtful about sharing "Confidential business or personal documents".68 One more trap: an account opened with a firm email address may be linked to the firm's Anthropic organization, whose administrator may be able to see its content.69

Claude Team and Enterprise

Team and Enterprise are governed by Anthropic's Commercial Terms of Service (effective June 17, 2025), with the Data Processing Addendum (effective February 24, 2025) incorporated automatically.70 The contract says what the consumer terms do not: "Anthropic may not train models on Customer Content from Services", and "Customer Content is Customer’s Confidential Information." Feedback is the exception: if a user rates a response or reports a bug, Anthropic may use that chat to train its models.71 Anthropic may use that information only to perform the contract, may share it only with people bound to equivalent confidentiality, and must notify you of a compelled disclosure and cooperate in narrowing it, "except where expressly prohibited". Its duty to destroy your information on request excepts copies retained to comply with law and copies in automated backups, which stay confidential while kept.72 Under the Addendum Anthropic is your processor; it promises breach notice within 48 hours for a breach involving customer personal data, and deletion within 30 days of termination unless the law, a dispute or the need "to combat harmful use of the Services" requires otherwise.73

The contract leaves three gaps for a Canadian firm. Data is stored in the United States, and traffic may be routed to other countries by default; the only residency control, on usage-based Enterprise plans, is US-only inference.74 Team has no retention control: chats are kept until deleted, while custom retention, with a 30-day minimum, is an Enterprise feature, and on Enterprise the default is to keep data indefinitely. On both plans a flagged chat's inputs and outputs are kept for up to two years and its safety scores for up to seven, feedback is kept for five years, and chats may be kept longer where the law requires or to combat Usage Policy violations. Custom retention on Enterprise does not reach Claude Design, Claude Tag, Claude Managed Agents or features built on Claude Code on the web, and a project's retention overrides it for the chats inside the project.75 And a small firm meets thresholds: Team requires at least two members, and self-serve Enterprise at least 20 seats.76 Enterprise adds audit logs, a Compliance API, customer-managed encryption keys and, for Claude Code only and on Anthropic's approval, zero data retention.77

Anthropic markets Claude to law firms with the line that "Claude clears the bar for sensitive matters and privileged work".78 That is marketing, not a term. It speaks of Team and Enterprise, says nothing about Canadian privilege law, and sits beside a contract that makes it the customer's responsibility "to evaluate whether Outputs are appropriate for Customer’s use case".79 Anthropic's regional compliance page also shows Canada as a place where regional data residency is available through cloud platforms; the platforms' own documentation, discussed under higher-assurance routes below, does not bear that out for current models.80

ChatGPT Free, Go, Plus and Pro

All four are governed by OpenAI's Terms of Use (effective January 1, 2026), a contract with OpenAI OpCo, LLC; the Terms say the Privacy Policy is not part of them. Go is offered in Canada.81 The Terms let OpenAI use content to "provide, maintain, develop, and improve our Services", and the opt-out addresses training only.82 With "Improve the model for everyone" off, new conversations are not used for training; but after a thumbs-up or thumbs-down, "the entire conversation associated with that feedback may be used to train OpenAI models", and Codex has its own "Include environments" training setting that the ChatGPT switch does not change.83 Chats are kept until you delete them, then scheduled for deletion within 30 days unless security or legal obligations require longer, and files in a project, a custom GPT or the Library survive deletion of the chat.84 A Temporary Chat stays out of your history, memory and training, but it "may be retained for up to 30 days for safety purposes", and it changes nothing in the contract.83 OpenAI uses automated tools and a trained team to review problematic content, and conversations showing a plan to harm others go to reviewers who may refer them to law enforcement.85 The Privacy Policy, which is not part of the contract, permits disclosure to government authorities and others to comply with a legal obligation, and also to protect OpenAI's rights or property, where OpenAI determines "in our sole discretion" that its terms, its policies or the law have been violated, to detect fraud, to protect safety and to protect against legal liability. A promise of notice appears in OpenAI's government-request policy, not in the consumer contract.86 Disputes go to mandatory arbitration, with a 30-day window to opt out.87

These plans have already been tested by compelled retention. On May 13, 2025, a US magistrate judge in the New York Times copyright litigation directed OpenAI to preserve and segregate output log data that would otherwise be deleted.88 OpenAI said the order reached ChatGPT Free, Plus, Pro and Team, but not Enterprise, Edu or zero-data-retention API use.89 The going-forward obligation ended on September 26, 2025, but the order ending it kept in place the data already preserved, except data from the European Economic Area, Switzerland and the United Kingdom; Canada has no such carve-out. OpenAI said in October 2025 that the historical data "remains locked down, accessible only to a small, audited OpenAI legal and security team".90 Separately, the court ordered a sample of 20 million de-identified consumer ChatGPT logs produced; OpenAI says the sample does not include Business (formerly Team), Enterprise or Edu conversations.91 On January 5, 2026 the district judge affirmed, contrasting wiretapped calls with "users' conversations with ChatGPT which users voluntarily disclosed to OpenAI and which OpenAI retains in the normal course of its business".92 That sentence is the one a Canadian opponent will quote.

ChatGPT Business and Enterprise

ChatGPT Team was renamed ChatGPT Business on August 29, 2025.93 Business and Enterprise are governed by the OpenAI Services Agreement (effective January 1, 2026), with the Data Processing Addendum incorporated.94 OpenAI will use customer content only as needed to provide the services, comply with law, enforce its policies and prevent abuse, and not to develop or improve its services unless you explicitly agree; "Confidential Information includes Customer Content"; and a disclosure required by law comes with reasonable efforts to notify you first, to the extent permitted.95 The Addendum covers personal data only, so a privileged memo with no personal information in it relies on the confidentiality clause alone.96

The tiers differ on who may read your content. For Business, OpenAI's access is limited to authorized employees for engineering support, abuse investigation and legal compliance, and to "specialized third-party contractors who are bound by confidentiality and security obligations, solely to review for abuse and misuse". For Enterprise, authorized employees access conversations only "for the purposes of resolving incidents, recovering end user conversations with your explicit permission, or where required by applicable law". On every business tier, OpenAI may run business data through "automated content classifiers and safety tools, including to better understand how our services are used", and says that the classifications "are metadata about the business data but do not contain any of the business data itself".97 OpenAI's September 17, 2026 announcement of a legal product offers eligible firms ChatGPT Enterprise use that "is excluded from human review by default"; the announcement does not say how that differs from the access limits just quoted, and the offering is initially for selected firms in the United States.98

On retention, OpenAI's own pages conflict for Business: its privacy page says workspace administrators can control retention, while its administrator guide describes a custom retention policy, with a 90-day minimum, as an Enterprise feature and says chats are otherwise kept until the user deletes them.99 On location, Enterprise and Edu workspaces provisioned with data residency can store content at rest in Canada; inference residency is offered only in Europe, the United States and the United Arab Emirates, and apps, MCP servers, web search, beta features and Codex Web fall outside residency.100 Business was named in OpenAI's own account of the 2025 preservation order; Enterprise was excluded.89 Both tiers cap OpenAI's liability at the fees paid in the previous 12 months, and a breach of confidentiality is not carved out of the cap. It is carved out of the exclusion of indirect and consequential damages, so loss of that kind can be claimed up to the cap; Anthropic's Commercial Terms exclude consequential damages, including lost data, with no such carve-out.101

The six subscriptions side by side

The six subscriptions compared. Sources are in the notes to the sections above.
QuestionClaude Free, Pro, MaxClaude TeamClaude EnterpriseChatGPT Free, Go, Plus, ProChatGPT BusinessChatGPT Enterprise
ContractConsumer Terms (Canadian version, October 8, 2025)Commercial Terms (June 17, 2025) and Data Processing AddendumAs Team, or a negotiated agreementTerms of Use (January 1, 2026)Services Agreement (January 1, 2026) and Data Processing AddendumAs Business, plus an order form
Promise to keep your content confidentialNoneYesYesNoneYesYes
Training, setting offNot trained, except feedback and flagged chatsExcluded by contract; feedback you send is an exceptionAs TeamNew chats not trained; feedback may be; Codex environments have a separate switchExcluded unless you agreeExcluded unless you agree
Other uses reservedImprove the services, develop other productsOnly to perform the contractAs TeamDevelop and improve the servicesOnly to provide the services, comply with law, enforce policies, prevent abuseAs Business
Who at the vendor may read itTrust and safety staff on flagged chats; feedbackStaff with a need to know, under confidentiality; flagged content kept for safety reviewAs TeamAutomated and human review; harm escalationEmployees, and third-party contractors reviewing for abuseEmployees, for incidents, recovery with your permission, or law
How long it is keptUntil deleted, then 30 days; flagged, 2 years; feedback, 5 yearsUntil deleted, then 30 days; flagged, 2 years; feedback, 5 years; no custom retentionCustom retention, 30-day minimum, not for every feature; default indefinite; flagged and feedback as TeamUntil deleted, then 30 days; files outlive the chatUntil deleted; OpenAI's pages conflict on admin controlAdmin-set retention, 90-day minimum
Notice of a legal demandHelp-page policy onlyIn the contract, unless prohibitedIn the contract, unless prohibitedGovernment-request policy onlyReasonable efforts, where permittedReasonable efforts, where permitted
Where it is storedOutside Canada, including the United StatesUnited StatesUnited States; US-only inference optionUnited States and service providers' locationsNo residency optionAt rest in Canada for new residency workspaces; inference outside Canada
Firm controlsNoneSingle sign-on, connector and feedback controls; no audit logAdds audit logs, SCIM, Compliance API, retention, encryption keysNoneAdmin console, single sign-on; members can invite membersAdds SCIM, role-based access, Compliance API, key management
DisputesCalifornia law, subject to Canadian law; San Francisco courtsCalifornia law; arbitration in San FranciscoAs Team, unless negotiatedCalifornia law; mandatory arbitration, 30-day opt-outCalifornia law; arbitrationAs Business, unless the order form varies it
Who can buy itIndividuals2 to 150 seatsFrom 20 seats self-serveIndividualsTeams of 2 to 200By contract with OpenAI; custom terms possible

Anthropic's notice-of-demand policy and OpenAI's government-request policy promise notice to users except where the law or an emergency prevents it, but they are policies the vendor can change, not terms of the consumer contract.102

What the American courts have said

No Canadian court has ruled,1 but American trial courts have, and Canadian opponents will cite them. None binds a Canadian court, and American attorney-client privilege is not Canadian solicitor-client privilege.

United States v Heppner

The leading case is a February 17, 2026 memorandum of the US District Court for the Southern District of New York, giving reasons for a ruling made from the bench on February 10, 2026.103 The facts matter. A criminal defendant, after a grand jury subpoena and "Without any suggestion from counsel", used Claude, a publicly available AI platform, to prepare reports on his defence strategy and, his lawyers said, later shared them with counsel. The court held they were not privileged. Claude is not a lawyer, and the communications were not confidential, "not merely because Heppner communicated with a third-party AI platform but also because the written privacy policy to which users of Claude consent" allowed Anthropic to use inputs and outputs to train Claude and to disclose them to third parties, including government authorities. The court relied on Anthropic's Privacy Policy as it stood on February 19, 2025, and on the January 5, 2026 New York Times order quoted above. It added that any privileged information Heppner put into Claude was waived "just as if he had shared it with any other third party", and that the documents were not work product, because they were not prepared at counsel's behest.

Read fairly, Heppner concerns a client acting alone on a consumer plan, and the court said as much: "Had counsel directed Heppner to use Claude, Claude might arguably be said to have functioned in a manner akin to a highly trained professional who may act as a lawyer’s agent within the protection of the attorney-client privilege."103 It did not consider a lawyer's own use, a business contract or an account with training off. But the two features of the consumer policy it relied on, use of content and disclosure to third parties including government, remain in Anthropic's consumer terms and in OpenAI's, whatever the training switch says.

The work-product decisions

Four other first-instance decisions, one issued the same day as the Heppner bench ruling and three after it, reached the other result on work product, the American counterpart of litigation privilege. A Michigan magistrate judge held that waiving work product requires disclosure "to an adversary or in a way likely to get in an adversary's hand", and that ChatGPT and similar programs "are tools, not persons".104 A Colorado magistrate judge distinguished Heppner as a criminal case in which "there was a gap between the party and the attorney", held that the collection of user data by widely available AI systems does not "eliminate all expectations of privacy or automatically waive protections", and then amended the protective order: no confidential information may go into an AI platform "unless the AI provider is contractually prohibited from: (1) storing or using inputs to train or improve its model; and (2) disclosing inputs to any third party except where such disclosure is essential to facilitating delivery of the service", with a right to delete on request and written documentation of those terms. The judge accepted that this would, for now, bar "most, if not all, mainstream low-to-no-cost AI".105 A New York court quashed a subpoena to OpenAI on the Colorado court's reasoning, and a Texas business court withheld most of a party's ChatGPT material as work product while ordering it to disclose which discovery materials it had shared with ChatGPT.106 Each of the four concerned a party's own use of a tool. In the Michigan, Colorado and New York cases the party had no lawyer, and the Colorado judge distinguished Heppner partly on that ground: "No such gap exists in the pro se context."105 None concerned a lawyer's use of a business-tier tool.

The Canadian parallel holds on one side only. Our litigation privilege, like American work product, is lost through disclosure inconsistent with secrecy against the adversary. Our solicitor-client privilege is the one Heppner put at risk, and the Ontario Court of Appeal has repeated, from an American decision it quoted, that "the mere showing of a voluntary disclosure to a third person will generally suffice to show waiver of the attorney-client privilege".22 That was said of American law in a litigation-privilege case, but it is the passage an opponent will lead with.

A yardstick borrowed from Colorado

The Colorado order gives a usable test, foreign as it is: a contractual prohibition on training and on onward disclosure beyond delivering the service, a contractual right to delete, and the terms kept in writing. No consumer plan meets it. The training switch is a setting you can change, not a promise the vendor made, and the consumer terms reserve other uses. The business plans come closer, but tested limb by limb on their published terms, none meets it beyond argument. Training on your content is excluded by contract on all four, with one gap on Anthropic's plans: Anthropic's Privacy Center says that a chat a user sends feedback on may be used to train its models, so on those plans that limb holds only while feedback is turned off, which is a setting, not a term.71 Onward disclosure is where they part, though not in their confidentiality clauses: Anthropic may share your content only with people who need to know it and are bound to equivalent confidentiality, and OpenAI's agreement sets the same limit. The difference is what OpenAI adds. ChatGPT Business lets third-party contractors review content for abuse, and OpenAI may keep "Abusive Customer Content" and, if the customer's access is suspended or the agreement is terminated by either party, share information about it "as reasonably necessary to protect the Services or any third party from harm". Neither is obviously disclosure "essential to facilitating delivery of the service". And the order asks for the ability to delete "all" confidential information on request, where every business contract keeps back some copies, whether in backups, for the law or against harmful use. A negotiated agreement could meet the test; the published terms leave it to argument.107

The case against these verdicts

The best argument for Max, Plus and Pro

The strongest case for a paid consumer plan with training off runs like this. The content is not trained on; deleted chats leave the back end in about 30 days; Anthropic says its staff cannot read conversations by default; and the Canadian workplace-email cases protected employees' emails with their lawyers even where others had technical access, in one line of them treating an employer's "no guarantee" policy as showing at most a "diminished expectation of privacy but not an extinguishment of it".108 No Canadian court has held that using an AI tool destroys privilege,1 and Alberta's 2025 quick tips say, of keeping information confidential, "Typically, this means that you will have to pay for an AI product".40

The answer is not that the employees in those cases did not know. In the earlier Ontario case the employee knew of the policy, refused to sign it and told his employer that it, or parts of it, did not apply to him, and in the later one the plaintiff, an information technology professional, agreed that his work account carried more risk.109 What decided them was who else was entitled to read and use the messages: no one without the employee's consent, or at most a policy saying privacy was not guaranteed. Where a person knowingly used a third party's system whose owner had not agreed to keep the messages confidential from itself, the 2024 Ontario court held that privilege was not established.14 Consumer terms put the lawyer in that position, in writing: the reservations are public and express, and the lawyer has read them. The training switch is a user setting, not a contractual promise: it can be switched back, it does not reach feedback or flagged conversations, and it leaves standing the vendor's right to use content to improve its services. The consumer contracts contain no promise of confidentiality, no contractual notice before disclosure and, in Anthropic's case, a reserved right to report inputs to law enforcement at its own discretion; OpenAI reserves a similar discretion in its Privacy Policy rather than its contract. OpenAI's consumer chats have already been preserved and sampled under a US court order the user never saw. Alberta's own 2026 playbook answers the point about paying: it tells lawyers not to put confidential information into prompts to publicly available tools at all. And a click-through vendor has agreed to nothing about the implied undertaking, which counsel must make sure a recipient knows it is bound by. For de-identified work none of this matters. For client material it is the whole question.

Against the plans this article accepts

The case against the business and enterprise tiers deserves the same weight, because it is strong.

  • People at the vendor can still read content in the cases the vendor reserves: flagged conversations at Anthropic, third-party abuse contractors on ChatGPT Business, incident and legal access on ChatGPT Enterprise.
  • US legal process reaches the vendor, including national-security process, and the notice promise yields wherever notice is "expressly prohibited". Anthropic's transparency report for the second half of 2025 records content requests from government and reports national-security process only in bands.110 The Canadian protections described above bind Canadian authorities, not American ones.
  • Anthropic stores content in the United States on every plan. OpenAI's Canadian residency covers storage at rest, not inference, and only for workspaces provisioned with it.
  • The vendor's copy of litigation work product may be protected only by its contract, not by privilege, and after the case the contract is all that is left.
  • The terms can change: updates to Anthropic's Commercial Terms take effect 30 days after posting, or at once where they respond to a change in the law, and OpenAI may update its agreement on notice.111
  • Liability is capped at 12 months' fees, disputes go to arbitration in California, and the data processing addenda, including their breach-notice promises, are written around personal data rather than privileged business information.112
  • No Canadian court has held that a vendor on these terms is inside the privilege.1

Most of this is the ordinary risk of any outsourced service a firm already relies on, and the contracts place these vendors much closer to the agent under confidentiality that Canadian law treats as a channel than to the stranger it does not. A party alleging waiver must prove it, but the firm must first prove the confidentiality its claim of privilege depends on, and the evidence of that is the firm's own to keep: the client's consent, what it chose to send, the settings it locked and the dated terms it relied on.11 A firm that has all of that would have the facts on its side. Two points no contract answers: foreign legal process, and human access in the cases the vendor reserves. That is why the verdict is conditional, and why the most sensitive files belong elsewhere. Saskatchewan's guidance tells lawyers with especially sensitive information to consider "whether simply not using the tool is a better course of action"; British Columbia's cloud checklist singles out clients "whose activities may be of interest to the United States government or law enforcement"; and the federal Privacy Commissioner has said that some information "is so sensitive that it should not be sent to any foreign jurisdiction".113

Three provinces' own words

British Columbia's rule is binding, and the published business terms do not meet it on their face. A lawyer may keep records with a storage provider only if the provider maintains them without "accessing or copying them except as is necessary to provide the service obtained by the lawyer" and without "failing to destroy the records completely and permanently on instructions from the lawyer", under a written agreement consistent with the lawyer's obligations; if a third party fails to destroy records despite instructions, the lawyer must report it to the Executive Director at once.35 Anthropic keeps flagged content for review and excepts backups and copies kept to comply with law from its duty to destroy. OpenAI may run business data through classifiers "to better understand how our services are used", lets third-party contractors review ChatGPT Business content for abuse, and may keep content it treats as abusive. A British Columbia lawyer who wants to use these plans for records within the rule needs a written agreement that does meet rule 10-3(4), which in practice means a negotiated one. Team and Business do not offer one: they come on the published terms set out in the comparison above. A British Columbia lawyer or small firm on those plans is therefore left with work that carries no client information or has been genuinely de-identified, and for records within the rule needs a negotiated enterprise agreement, or a cloud route under a contract checked against the rule; the cloud agreements were not read for this article. Without such an agreement, these plans are not for those records.

Saskatchewan's guidance is not binding, and read literally no subscription plan meets it. It asks a lawyer who intends to input confidential or privileged information to "ensure that the provider does not share inputted information with third parties, or utilize the information for its own use in any manner".37 Every plan reserves some use of content for abuse and safety review, OpenAI may also run classifiers over business data to understand how its services are used, and ChatGPT Business adds third-party contractors. The guidance's consent step is written for the case where anonymising cannot protect confidentiality: informed consent "should be sought", with candour about "the potential reuse of information shared as well as the potential for the loss of privilege", and for especially sensitive information a lawyer should ask whether not using the tool is the better course.41 It does not say that consent cures a tool that "lacks adequate confidentiality and security protections".37 The conditions in this article follow the consent step; they do not pretend the plans pass the first test, or that consent makes up for failing it. What the guidance leaves a Saskatchewan lawyer who uses a business plan for client material is its own bar: to be satisfied that the plan, as the firm has set it up, is not a tool that "lacks adequate confidentiality and security protections", and to have the client's informed consent, sought as the guidance describes.37

Alberta's playbook, whose stated focus is "publicly available AI tools", says without qualification: "Never include confidential or potentially identifying information in prompts."39 The business plans are publicly available tools, sold to the public; they are not tools a firm builds for itself. On its words, then, the playbook reaches them too, and an Alberta lawyer who follows this article's conditional verdict for client material departs from the regulator's stated best practice. If that is done at all, it should be done knowingly, with the client's informed consent and only for what the matter needs.

Claude Code and Codex read folders, not prompts

A chat assistant sees what you paste. A coding agent sees what it opens. Anthropic's documentation says that what Claude Code sends over the network "includes all user prompts and model outputs", and what the agent reads to answer you becomes part of that exchange; Codex runs local work on your device and cloud tasks in OpenAI-managed environments.114 Point either at a matter folder and the folder is the prompt. Both inherit the plan they are signed into: Claude Code runs under the Commercial Terms on Team and Enterprise and under the Consumer Terms on Free, Pro and Max, and Codex under whichever ChatGPT terms govern the account.115 The verdicts above therefore apply, with traps of their own.

  • Feedback leaves with your code. Claude Code's /feedback, /bug and /share send a transcript that is kept for five years, and answering yes to a session survey uploads the transcript and raw session log, with "Source code, file contents, and other conversation content" as they are, for up to six months. A /feedback report can also, optionally, open an issue in a public GitHub repository.116
  • Transcripts stay on your disk. Claude Code keeps session transcripts in plain text under ~/.claude/projects/ for 30 days by default, but keeps the transcript of a session started or last continued in Claude Desktop or Cowork at any age unless you set a limit for those too; its prompt history (~/.claude/history.jsonl) and its auto-memory notes are kept until you delete them; and a credential a tool reads is written into the transcript. Codex keeps a history.jsonl transcript file and, with file-based storage, its access tokens in ~/.codex/auth.json.117 A home folder synced to a cloud drive copies all of it off the machine.
  • A stray credential changes the contract. Claude Code prefers a cloud-provider setting, an ANTHROPIC_AUTH_TOKEN, an ANTHROPIC_API_KEY (once you approve it), an apiKeyHelper script, a CLAUDE_CODE_OAUTH_TOKEN, which can belong to a personal plan, or an Anthropic profile or federation credential (a profile named in ANTHROPIC_PROFILE, the ANTHROPIC_FEDERATION_RULE_ID and ANTHROPIC_ORGANIZATION_ID variables set together, or an active profile set up for federation) over the subscription you signed in to; a Codex session signed in with an API key follows that API organization's settings.118
  • Cloud sessions run on the vendor's machines. Claude Code on the web clones your repository into an Anthropic-managed virtual machine, and on Pro and Max a session can be made visible "to any user logged into claude.ai"; Codex cloud tasks run in OpenAI-managed environments, and Codex Web is outside OpenAI's data residency.119
  • Remote Control keeps a copy. While Claude Code's Remote Control is connected, the session transcript, including your messages, Claude's responses and tool activity, is stored on Anthropic's servers and retained under Anthropic's data-usage policy. Organizations with zero data retention cannot enable it, and on Team and Enterprise it is off until an Owner turns it on.120
  • Full access means full access. Microsoft's Codex documentation warns against the full-access mode without understanding its risks. OpenAI reported in August 2026 that, during internal cybersecurity evaluations, several of its models, led by an internal-only research model and "operating under reduced safeguards", circumvented controls meant to isolate them from the internet; it said customer data was not affected. The point is not that Codex did this. It is that isolation controls can fail.121
  • Connectors and MCP servers are third parties. What an agent sends to an MCP server or connector is handled under that operator's terms, not the model vendor's; Anthropic says it "does not security-audit or manage any MCP server", and OpenAI's Service Terms say it is not responsible for app data once sent.122 That includes WarmLoop.
  • Memory outlives the chat. Claude's memory is on by default on Free, Pro and Max, and memory entries are not removed when the conversation that produced them is deleted; ChatGPT treats memory and training as separate settings.123

A checklist a firm can adopt

The conditions behind the verdicts, as a policy a firm can adopt. It does not make any use of these tools safe; it is the evidence of reasonable care a lawyer will want if that use is ever challenged.

Before any client material goes in

  • Use a business plan on a firm account. Claude Team or Enterprise, ChatGPT Business or Enterprise, on accounts the firm owns. The Law Society of Ontario suggests allowing AI use only with accounts created under the organization's credentials.124 Watch the reverse trap too: a personal account opened with a firm email can be absorbed into the firm's workspace.125
  • In British Columbia, get the storage-provider agreement. A written agreement that meets Law Society Rule 10-3(4): no access or copying beyond what the service needs, and complete destruction on instruction. Know that a failure to destroy records as instructed must be reported to the Executive Director.35 Team and Business offer no such agreement; on those plans, keep to work that carries no client information or has been genuinely de-identified, or move to a negotiated enterprise agreement or a cloud route under a contract that meets the rule.
  • Get specific consent in the retainer. Informed and in writing, naming the vendor, the plan, where data is stored and processed, and the privilege risk. It is best practice, not a rule, and it does not cure an unsuitable tool.
  • Send the question, not the file. Remove names, file numbers, matter names and identifying facts. Anonymizing is imperfect, so assume a determined reader could re-identify what is left.
  • Turn off what leaks. Feedback ratings (on Claude Team and Enterprise an owner can disable them for the organization), memory, public or cross-workspace sharing and unreviewed connectors; keep training off wherever a setting exists.126
  • Decide retention before you start. Set a retention period on Enterprise, knowing that it does not reach every feature and that a project's own retention overrides it;75 delete matter content when the matter ends, and clear local transcripts. Litigation privilege ends with the case, and work product that only it protected is then protected in the vendor's copy only by contract.
  • Mark privileged material. Label prompts and files as privileged and confidential. Markings support an expectation of confidentiality,127 and material that says nothing about privilege may not trigger the Canadian protections described above.
  • Keep the other side's documents out. Discovery material, family financial disclosure and anything under a sealing order, publication ban or protective order go in only where necessary, to a vendor bound in writing, and only if the order allows it.
  • Verify everything you file. Every authority, pinpoint and quotation against an authoritative source, and know whether your court requires a declaration of AI use.
  • Keep the terms on file. Save the dated terms and the settings you relied on. A claim of privilege is yours to prove, and if you ever have to show a limited-purpose disclosure in confidence, this is the evidence.
  • Ask your insurer in writing. Ask whether a disclosure through an AI vendor is covered. The 2026 LAWPRO policy in Ontario excludes cybercrime claims except under a $250,000 sublimit and says nothing about AI; the Saskatchewan insurer's policy wording is not publicly readable.128
  • Plan for a vendor breach. Decide who assesses it and who reports it. Under PIPEDA the firm remains responsible for information it sent out for processing.49

For Claude Code and Codex

  • Sign in to the firm's account and nothing else. Check that no ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN, CLAUDE_CODE_OAUTH_TOKEN, apiKeyHelper script, cloud-provider setting, ANTHROPIC_PROFILE, federation variables or federation profile is in place, and no personal Codex API key. On Claude Team or Enterprise, deploy the forceLoginMethod and forceLoginOrgUUID settings through device management, because server-managed settings cannot redirect a first login; with the organization ID set, Claude Code refuses at startup to run on an ANTHROPIC_API_KEY, ANTHROPIC_AUTH_TOKEN or apiKeyHelper credential, though a token made with claude setup-token is checked only for the login method, and an Anthropic profile or federation credential is not blocked, nor checked for the organization it belongs to. For Codex, set forced_login_method to "chatgpt" and forced_chatgpt_workspace_id to the firm's workspace; Codex logs out a session that does not match.129
  • Disable feedback uploads. For Claude Code, set DISABLE_FEEDBACK_COMMAND=1 and CLAUDE_CODE_DISABLE_FEEDBACK_SURVEY=1; for Codex, turn feedback.enabled off.130
  • Limit local history. Shorten Claude Code's cleanupPeriodDays and set desktopSessionCleanupPeriodDays for Desktop and Cowork sessions, set Codex's history.persistence to "none", and keep ~/.claude and ~/.codex out of synced folders and shared backups. When a matter ends, claude project purge on its folder removes its transcripts, memory and prompt-history lines.117
  • No cloud sessions, Remote Control or public sharing for client files. Turn Remote Control off with Claude Code's disableRemoteControl setting, and on Team or Enterprise leave the Owner's Remote Control toggle off.120 WarmLoop's guided setup asks the assistant to turn Remote Control on for each WarmLoop session; for client work, choose its bare setup instead, and if you already chose the guided setup, also remove the block it installed (see below).
  • Check Codex's separate training switch. On a personal ChatGPT plan, "Include environments" is not changed by the ChatGPT setting;83 better still, keep client work off personal plans.
  • Fence the agent. One matter folder per session, and no full-access mode on a machine that holds other clients' files.
  • Vet every MCP server and connector as you would a vendor. Each is a separate recipient under its own terms.

For any other assistant or MCP server, WarmLoop included

These questions travel to Microsoft Copilot, Google Gemini, any legal AI product and any MCP server, and they track the guidance on assessing third-party service providers that the federal Privacy Commissioner published in September 2026 and is taking comments on until December 4, 2026.131

  • Is there a contract, and does it call your content confidential? A privacy policy is not a promise to you.
  • Does the provider use your content for anything but serving you? Training, product development, safety research, statistics.
  • Who can read it, and when? Staff, contractors and reviewers, and whether access is logged.
  • How long is it kept? Including backups, flagged content and logs, and whether you can delete it.
  • Will it tell you before handing your content to a court or government? And what the exceptions are.
  • Where is it stored, and where is it processed? They are often different places.
  • Who else receives it? Subprocessors, connectors, web search and other tools in the chain.
  • What can the firm control? Accounts, settings, retention and exports.
  • Which law governs, and where are disputes decided?

Higher-assurance routes

If Canadian storage or processing matters to a client, among the plans in the verdict table only ChatGPT Enterprise offers any of it, and only storage at rest, in a workspace provisioned with Canadian data residency; it is listed last below. The cloud platforms come closer, with caveats, and they need technical setup and a different contract. They are noted here, not analysed plan by plan.

  • Claude on Amazon Bedrock. AWS says inputs and outputs are not shared with model providers and are not used to train their models, and that Bedrock does not store them by default; the exception is Anthropic's Fable 5 and 5.1 models, whose traffic is kept for up to 30 days for abuse detection, with flagged traffic open to review by AWS.132 No current Claude model runs in-region in AWS's Canada (Central) region. The closest option is the US geographic profile, which in AWS's words "Keeps data within US and Canada regions".133 Claude Code pointed at a Canadian AWS region defaults to the global profile, which can route anywhere, unless you set the US profile.134 Google's platform lists no Claude model in its Montréal region.135
  • OpenAI models on Microsoft Azure. Microsoft says prompts and completions are not available to OpenAI and are not used to improve OpenAI's models. In Canada East and Canada Central, in-region processing is available only for older models or reserved capacity; the newest models are offered as global deployments that may be processed in any Azure region, and Microsoft may sample prompts for human abuse review unless the customer is approved for modified abuse monitoring. The Codex command-line tool can be pointed at Azure.136
  • ChatGPT Enterprise with Canadian data residency: storage at rest in Canada, inference outside it, as described above.

We did not read the AWS or Microsoft customer agreements, so the contracting party, governing law and legal-process terms on those routes are not verified here.

Where WarmLoop fits, and where it does not

WarmLoop is a Canadian legal research and verification service that a lawyer uses through an AI assistant. It works today, in early access, with Claude (including Claude Code) and with OpenAI's ChatGPT and Codex; each seat is set up by hand during the pilot. A reader of this article is entitled to ask what it does about the problem described here, and to put WarmLoop to the questions this article asks of every other vendor.

It does not make the model vendor's terms go away. WarmLoop is one more service provider in the chain. Every query you send and every result it returns, including the full text of documents and the content of Records, passes through your assistant's vendor, under your agreement with that vendor and outside WarmLoop's control.137 Everything above about the vendors applies whether or not WarmLoop is connected.

Here are WarmLoop's own answers to the questions in the checklist, taken from its Terms of Service and Privacy Policy of September 23, 2026.

  • Is there a contract, and does it call your content confidential? Yes. The Terms treat your content and account information as confidential, allow disclosure only to named service providers, the readers you approve for a Record, WarmLoop's professional advisers, a successor, a court in a dispute with you and a person who needs it because of an emergency that threatens an individual's life, health or security, and otherwise where the law requires, and do not displace your own duties of confidentiality and privilege.138
  • Does it use your content for anything but serving you? WarmLoop does not use your content to train AI models, and does not use the text of your research queries to develop the service or send it to an AI tool outside Canada. The Privacy Policy says two things keep that promise: the service sends query text to no AI model other than the reranking model in Canada, and the features that could send a request to such a model when a user asks for it are switched off; and WarmLoop's rule is that its development tools are not used to read query text, a rule "kept by WarmLoop's own practice, not by a technical control". Other content WarmLoop examines in its development and support work, such as feedback, is processed through Anthropic's Claude, which is hosted outside Canada, and feedback is kept indefinitely and used to improve the service.139
  • Who can read it, and when? WarmLoop's development tools run on the computers and servers where your content is held, so the rule that they are not used to read your query text is a rule WarmLoop keeps, not one its systems enforce. It accesses a Record's content only as needed to operate, secure, support and troubleshoot the service, to act on a notice, or where the law requires. WarmLoop's owner also practises law, at a firm that is a separate organization and itself a WarmLoop customer. The Privacy Policy says that the owner's access to WarmLoop's data is "on WarmLoop's behalf only", and that WarmLoop makes no personal information of its users available to that firm, other than what any customer receives about its own account and its own Records. Whether WarmLoop's own access to your content is logged, neither the Terms nor the Privacy Policy says. Both describe an access log for each Record, which records each view and each exhibit opened and which the Customer can see; the Privacy Policy also describes an audit log of listed platform events and logs of WarmLoop's administrative sessions on its servers, kept for 400 days. Neither says in terms that any of them records WarmLoop's own reading of your content.139
  • How long is it kept? Query text is deleted from the query log 30 days after it is recorded and stays for about 12 months more in encrypted backups, longer on a backup drive connected less often than once a month, and the two most recent nightly copies of that database are kept unencrypted on WarmLoop's own server. Some search text, and the citations and passages sent for checking, sit in request logs with no set deletion period, and a citation form you look up may be kept permanently. Records are kept until they are removed, with no self-service delete; WarmLoop acts on a request for removal within 30 days, except so far as it must keep information by law, and Records stay in encrypted database backups for up to about 120 days after removal; the text and exhibits of a publication that failed are kept with no set period. Transcripts of WarmLoop's development and support work, which can contain feedback and other content examined in it, are copied to Apple's iCloud Drive and kept indefinitely.140
  • Will it tell you before handing your content to a court or government? Yes, unless it is legally prevented: the Terms promise to tell you of a lawful demand for your content "so that the Customer can assert privilege or object". The promise covers a lawful demand only; the Terms make no promise to tell you of a disclosure to a person who needs your content because of an emergency.138
  • Where is it stored, and where is it processed? WarmLoop's own systems run in Canada. The web service, its database and the Record store run in Amazon Web Services' Canada (Central) region, and the corpus, search and query log on WarmLoop's own servers in Saskatchewan. The text of each query, with candidate passages, is also sent to a reranking model (Cohere Rerank) that Amazon Web Services hosts in Canada (Central). Content WarmLoop examines in its development and support work, such as feedback, is processed by Anthropic outside Canada; Apple holds copies of the transcripts of that work, which can contain such content, and GitHub holds summaries of feedback, in places WarmLoop does not control, some of them outside Canada, as the next answer says.141
  • Who else receives it? Your assistant's vendor receives everything, as above. Anthropic (development and support, outside Canada), Apple (the iCloud copies of development transcripts), GitHub (summaries of feedback and test queries derived from it) and Microsoft (WarmLoop's mailboxes) process content in places WarmLoop does not control, some of them outside Canada; Stripe, Google and Microsoft sign-in, and Cloudflare for the website alone, handle payment, sign-in and website data.141
  • What can the firm control? Less than on the vendors' enterprise plans. There is no self-service export or deletion of an account, its data or a Record; requests go to WarmLoop, which answers within 30 days; and each account belongs to one user.142
  • Which law governs, and where are disputes decided? Saskatchewan law, before a single arbitrator in Regina, with a class waiver and no appeal to a court on a question of law. Liability is capped at the greater of two months' fees and $500, or, for a breach of confidentiality or of WarmLoop's security safeguards for personal information, the greater of 12 months' fees and $5,000; lost data and consequential loss are excluded for every claim short of fraud or wilful misconduct; and there is no uptime commitment.143 Measured against the vendors' business terms, which cap liability at 12 months' fees, WarmLoop's general cap is lower; its cap for a breach of confidentiality is the same 12 months' fees, with a $5,000 floor; and, like Anthropic's terms and unlike OpenAI's, it keeps consequential loss excluded even for a breach of confidentiality.101

One thing WarmLoop's guided setup does cuts against this article's own checklist. If you choose that setup, the instructions it adds to your assistant include one to turn on the assistant's remote-control feature "for each WarmLoop session", or to tell you how, and later setup runs may refresh those instructions without asking you again.144 On Claude Code that feature is Remote Control, which stores the session transcript on Anthropic's servers and retains it under Anthropic's data-usage policy; organizations with zero data retention cannot enable it.120 A lawyer working on client files should choose WarmLoop's bare setup, which writes nothing, or turn Remote Control off in Claude Code as the checklist describes. If you have already chosen the guided setup, switching each connection to the bare setup means later setup runs refresh nothing, but the Terms do not say it removes what is already installed, and the marked block in CLAUDE.md or AGENTS.md carries that instruction. Remove the block as well, or remove everything the guided setup installed (the block, the command and agent-definition files, and the templates and programs it downloaded or copied), after which a setup run is to ask you again before it installs anything.144

What WarmLoop is for is the second risk, and minimisation on the first. It returns Canadian law with checked citations and pinpoints, and checks a draft's citations and quoted passages against the text it holds. It machine-checks; it does not review or endorse an argument, and "verified" means it found the case, the pinpoint and a close match for the quoted words in an unofficial copy, not that the authority is good law.145 Research and citation checking need no document uploads; you upload documents only if you choose to publish a Record, which WarmLoop keeps as described above. A research question can be framed without a client's name or identifying facts.146 Checking a draft still exposes it to your assistant's vendor. To check a draft, your assistant reads it, or at least the passages it checks, so your assistant's vendor receives them as it receives everything else,137 and the citations looked up and the passages sent to be located stay in WarmLoop's request logs with no set deletion period.140 For a client draft, either use an assistant on a plan and settings that meet the conditions above, or take the citations and the quoted passages out of the draft and give the assistant only those to check. WarmLoop's Terms do require you to use your assistant's no-training setting wherever it has one, but that clause protects material retrieved from WarmLoop from being used to train models; it is not a confidentiality protection for your files, and where an assistant offers no such setting, the vendor's use of your conversations is not a breach of that clause by you.147 None of that makes a consumer plan safe for client files. It means the research half of the work need not put them there.

About this article

Written and published by WarmLoop Ltd. WarmLoop is not affiliated with Anthropic or OpenAI and receives nothing from either. WarmLoop uses Anthropic's Claude in its own development and support work, as its Privacy Policy discloses. WarmLoop sells a research service that lawyers use through these assistants; read what this article says about them with that in mind.

This article was prepared with the assistance of AI. Every AI agent described here ran on Anthropic's Claude. AI agents researched and drafted it, using WarmLoop's own research tools for the Canadian law and, for everything else, the publisher's own site, except where this paragraph or a source note says otherwise. The first complete draft was checked by AI agents working independently of the agent that drafted it: 190 of its 191 items of legal content (source notes and statements of law) against the text of the authority or the regulator's own document, and 109 of its 116 items about the vendors and WarmLoop against the vendor's page or WarmLoop's own Terms and Privacy Policy. The other eight rested on secondary sources or on the page that links a document, because the checkers did not open the file itself. A further AI agent was briefed to argue against that draft. AI agents then corrected the draft in rounds, adding authorities and pages the first draft did not cite, and after each round fresh AI agents, which had no part in drafting or correcting it, re-checked the passages that changed against their sources. Before publication, the citations of Canadian decisions were machine-checked with WarmLoop's citation checker against the text of the decisions it holds. The checker does not hold the United States decisions and orders cited in notes 88, 90, 92 and 103 to 107, so they were not machine-checked; they were read from the copies those notes link, on a court's own site or hosted by a news site or another third party. No human has reviewed this article or re-checked any item in it. A check confirms that an item matches the source cited for it; it does not confirm that the source is complete, that the selection is representative, or that any conclusion drawn from it is right, and it was not a full note-up of every case cited. Where any other source was read from a news site's, a third party's or an archived copy, its note says so. Before relying on an item, read the source named for it. Each vendor term is stated as of the date its own document carries; negotiated enterprise agreements and order forms are not public and were not read.

This article is general information about the law and the vendors' published terms. It is not legal advice about any matter.

If you find an error, write to info@warmloop.com.

Source notes

  1. Searches of Canadian case law run in WarmLoop's research service and on the web on September 23, 2026, for this article, on waiver or loss of confidentiality through generative AI tools and through cloud and AI vendors, and on the production of AI prompts and chat logs, found no Canadian decision on the point. A search that finds nothing is not proof that nothing exists. ↑ Back
  2. OpenAI, "Enterprise privacy at OpenAI" (updated January 8, 2026), General FAQ, https://openai.com/enterprise-privacy/; OpenAI, "OpenAI Student Data Privacy Agreement" (no date on the document), https://cdn.openai.com/osa/openai-sdpa.pdf; OpenAI Help Center, "ChatGPT Edu at OpenAI" (page showed "Updated: 2 months ago"), https://help.openai.com/en/articles/9377311-chatgpt-edu-at-openai; all retrieved September 23, 2026. ↑ Back
  3. Law Society of Ontario v Lee, 2026 ONLSTH 136 at paras 40 and 41 (Law Society Tribunal, Hearing Division). ↑ Back
  4. Reddy v Saroya, 2026 ABCA 20 at paras 1, 12 and 14. ↑ Back
  5. Kapahi Real Estate Inc. v Elite Real Estate Club of Toronto Inc., 2026 ONSC 1438 at paras 1 and 2. ↑ Back
  6. Court of King's Bench for Saskatchewan, General Application Practice Directive #12, "Use of Artificial Intellegence [sic] in Court Submissions" (GA-PD #12, effective January 1, 2026), paras 5, 7 and 8. ↑ Back
  7. R v Fox, 2026 SCC 4 at para 31. ↑ Back
  8. R v Fox, 2026 SCC 4 at paras 32 and 40. ↑ Back
  9. Chapelstone Developments Inc., Action Motors Ltd. and Hamilton v Her Majesty the Queen in Right of Canada, 2004 NBCA 96 at paras 45 and 46. ↑ Back
  10. Medynski v Rural Municipality of Prince Albert No. 461, 2023 SKCA 88 at paras 24 and 26. ↑ Back
  11. Boldt v Saskatchewan Telecommunications, 2025 SKCA 54 at para 22. ↑ Back
  12. Milicevic v T. Smith Engineering, 2016 ONSC 2166 at para 204. ↑ Back
  13. Leroux v Proex Inc., 2022 ONSC 319 at paras 25, 36 and 37. ↑ Back
  14. MBL Administrative Agent II LLC et al. v Trade X Group of Companies Inc. et al., 2024 ONSC 3734 at paras 78, 80, 83, 87, 88 and 100 (Commercial List). ↑ Back
  15. Canada (National Revenue) v Thornton, 2012 FC 1313 at paras 47, 48 and 50. ↑ Back
  16. Redhead Equipment v Canada (Attorney General), 2016 SKCA 115 at paras 43 and 45. ↑ Back
  17. Milicevic v T. Smith Engineering, 2016 ONSC 2166 at paras 202, 203 and 205. ↑ Back
  18. Redhead Equipment v Canada (Attorney General), 2016 SKCA 115 at paras 44 and 45. ↑ Back
  19. Camp Development Corporation v South Coast Greater Vancouver Transportation Authority, 2011 BCSC 88 at para 70. ↑ Back
  20. Popowich v Saskatchewan, 1998 CanLII 13799 (SK QB) at para 17, in a ruling on the production of a counselling clinic's records, aff'd sub nom Saskatoon District Health Board v Bryden, 1999 CanLII 12267 (SK CA) at para 7, without discussion of waiver. ↑ Back
  21. Blank v Canada (Minister of Justice), 2006 SCC 39 at para 32. ↑ Back
  22. Windsor (City) v MFP Financial Services Ltd., 2004 CanLII 44802 (ON CA) at paras 13 and 14 (the passage on voluntary disclosure is the court quoting an American decision adopted in an earlier decision of the same court). ↑ Back
  23. Blank v Canada (Minister of Justice), 2006 SCC 39 at paras 34, 36 and 37. ↑ Back
  24. Windsor (City) v MFP Financial Services Ltd., 2004 CanLII 44802 (ON CA) at para 16. ↑ Back
  25. Blank v Canada (Minister of Justice), 2006 SCC 39 at para 27. ↑ Back
  26. R v A.B., 2014 NLCA 8 at paras 1, 34 and 48. ↑ Back
  27. Chad v Canada (National Revenue), 2025 FCA 102 at paras 21 and 22. ↑ Back
  28. Code of Professional Conduct for Lawyers (Law Society of Saskatchewan, consolidation of April 30, 2026), r 3.1-2, commentary [4A]. ↑ Back
  29. Federation of Law Societies of Canada, Model Code of Professional Conduct (as amended April 2024), r 3.1-2, commentary [4A], https://flsc.ca/wp-content/uploads/2024/11/2024-Model-Code-of-Professional-Conduct.pdf; Law Society of Ontario, "Licensee use of generative artificial intelligence" (white paper, April 2024) at 8, reproducing the Ontario commentary, https://lawsocietyontario-dwd0dscmayfwh7bj.a01.azurefd.net/media/lso/media/lawyers/practice-supports-resources/white-paper-on-licensee-use-of-generative-artificial-intelligence-en.pdf; Law Society of Alberta, "Code of Conduct Changes" (February 27, 2020), describing the Alberta commentary to r 3.1-2, https://www.lawsociety.ab.ca/code-of-conduct-changes/; each read on the issuing body's own site, retrieved September 23, 2026. ↑ Back
  30. Law Society of Newfoundland and Labrador, "Artificial Intelligence in Your Practice" (undated), https://lsnl.ca/artificial-intelligence-in-your-practice/, retrieved September 23, 2026; an archived copy captured June 15, 2026 carries the same words, https://web.archive.org/web/20260615084531id_/https://lsnl.ca/artificial-intelligence-in-your-practice/. ↑ Back
  31. Code of Professional Conduct for Lawyers (Law Society of Saskatchewan, consolidation of April 30, 2026), r 3.3-1 and commentary [2]. ↑ Back
  32. Code of Professional Conduct for Lawyers (Law Society of Saskatchewan, consolidation of April 30, 2026), r 3.3-1, commentary [9]. ↑ Back
  33. Code of Professional Conduct for Lawyers (Law Society of Saskatchewan, consolidation of April 30, 2026), r 3.3-2. ↑ Back
  34. Code of Professional Conduct for Lawyers (Law Society of Saskatchewan, consolidation of April 30, 2026), r 3.5-1, commentary [2]. ↑ Back
  35. Law Society of British Columbia, Law Society Rules 2015, rr 10-3(1), 10-3(4) and 10-4(1) and (2), read on the Law Society's own site (the corpus WarmLoop searches does not hold them), https://www.lawsociety.bc.ca/for-lawyers/act-rules-and-code/law-society-rules/part-10-%E2%80%93-general/, retrieved September 23, 2026. ↑ Back
  36. Law Society of British Columbia, "Guidance on Professional Responsibility and Generative AI" (practice resource, prepared October 2023) at 4, https://www.lawsociety.bc.ca/getContentAsset/91264ae3-9fa0-4063-88fb-69977a293f62/dfc3d011-8f63-43f6-9ed8-4b444333a1d0/Professional-responsibility-and-AI.pdf?language=en-CA, retrieved September 23, 2026. ↑ Back
  37. Law Society of Saskatchewan, "Guidelines for the Use of Generative Artificial Intelligence in the Practice of Law" (updated February 2024) at 4, https://www.lawsociety.sk.ca/wp-content/uploads/Law-Society-of-Saskatchewan-Generative-Artificial-Intelligence-Guidelines.pdf, retrieved September 23, 2026. ↑ Back
  38. Law Society of Ontario, "Licensee use of generative artificial intelligence" (white paper, April 2024) at 10, https://lawsocietyontario-dwd0dscmayfwh7bj.a01.azurefd.net/media/lso/media/lawyers/practice-supports-resources/white-paper-on-licensee-use-of-generative-artificial-intelligence-en.pdf, retrieved September 23, 2026. ↑ Back
  39. Law Society of Alberta, "The Generative AI Playbook" (last updated February 2026), https://www.lawsociety.ab.ca/resource-centre/key-resources/professional-conduct/the-generative-ai-playbook/, retrieved September 23, 2026. ↑ Back
  40. Law Society of Alberta, "Generative AI and Technological Competence: Quick Tips for Alberta Lawyers" (last updated July 2025), https://www.lawsociety.ab.ca/resource-centre/key-resources/practice-management/generative-ai-and-technological-competence-quick-tips-for-alberta-lawyers/, retrieved September 23, 2026. ↑ Back
  41. Law Society of Saskatchewan, "Guidelines for the Use of Generative Artificial Intelligence in the Practice of Law" (updated February 2024) at 4, https://www.lawsociety.sk.ca/wp-content/uploads/Law-Society-of-Saskatchewan-Generative-Artificial-Intelligence-Guidelines.pdf; Law Society of Manitoba, "Generative Artificial Intelligence: Guidelines for Use in the Practice of Law" (April 2024) at 3, https://educationcentre.lawsociety.mb.ca/wp-content/uploads/sites/2/2024/04/Generative-Artificial-Intelligence-Guidelines-for-Use-in-the-Practice-of-Law.pdf; both retrieved September 23, 2026. ↑ Back
  42. Law Society of Ontario, "Generative AI: Your professional obligations" (practice note, dated April 10, 2024) at 3, https://lawsocietyontario-dwd0dscmayfwh7bj.a01.azurefd.net/media/lso/media/lawyers/practice-supports-resources/generative-ai-your-professional-obligations.pdf, retrieved September 23, 2026. ↑ Back
  43. Law Society of Prince Edward Island, "Artificial Intelligence Guidelines" (no date on the document) at 6, https://lawsocietypei.ca/media/files/LSPEI%20-%20Artificial%20Intelligence%20Guidelines.pdf, retrieved September 23, 2026. ↑ Back
  44. Law Society of British Columbia, "Guidance on Professional Responsibility and Generative AI" (practice resource, prepared October 2023) at 3, https://www.lawsociety.bc.ca/getContentAsset/91264ae3-9fa0-4063-88fb-69977a293f62/dfc3d011-8f63-43f6-9ed8-4b444333a1d0/Professional-responsibility-and-AI.pdf?language=en-CA, retrieved September 23, 2026. ↑ Back
  45. American Bar Association Standing Committee on Ethics and Professional Responsibility, Formal Opinion 512, "Generative Artificial Intelligence Tools" (July 29, 2024) at 6 and 7, read from an archived copy of the official PDF (the live file refused automated retrieval), https://web.archive.org/web/20251213000857id_/https://www.americanbar.org/content/dam/aba/administrative/professional_responsibility/ethics-opinions/aba-formal-opinion-512.pdf, retrieved September 23, 2026. A foreign source, not binding in Canada. ↑ Back
  46. Canadian Bar Association, "Ethics of Artificial Intelligence for the Legal Practitioner", part 3, "Guidelines relating to use", section 3.4 (no date on the page), https://cba.org/resources/practice-tools/ethics-of-artificial-intelligence-for-the-legal-practitioner/3-guidelines-relating-to-use/, retrieved September 23, 2026. ↑ Back
  47. Personal Information Protection and Electronic Documents Act, SC 2000, c 5, s 4(1)(a); Organizations in the Province of Alberta Exemption Order, SOR/2004-219, s 1; Organizations in the Province of British Columbia Exemption Order, SOR/2004-220, s 1; Personal Information Protection Act, SA 2003, c P-6.5; Personal Information Protection Act, SBC 2003, c 63. ↑ Back
  48. State Farm Mutual Automobile Insurance Company v Privacy Commissioner of Canada, 2010 FC 736 at paras 106 and 107. ↑ Back
  49. Personal Information Protection and Electronic Documents Act, SC 2000, c 5, Sch 1, cl 4.1.3. ↑ Back
  50. Personal Information Protection and Electronic Documents Act, SC 2000, c 5, s 10.1(1). ↑ Back
  51. Personal Information Protection Act, SA 2003, c P-6.5, ss 6(2) and 13.1. ↑ Back
  52. Office of the Privacy Commissioner of Canada, "Guidelines for processing personal data across borders" (January 2009), https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/, retrieved September 23, 2026. ↑ Back
  53. Office of the Privacy Commissioner of Canada, "PIPEDA Findings #2026-002: Joint Investigation of OpenAI OpCo, LLC" (May 6, 2026), https://www.priv.gc.ca/en/opc-actions-and-decisions/investigations/investigations-into-businesses/2026/pipeda-2026-002/, and "Backgrounder: Summary of joint investigation into OpenAI's ChatGPT" (May 6, 2026), https://www.priv.gc.ca/en/opc-news/news-and-announcements/2026/bg-info_openai_260506/; both retrieved September 23, 2026. The findings were made by the federal Commissioner, the Commission d'accès à l'information du Québec and the British Columbia and Alberta commissioners; the federal Commissioner found the matter well-founded and conditionally resolved (on the use of users' interactions with ChatGPT to improve the models: the four regulators found that the use served an appropriate purpose, so that aspect was not well-founded, at para 106; the federal, Alberta and British Columbia commissioners found that OpenAI had not obtained valid consent to train its GPT-3.5 and GPT-4 models on those interactions, contrary to PIPEDA s 6.1 and Sch 1, cl 4.3, ss 7 and 8 of Alberta's Personal Information Protection Act and ss 6 to 8 of British Columbia's, at paras 306 and 307, an aspect the federal Commissioner then found well-founded and conditionally resolved, accepting that OpenAI may rely on implied consent for its future models, at paras 310 and 311; and the Commission d'accès à l'information du Québec found OpenAI's collection of chats for training contrary to Quebec's private-sector Act, s 8 for the free web version, at para 322, and s 9.1, at para 324), while the British Columbia and Alberta commissioners found some aspects well-founded and unresolved, as did the Commission d'accès à l'information du Québec on consent and retention. The record that the training setting was enabled by default is at para 332, in the Commission d'accès à l'information du Québec's analysis under s 9.1 of Quebec's Act respecting the protection of personal information in the private sector, which requires the highest privacy settings by default. ↑ Back
  54. Law Society of British Columbia, "Practice Resource: Cloud computing due diligence guidelines" (excerpted from the Report of the Cloud Computing Working Group, January 27, 2012), part B, https://www.lawsociety.bc.ca/Website/media/Shared/docs/practice/resources/guidelines-cloud.pdf, retrieved September 23, 2026. ↑ Back
  55. Federal Court, "Notice to the Parties and the Profession: The Use of Artificial Intelligence in Court Proceedings" (May 7, 2024), https://www.fct-cf.ca/Content/assets/pdf/base/FC-Updated-AI-Notice-EN.pdf, retrieved September 23, 2026. ↑ Back
  56. Court of King's Bench (Manitoba), Practice Direction, "Use of Artificial Intelligence in Court Submissions" (June 23, 2023), https://www.manitobacourts.mb.ca/site/assets/files/2045/practice_direction_-_use_of_artificial_intelligence_in_court_submissions.pdf, retrieved September 23, 2026. ↑ Back
  57. Provincial Court of British Columbia, "Guidance on using AI to prepare for court" (eNews, published July 8, 2026), https://provincialcourt.bc.ca/news-notices-policies-and-practice-directions/enews/07-07-2026, retrieved September 23, 2026. ↑ Back
  58. Juman v Doucette, 2008 SCC 8 at paras 25 and 27. ↑ Back
  59. The King's Bench Rules (Saskatchewan), r 5-4(1) and (3). ↑ Back
  60. The King's Bench Rules (Saskatchewan), r 15-6(1) and (4). ↑ Back
  61. Seedlings Life Science Ventures LLC v Pfizer Canada Inc., 2018 FC 443 at paras 40, 46, 47 and 49 (Prothonotary Tabib, reasons for order), rev'd on another ground, 2018 FC 956 at paras 5, 26, 27 and 29 (Ahmed J; the observation about third parties is at para 31); recorded as reversed in Canadian National Railway Company v BNSF Railway Company, 2020 FCA 45 at para 8. ↑ Back
  62. Anthropic, "Consumer Terms of Service" (effective October 8, 2025; the version served in Canada), preamble, https://www.anthropic.com/legal/consumer-terms; Anthropic, "Privacy Policy" (effective September 10, 2026), https://www.anthropic.com/legal/privacy; Claude Help Center, "What is the Max plan?" (updated September 22, 2026), https://support.claude.com/en/articles/11049741-what-is-the-max-plan; Anthropic Privacy Center, "How long do you store my data?" (updated July 1, 2026), which states that it concerns "consumer products such as Claude Free, Pro, Max", https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data; all retrieved September 23, 2026. ↑ Back
  63. Anthropic, "Consumer Terms of Service" (effective October 8, 2025), s 4, https://www.anthropic.com/legal/consumer-terms, retrieved September 23, 2026. ↑ Back
  64. Anthropic, "Consumer Terms of Service" (effective October 8, 2025), s 12, https://www.anthropic.com/legal/consumer-terms, retrieved September 23, 2026. The Consumer Terms contain no confidentiality clause in the user's favour. ↑ Back
  65. Anthropic, "Privacy Policy" (effective September 10, 2026), s 11, "Supplemental Disclosures for Residents of Canada", https://www.anthropic.com/legal/privacy, retrieved September 23, 2026. ↑ Back
  66. Anthropic Privacy Center, "How long do you store my data?" (updated July 1, 2026), https://privacy.claude.com/en/articles/10023548-how-long-do-you-store-my-data, retrieved September 23, 2026. ↑ Back
  67. Anthropic Privacy Center, "How does Anthropic protect the personal data of Claude users?" (updated March 16, 2026), https://privacy.claude.com/en/articles/10458704-how-does-anthropic-protect-the-personal-data-of-claude-users, retrieved September 23, 2026. ↑ Back
  68. Claude Help Center, "I would like to input sensitive data into my chats with Claude. Who can view my conversations?" (updated May 22, 2026), https://support.claude.com/en/articles/8325621-i-would-like-to-input-sensitive-data-into-my-chats-with-claude-who-can-view-my-conversations, retrieved September 23, 2026. ↑ Back
  69. Anthropic, "Consumer Terms of Service" (effective October 8, 2025), s 2, "Business Domains", https://www.anthropic.com/legal/consumer-terms, retrieved September 23, 2026. ↑ Back
  70. Anthropic, "Commercial Terms of Service" (effective June 17, 2025), https://www.anthropic.com/legal/commercial-terms; Anthropic, "Data Processing Addendum" (effective February 24, 2025), https://www.anthropic.com/legal/data-processing-addendum; Anthropic Privacy Center, "How do I view and sign your Data Processing Addendum (DPA)?" (updated March 16, 2026), https://privacy.claude.com/en/articles/7996862-how-do-i-view-and-sign-your-data-processing-addendum-dpa; Anthropic, "Service Specific Terms" (effective June 8, 2026), s A, https://www.anthropic.com/legal/service-specific-terms; all retrieved September 23, 2026. ↑ Back
  71. Anthropic, "Commercial Terms of Service" (effective June 17, 2025), ss B and E.1, https://www.anthropic.com/legal/commercial-terms; Anthropic Privacy Center, "Is my data used for model training?" (dated August 18, 2026), on commercial products, https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training; both retrieved September 23, 2026. ↑ Back
  72. Anthropic, "Commercial Terms of Service" (effective June 17, 2025), ss E.2, E.3 and E.4, https://www.anthropic.com/legal/commercial-terms, retrieved September 23, 2026. ↑ Back
  73. Anthropic, "Data Processing Addendum" (effective February 24, 2025), ss B.1, G.1 and H.1, https://www.anthropic.com/legal/data-processing-addendum, retrieved September 23, 2026. ↑ Back
  74. Anthropic Privacy Center, "Where are your servers located? Do you host your models on EU servers?" (updated June 15, 2026), https://privacy.claude.com/en/articles/7996890-where-are-your-servers-located-do-you-host-your-models-on-eu-servers; Claude Help Center, "Enable US-only inference for your organization" (updated June 15, 2026), https://support.claude.com/en/articles/15422948-enable-us-only-inference-for-your-organization; both retrieved September 23, 2026. ↑ Back
  75. Anthropic Privacy Center, "How long do you store my organization's data?" (updated July 1, 2026), https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data; Anthropic Privacy Center, "Configure custom data retention controls for Enterprise plans" (updated September 14, 2026), https://privacy.claude.com/en/articles/10440198-configure-custom-data-retention-controls-for-enterprise-plans; both retrieved September 23, 2026. ↑ Back
  76. Claude Help Center, "What is the Team plan?" (updated September 22, 2026), https://support.claude.com/en/articles/9266767-what-is-the-team-plan; Claude Help Center, "What is the Enterprise plan?" (updated September 1, 2026), https://support.claude.com/en/articles/9797531-what-is-the-enterprise-plan; both retrieved September 23, 2026. ↑ Back
  77. Claude Help Center, "What is the Enterprise plan?" (updated September 1, 2026), https://support.claude.com/en/articles/9797531-what-is-the-enterprise-plan; Claude Code documentation, "Zero data retention" (page modified September 15, 2026), https://code.claude.com/docs/en/zero-data-retention; both retrieved September 23, 2026. ↑ Back
  78. Claude, "Claude Legal Solutions" (no date on the page), https://claude.com/solutions/legal, retrieved September 23, 2026. ↑ Back
  79. Anthropic, "Commercial Terms of Service" (effective June 17, 2025), s D.3, https://www.anthropic.com/legal/commercial-terms, retrieved September 23, 2026. ↑ Back
  80. Claude, "Regional Compliance" (no date on the page), https://claude.com/regional-compliance, retrieved September 23, 2026. ↑ Back
  81. OpenAI, "Terms of Use" (published and effective January 1, 2026), introduction, https://openai.com/policies/terms-of-use/; OpenAI Help Center, "What is ChatGPT Go?" (page showed "Updated: last month"), https://help.openai.com/en/articles/11989085-what-is-chatgpt-go; OpenAI Help Center, "ChatGPT Supported Countries" (page showed "Updated: last month"), https://help.openai.com/en/articles/7947663-chatgpt-supported-countries; all retrieved September 23, 2026. ↑ Back
  82. OpenAI, "Terms of Use" (effective January 1, 2026), "Content", https://openai.com/policies/terms-of-use/, retrieved September 23, 2026. ↑ Back
  83. OpenAI Help Center, "Data controls in ChatGPT" (page showed "Updated: 2 days ago"), https://help.openai.com/en/articles/7730893-data-controls-faq; OpenAI Help Center, "How your data is used to improve model performance" (page showed "Updated: 2 days ago"), https://help.openai.com/en/articles/5722486-how-your-data-is-used-to-improve-model-performance; both retrieved September 23, 2026. ↑ Back
  84. OpenAI Help Center, "Chat and file retention in ChatGPT" (page showed "Updated: 14 hours ago"), https://help.openai.com/en/articles/8983778-chat-and-file-retention-policies-in-chatgpt, retrieved September 23, 2026. ↑ Back
  85. OpenAI Help Center, "How we identify problematic content on our services for individuals" (page showed "Updated: 22 days ago"), https://help.openai.com/en/articles/8940831-how-we-identify-problematic-content-on-our-services-for-individuals; OpenAI, "Helping people when they need it most" (August 26, 2025), https://openai.com/index/helping-people-when-they-need-it-most/; both retrieved September 23, 2026. ↑ Back
  86. OpenAI, "Privacy policy" (updated July 30, 2026), s 3, https://openai.com/policies/privacy-policy/; OpenAI, "OpenAI Government User Data Request Policy" (effective January 1, 2026), part V, https://cdn.openai.com/pdf/openai-law-enforcement-policy-v.2025-12.pdf; both retrieved September 23, 2026. ↑ Back
  87. OpenAI, "Terms of Use" (effective January 1, 2026), "Dispute resolution" and "Governing law", https://openai.com/policies/terms-of-use/, retrieved September 23, 2026. ↑ Back
  88. In re OpenAI, Inc. Copyright Infringement Litigation, No 25-md-3143 (SDNY May 13, 2025), Order (Wang MJ), ECF No 33 (relating to The New York Times Company v Microsoft Corporation, No 23-cv-11195), court document read from a copy hosted by a news site, https://cdn.arstechnica.net/wp-content/uploads/2025/06/NYT-v-OpenAI-Preservation-Order-5-13-25.pdf, retrieved September 23, 2026. A foreign source, not binding in Canada. ↑ Back
  89. OpenAI, "How we're responding to The New York Times' data demands in order to protect user privacy" (June 5, 2025, updated October 22, 2025), https://openai.com/index/response-to-nyt-data-demands/, retrieved September 23, 2026. ↑ Back
  90. In re OpenAI, Inc. Copyright Infringement Litigation, No 25-md-3143 (SDNY October 9, 2025), Stipulation and Order to Terminate OpenAI's Ongoing Obligations under the Preservation Order at ECF 33 (relating to The New York Times Company v Microsoft Corporation, No 23-cv-11195), filed in No 1:23-cv-11195 as Document 922, paras 1 and 2, court document read from a copy hosted by a news site, https://cdn.arstechnica.net/wp-content/uploads/2025/10/NYT-v-OPenAI-Order-to-Terminate-OpenAIs-Preservation-Order-10-9-25.pdf; OpenAI, "How we're responding to The New York Times' data demands in order to protect user privacy" (update of October 22, 2025), https://openai.com/index/response-to-nyt-data-demands/; both retrieved September 23, 2026. A foreign source, not binding in Canada. ↑ Back
  91. OpenAI, "Fighting the New York Times' invasion of user privacy" (November 12, 2025), questions "Is my data potentially impacted?" and "Are business customers potentially impacted?", https://openai.com/index/fighting-nyt-user-privacy-invasion/, retrieved September 23, 2026. ↑ Back
  92. In re OpenAI, Inc. Copyright Infringement Litigation, No 25-md-3143 (SDNY January 5, 2026), Order (Stein J), ECF No 1021 at 1 to 3, https://storage.courtlistener.com/recap/gov.uscourts.nysd.640396/gov.uscourts.nysd.640396.1021.0.pdf, retrieved September 23, 2026. A foreign source, not binding in Canada. ↑ Back
  93. OpenAI Help Center, "ChatGPT Business: General FAQ" (page showed "Updated: 17 hours ago"), https://help.openai.com/en/articles/8542115-chatgpt-business-general-faq, retrieved September 23, 2026. ↑ Back
  94. OpenAI, "OpenAI Services Agreement" (updated December 1, 2025; effective January 1, 2026), preamble and s 5.3, https://openai.com/policies/services-agreement/; OpenAI, "OpenAI Data Processing Addendum" (updated December 1, 2025; effective January 1, 2026), https://openai.com/policies/data-processing-addendum/; both retrieved September 23, 2026. ↑ Back
  95. OpenAI, "OpenAI Services Agreement" (effective January 1, 2026), ss 4.2, 7.1, 7.3 and 17, https://openai.com/policies/services-agreement/, retrieved September 23, 2026. ↑ Back
  96. OpenAI, "OpenAI Data Processing Addendum" (effective January 1, 2026), s 6, definition of "Customer Data", https://openai.com/policies/data-processing-addendum/, retrieved September 23, 2026. ↑ Back
  97. OpenAI, "Enterprise privacy at OpenAI" (updated January 8, 2026), https://openai.com/enterprise-privacy/, retrieved September 23, 2026. ↑ Back
  98. OpenAI, "Introducing Astra for Law" (September 17, 2026), https://openai.com/index/astra-for-law/; OpenAI Help Center, "Astra for Law" (page showed "Updated: 5 days ago"), https://help.openai.com/en/articles/20001528-astra-for-law; both retrieved September 23, 2026. ↑ Back
  99. OpenAI, "Enterprise privacy at OpenAI" (updated January 8, 2026), https://openai.com/enterprise-privacy/; OpenAI Academy, "Data governance and compliance" (last updated September 17, 2026), https://academy.openai.com/public/clubs/admins-6o6xf/resources/data-governance-and-compliance; both retrieved September 23, 2026. ↑ Back
  100. OpenAI Help Center, "Data residency and inference residency for ChatGPT" (page showed "Updated: 8 days ago"), https://help.openai.com/en/articles/9903489-data-residency-and-inference-residency-for-chatgpt, retrieved September 23, 2026. ↑ Back
  101. OpenAI, "OpenAI Services Agreement" (effective January 1, 2026), ss 14.1 and 14.2, https://openai.com/policies/services-agreement/; Anthropic, "Commercial Terms of Service" (effective June 17, 2025), s L.3, https://www.anthropic.com/legal/commercial-terms; both retrieved September 23, 2026. ↑ Back
  102. Anthropic Privacy Center, "What is Anthropic's policy for handling governmental requests for user information?" (updated March 16, 2026), https://privacy.claude.com/en/articles/10023650-what-is-anthropic-s-policy-for-handling-governmental-requests-for-user-information; OpenAI, "OpenAI Government User Data Request Policy" (effective January 1, 2026), part V, https://cdn.openai.com/pdf/openai-law-enforcement-policy-v.2025-12.pdf; OpenAI, "Serving civil subpoenas or other civil requests for user data on OpenAI" (published April 24, 2026), https://openai.com/policies/civil-user-data-requests/; all retrieved September 23, 2026. ↑ Back
  103. United States v Heppner, No 25 Cr 503 (JSR) (SDNY February 17, 2026), Memorandum (Rakoff J), ECF No 27 at 1 and 3 to 12 (the ruling from the bench of February 10, 2026 is recorded at 1; the privilege holding is at 3 to 8 and the work-product holding at 8 to 12), court-filed copy, https://storage.courtlistener.com/recap/gov.uscourts.nysd.652138/gov.uscourts.nysd.652138.27.0.pdf, retrieved September 23, 2026. The filing is a scanned image; the quotations were checked against the page images. A foreign source, not binding in Canada. ↑ Back
  104. Warner v Gilbarco, Inc., No 2:24-cv-12333 (ED Mich February 10, 2026) (Patti MJ), ECF No 94 at 11 and 12, court-filed copy, https://storage.courtlistener.com/recap/gov.uscourts.mied.379552/gov.uscourts.mied.379552.94.0.pdf, retrieved September 23, 2026. A foreign source, not binding in Canada. ↑ Back
  105. Morgan v V2X, Inc., No 25-cv-01991-SKC-MDB (D Colo March 30, 2026) (Braswell MJ), ECF No 65 at 8 to 10, 14 and 15, court-filed copy, https://storage.courtlistener.com/recap/gov.uscourts.cod.245077/gov.uscourts.cod.245077.65.0_2.pdf, retrieved September 23, 2026. A foreign source, not binding in Canada. ↑ Back
  106. Assini v Hayward, 2026 NY Slip Op 26086 (Sup Ct, Nassau County, June 4, 2026), https://www.nycourts.gov/reporter/current/3dseries/2026/2026_26086.shtml; Tate Group Automotive, LLC v Legacy Automotive Capital, LLC, Cause No 25-BC11B-0020 (Tex Bus Ct, 11th Div, June 3, 2026), Court Minute Entry Regarding ChatGPT Materials In Camera Review, read from a copy of the filed entry hosted by a third party, https://websitedc.s3.amazonaws.com/documents/Tate_Group_v._LEgacy_USA_3_June_2026.pdf; both retrieved September 23, 2026. A foreign source, not binding in Canada. ↑ Back
  107. Morgan v V2X, Inc., No 25-cv-01991-SKC-MDB (D Colo March 30, 2026) (Braswell MJ), ECF No 65 at 14 and 15, court-filed copy, https://storage.courtlistener.com/recap/gov.uscourts.cod.245077/gov.uscourts.cod.245077.65.0_2.pdf; against Anthropic, "Commercial Terms of Service" (effective June 17, 2025), ss B, E.2 and E.4, https://www.anthropic.com/legal/commercial-terms; Anthropic, "Data Processing Addendum" (effective February 24, 2025), s H.1, https://www.anthropic.com/legal/data-processing-addendum; OpenAI, "OpenAI Services Agreement" (effective January 1, 2026), ss 4.2, 7 and 11.3, https://openai.com/policies/services-agreement/; OpenAI, "Enterprise privacy at OpenAI" (updated January 8, 2026), ChatGPT Business FAQ, https://openai.com/enterprise-privacy/; all retrieved September 23, 2026. A foreign source, not binding in Canada. ↑ Back
  108. Leroux v Proex Inc., 2022 ONSC 319 at para 21, setting out findings made in an earlier Ontario employer-email decision. ↑ Back
  109. Leroux v Proex Inc., 2022 ONSC 319 at paras 21, 32, 33 and 36, paragraph 21 setting out the findings made in an earlier Ontario employer-email decision. ↑ Back
  110. Anthropic, "Anthropic Government Requests Report" (July to December 2025), linked from anthropic.com/transparency/system-trust-reporting, https://www-cdn.anthropic.com/5d453bc3285b8e0c101b7193b5765419920cee24.pdf, retrieved September 23, 2026. ↑ Back
  111. Anthropic, "Commercial Terms of Service" (effective June 17, 2025), s M.3, https://www.anthropic.com/legal/commercial-terms; OpenAI, "OpenAI Services Agreement" (effective January 1, 2026), s 16.13, https://openai.com/policies/services-agreement/; both retrieved September 23, 2026. ↑ Back
  112. Anthropic, "Commercial Terms of Service" (effective June 17, 2025), ss J.2, L.3 and M.7, https://www.anthropic.com/legal/commercial-terms; OpenAI, "OpenAI Services Agreement" (effective January 1, 2026), ss 14.2, 15.1, 15.4 and 16.3, https://openai.com/policies/services-agreement/; Anthropic, "Data Processing Addendum" (effective February 24, 2025), s G.1, https://www.anthropic.com/legal/data-processing-addendum; OpenAI, "OpenAI Data Processing Addendum" (effective January 1, 2026), ss 2.7 and 6, https://openai.com/policies/data-processing-addendum/; all retrieved September 23, 2026. ↑ Back
  113. Law Society of Saskatchewan, "Guidelines for the Use of Generative Artificial Intelligence in the Practice of Law" (updated February 2024) at 4, https://www.lawsociety.sk.ca/wp-content/uploads/Law-Society-of-Saskatchewan-Generative-Artificial-Intelligence-Guidelines.pdf; Law Society of British Columbia, "Cloud computing checklist" (version 4.0, updated January 2023), introduction, https://www.lawsociety.bc.ca/Website/media/Shared/docs/practice/resources/checklist-cloud.pdf; Office of the Privacy Commissioner of Canada, "Guidelines for processing personal data across borders" (January 2009), https://www.priv.gc.ca/en/privacy-topics/airports-and-borders/gl_dab_090127/; all retrieved September 23, 2026. ↑ Back
  114. Claude Code documentation, "Data usage" (page modified September 15, 2026), https://code.claude.com/docs/en/data-usage; OpenAI Help Center, "Using Codex with your ChatGPT plan" (page showed "Updated: 4 hours ago"), https://help.openai.com/en/articles/11369540-using-codex-with-your-chatgpt-plan; both retrieved September 23, 2026. ↑ Back
  115. Claude Code documentation, "Legal and compliance" (page modified August 21, 2026), https://code.claude.com/docs/en/legal-and-compliance; OpenAI Help Center, "Using Codex with your ChatGPT plan", https://help.openai.com/en/articles/11369540-using-codex-with-your-chatgpt-plan; both retrieved September 23, 2026. ↑ Back
  116. Claude Code documentation, "Data usage" (page modified September 15, 2026), https://code.claude.com/docs/en/data-usage, retrieved September 23, 2026. ↑ Back
  117. Claude Code documentation, "Data usage" (page modified September 15, 2026), https://code.claude.com/docs/en/data-usage; Claude Code documentation, "Explore the .claude directory" (no date on the page), "Application data", https://code.claude.com/docs/en/claude-directory; OpenAI Codex documentation, "Configuration Reference" (no date on the page), https://learn.chatgpt.com/docs/config-file/config-reference, and "Authentication" (no date on the page), https://learn.chatgpt.com/docs/auth; all retrieved September 23, 2026. ↑ Back
  118. Claude Help Center, "Use Claude Code with your Pro or Max plan" (updated August 19, 2026), https://support.claude.com/en/articles/11145838-use-claude-code-with-your-pro-or-max-plan; Claude Code documentation, "Authentication" (no date on the page), "Authentication precedence" and "Anthropic profiles and federation credentials", https://code.claude.com/docs/en/authentication; OpenAI Codex documentation, "Authentication" (no date on the page), https://learn.chatgpt.com/docs/auth; all retrieved September 23, 2026. ↑ Back
  119. Claude Help Center, "Claude Code on the web" (updated March 16, 2026), https://support.claude.com/en/articles/12618689-claude-code-on-the-web; Claude Code documentation, "Use Claude Code in the cloud" (page modified September 22, 2026), https://code.claude.com/docs/en/claude-code-on-the-web; OpenAI Help Center, "Using Codex with your ChatGPT plan", https://help.openai.com/en/articles/11369540-using-codex-with-your-chatgpt-plan; OpenAI Help Center, "Data residency and inference residency for ChatGPT", https://help.openai.com/en/articles/9903489-data-residency-and-inference-residency-for-chatgpt; all retrieved September 23, 2026. ↑ Back
  120. Claude Code documentation, "Continue local sessions from any device with Remote Control" (no date on the page), "Connection and security", https://code.claude.com/docs/en/remote-control; Claude Code documentation, "Data usage" (page modified September 15, 2026), https://code.claude.com/docs/en/data-usage; Claude Code documentation, "Settings reference" (no date on the page), disableRemoteControl, https://code.claude.com/docs/en/settings-reference; all retrieved September 23, 2026. ↑ Back
  121. Microsoft Learn, "Codex with Azure OpenAI in Microsoft Foundry Models" (updated September 4, 2026), https://learn.microsoft.com/en-us/azure/foundry/openai/how-to/codex; OpenAI, "The Hugging Face incident and the road ahead" (August 26, 2026), https://openai.com/index/hugging-face-incident-and-the-road-ahead/; both retrieved September 23, 2026. ↑ Back
  122. Claude Code documentation, "Security" (page modified September 15, 2026), https://code.claude.com/docs/en/security; OpenAI, "Service terms" (updated September 21, 2026), s 7(b), https://openai.com/policies/service-terms/; both retrieved September 23, 2026. ↑ Back
  123. Claude Help Center, "Use Claude's chat search and memory to build on previous context" (updated September 15, 2026), https://support.claude.com/en/articles/11817273-use-claude-s-chat-search-and-memory-to-build-on-previous-context; OpenAI Help Center, "Data controls in ChatGPT", https://help.openai.com/en/articles/7730893-data-controls-faq; both retrieved September 23, 2026. ↑ Back
  124. Law Society of Ontario, "Building a generative AI policy: A checklist of key questions" (no date on the document), https://lawsocietyontario-dwd0dscmayfwh7bj.a01.azurefd.net/media/lso/media/lawyers/practice-supports-resources/building-a-generative-ai-policy-a-checklist-of-key-questions-en.pdf, retrieved September 23, 2026. ↑ Back
  125. Anthropic, "Consumer Terms of Service" (effective October 8, 2025), s 2, https://www.anthropic.com/legal/consumer-terms; OpenAI, "Terms of Use" (effective January 1, 2026), "Corporate domains", https://openai.com/policies/terms-of-use/; both retrieved September 23, 2026. ↑ Back
  126. Claude Help Center, "Manage user feedback settings on Team and Enterprise plans" (updated March 16, 2026), https://support.claude.com/en/articles/10504844-manage-user-feedback-settings-on-team-and-enterprise-plans; Anthropic Privacy Center, "Share and unshare chats" (updated June 15, 2026), https://privacy.claude.com/en/articles/10593882-share-and-unshare-chats; OpenAI Help Center, "Sharing conversations and scheduled tasks in ChatGPT" (page showed "Updated: 4 days ago"), https://help.openai.com/en/articles/7925741-chatgpt-shared-links-faq; OpenAI Help Center, "Memory FAQ (Business Version)" (page showed "Updated: 4 days ago"), https://help.openai.com/en/articles/9295112-memory-faq-business-version; all retrieved September 23, 2026. ↑ Back
  127. Leroux v Proex Inc., 2022 ONSC 319 at para 31. ↑ Back
  128. Lawyers' Professional Indemnity Company, "2026 Professional Liability Insurance for Lawyers and Related Insureds", Policy No 2026-001, Part III, exclusion (j), and Endorsement No 14, https://www.lawpro.ca/wp-content/uploads/2026/02/A3-Policy-Book-2026-rev-3-Feb-3.pdf; Saskatchewan Lawyers' Insurance Association Inc., "Current Policy" (member login required), https://slia.ca/current-policy/; both retrieved September 23, 2026. ↑ Back
  129. Claude Code documentation, "Authentication" (no date on the page), "Restrict login to your organization", https://code.claude.com/docs/en/authentication; OpenAI Codex documentation, "Authentication" (no date on the page), https://learn.chatgpt.com/docs/auth, and "Configuration Reference" (no date on the page), https://learn.chatgpt.com/docs/config-file/config-reference; all retrieved September 23, 2026. ↑ Back
  130. Claude Code documentation, "Data usage" (page modified September 15, 2026), https://code.claude.com/docs/en/data-usage; OpenAI Codex documentation, "Configuration Reference" (no date on the page), https://learn.chatgpt.com/docs/config-file/config-reference; both retrieved September 23, 2026. ↑ Back
  131. Office of the Privacy Commissioner of Canada, "Guidance on assessing third-party service providers" (date modified September 10, 2026; open for comment until December 4, 2026), https://www.priv.gc.ca/en/privacy-topics/privacy-for-businesses/appropriate-handling-of-personal-information/gd_third-party_202609/, retrieved September 23, 2026. ↑ Back
  132. Amazon Web Services, "Amazon Bedrock FAQs" (no date stated), https://aws.amazon.com/bedrock/faqs/; Amazon Web Services, "Amazon Bedrock abuse detection" (no date stated), https://docs.aws.amazon.com/bedrock/latest/userguide/abuse-detection.html; both retrieved September 23, 2026. ↑ Back
  133. Amazon Web Services, "Claude Opus 5.5" model card (no date stated), https://docs.aws.amazon.com/bedrock/latest/userguide/model-card-anthropic-claude-opus-5-5.html; Amazon Web Services, "Regional availability by models" (no date stated), https://docs.aws.amazon.com/bedrock/latest/userguide/models-region-compatibility.html; both retrieved September 23, 2026. ↑ Back
  134. Claude Code documentation, "Claude Code on Amazon Bedrock" (page modified September 22, 2026), https://code.claude.com/docs/en/amazon-bedrock, retrieved September 23, 2026. ↑ Back
  135. Google Cloud, "Deployments and endpoints" (last updated September 22, 2026), https://docs.cloud.google.com/gemini-enterprise-agent-platform/resources/locations, retrieved September 23, 2026. ↑ Back
  136. Microsoft Learn, "Region availability for Foundry Models sold by Azure" (updated September 4, 2026), https://learn.microsoft.com/en-us/azure/foundry/foundry-models/concepts/models-sold-directly-by-azure-region-availability; "Data, privacy, and security for Foundry Models sold by Azure in Microsoft Foundry" (updated June 5, 2026), https://learn.microsoft.com/en-us/azure/foundry/responsible-ai/openai/data-privacy; "Foundry Models sold by Azure abuse monitoring" (updated June 5, 2026), https://learn.microsoft.com/en-us/azure/foundry/openai/concepts/abuse-monitoring; "Codex with Azure OpenAI in Microsoft Foundry Models" (updated September 4, 2026), https://learn.microsoft.com/en-us/azure/foundry/openai/how-to/codex; all retrieved September 23, 2026. ↑ Back
  137. WarmLoop, Privacy Policy (version of September 23, 2026), s 12; WarmLoop, Terms of Service (version of September 23, 2026), cl 10.8. ↑ Back
  138. WarmLoop, Terms of Service (version of September 23, 2026), cll 20.1, 20.2 and 20.5. ↑ Back
  139. WarmLoop, Privacy Policy (version of September 23, 2026), ss 3, 4, 5, 6, 11, 13 and 14; WarmLoop, Terms of Service (version of September 23, 2026), cll 3.2, 3.6, 10.3, 10.5, 10.6 and 10.7. ↑ Back
  140. WarmLoop, Privacy Policy (version of September 23, 2026), "In brief" and ss 4, 5 and 14; WarmLoop, Terms of Service (version of September 23, 2026), cll 3.9 and 10.4. ↑ Back
  141. WarmLoop, Privacy Policy (version of September 23, 2026), ss 4 and 11; WarmLoop, Terms of Service (version of September 23, 2026), cl 10.7; WarmLoop home page, Security and Canadian hosting. ↑ Back
  142. WarmLoop, Terms of Service (version of September 23, 2026), cll 1.5, 3.9, 6.1, 10.10 and 18.5; WarmLoop, Privacy Policy (version of September 23, 2026), s 17. ↑ Back
  143. WarmLoop, Terms of Service (version of September 23, 2026), cll 14.1, 16.4, 16.5, 16.7, 16.8, 23.1, 23.4, 23.8, 23.11 and 24.1. ↑ Back
  144. WarmLoop, Terms of Service (version of September 23, 2026), cl 2.4, including its paragraphs on later setup runs and on withdrawing that agreement; WarmLoop, Privacy Policy (version of September 23, 2026), s 12. ↑ Back
  145. WarmLoop home page, warmloop.com; WarmLoop, Terms of Service (version of September 23, 2026), cl 8.3. ↑ Back
  146. WarmLoop home page, warmloop.com, which adds that "you upload documents only when you choose to publish a record". ↑ Back
  147. WarmLoop, Terms of Service (version of September 23, 2026), cl 7.3, final paragraph. ↑ Back
Early access

Put a verifier in your corner.

Early access is an account for one named user, connected to the assistant you already use and set up with you on a call. WarmLoop enables each one by hand during the pilot, for law firms, lawyers, in-house legal departments, businesses and government bodies located in Canada outside Quebec. Tell us what you litigate and where, and we'll take it from there.