Skip to main content
Claude Science is client-side software that your organization installs and runs on computers it controls, and Anthropic provides the Claude models the app calls. This page covers what that means for your research data.

Model training and ownership of your work

On Team and Enterprise plans the Commercial Terms of Service apply. Under them Anthropic “may not train models on Customer Content from Services,” and, as between the parties and to the extent permitted by applicable law, your organization “retains all rights to its Inputs” and “owns its Outputs,” including the analyses, code, and results your researchers produce with Claude Science. Anthropic may use content to improve its models only when a member gives express consent, by providing feedback, which includes a copy of that conversation, or when your organization otherwise expressly chooses to allow it (see Is my data used for model training?). To turn off the ability for your researchers to provide feedback, an Owner can turn off the Rate chats toggle under Organization settings > Data and privacy. On Pro and Max plans the Consumer Terms of Service, Anthropic Privacy Policy, and your Claude privacy settings in the Settings panel apply (see Legal and compliance).

Where Claude Science data lives

Sign-in tokens and the credentials members store for compute and cloud storage are encrypted on the computer, and the rest of the local folder relies on operating-system permissions, so apply your full-disk encryption and device management policies to it.

What Anthropic receives

The app sends the following to Anthropic, over TLS and signed in with the member’s Claude account (see Network requirements for the domains):
  • Requests to Claude every time Claude responds, carrying the conversation so far, including the member’s prompts, the contents of files Claude has read (PDFs included), code and command output, connector results, images Claude is shown, and recalled memory facts. Anthropic keeps these as model-call logs (see What Anthropic keeps and for how long).
  • Web search queries, run by Anthropic’s web search service through a third-party search provider listed among Anthropic’s subprocessors.
  • Dictation audio, streamed to Anthropic’s speech-to-text service only while a member dictates. If the app can’t use that service while Claude Science is open in a browser such as Chrome or Edge, it falls back to the browser’s built-in speech recognition, and that browser’s vendor then processes the audio.
  • Feedback, only when a member sends it, consisting of the rating, the comment, and a copy of that conversation (members are reminded before submission) with known credential formats and email addresses redacted. Not accepted from organizations with HIPAA compliance or customer-managed encryption keys.
  • Custom skills a member publishes, stored with the member’s claude.ai skills.
  • Usage telemetry and error reports, which carry app, device, and timing data, plus account and organization identifiers on telemetry events, but no conversation content, file contents, or file names (see Telemetry for the device setting that turns them, and feedback, off).
  • Calls to connectors Anthropic hosts from your claude.ai connector directory, which pass through Anthropic’s connector service as in claude.ai, plus routine account, settings, and update traffic.

What Anthropic keeps and for how long

For Team and Enterprise organizations, Anthropic processes this data under the Data Processing Addendum, encrypted at rest and in transit. Model-call logs follow Anthropic’s commercial data retention policy, including its longer retention for content flagged by automated trust and safety systems or required by law. Requests to models designated Covered Models are retained for 30 days to support Anthropic’s safety work, as Data retention practices for Covered Models describes. Feedback submissions are kept under the feedback terms in the same policy.

Who at Anthropic can access retained content

Human review of model-call logs, published skills, or Compliance API transcripts requires a specific reason, such as reviewing content that automated safety systems flagged, responding to a security incident, or meeting a legal obligation, through a controlled path where access is restricted to personnel whose role requires it and logged as the Data Processing Addendum describes, and content reviewed this way isn’t used to train Claude models. Feedback a member chooses to send is handled separately, as Model training and ownership of your work describes. Access Transparency records don’t cover the Claude apps, including Claude Science.

Controls available to your organization

  • Organization settings for connectors, skills, the sandbox network allowlist, SSH hosts, Modal, model endpoints, memory, and access to previously saved Claude Science work (see Admin controls). There is no organization setting for web search, dictation, or telemetry.
  • US-only inference (usage-based Enterprise plans) runs model inference for Claude Science requests in the United States, as for your other Claude apps (see Enable US-only inference).
  • Device configuration turns off telemetry, error reports, and feedback and relocates the local data folder (see Manage Claude Science on devices).
  • Running Claude Science next to your data, on a Linux server or virtual machine you control, keeps datasets on your infrastructure, apart from what Claude reads into the conversation, while Claude’s inference runs on Anthropic’s service (see Run on a remote Linux server).
  • Usage analytics show adoption and session metrics without conversation content (see Monitor usage).

Compliance API coverage

On Enterprise plans with the Compliance API enabled, your organization gets a record of Claude Science settings changes and its own read-only transcripts of members’ Claude Science sessions (coverage is in beta), which are kept for your organization’s own retention period (6 years by default) and, in organizations that use customer-managed encryption keys, encrypted under your key. Retrieve session transcripts describes what a transcript contains and which sessions aren’t captured, including those in organizations with HIPAA compliance enabled.

Customer-managed encryption keys

Organizations that use customer-managed encryption keys (CMEK) can turn on Claude Science. The content Anthropic stores from the app is encrypted under your key, including the model-call logs of members’ conversations with Claude, skills members publish, and, for Enterprise organizations with the Compliance API enabled, session transcripts. The app’s conversation history, files, artifacts, and memory are stored on the member’s computer and aren’t hosted by Anthropic; of these, only what the app sends to Claude reaches Anthropic, where your key covers it as this section describes. Work members send to their own SSH hosts, Modal account, or scientific model endpoints goes directly there, not through Anthropic, and isn’t under your key or any Anthropic-managed key, so review those providers’ data handling. You can turn these connections off under Organization settings > Claude Science. In organizations with CMEK enabled, the app hides its response rating buttons and feedback form, as claude.ai does.

What isn’t available for Claude Science

Zero data retention (a Claude Code zero-data-retention arrangement covers Claude Code sessions, not Claude Science), Enterprise Frontier Safeguards, coverage under Anthropic’s Business Associate Agreement (keep protected health information out of Claude Science), and inference through a third-party cloud platform or your own cloud tenancy aren’t available for Claude Science. See Admin controls for how the other claude.ai admin settings apply to the app. Commercial Terms of Service, Data Processing Addendum, subprocessor list, Usage Policy, the Anthropic Trust Center for certifications and security documentation, and Admin controls.