The short version: which Grok account your team uses decides what happens to what they type into it. On consumer accounts, xAI's privacy policy says conversations may be used to train and improve its models by default. On Grok Business and Grok Enterprise, xAI states that customer data is not used for model training. If people at your company are pasting client notes, pricing, or source code into a personal Grok login, that difference is the whole risk.
Start with which account people are actually using
Before changing any setting, find out how Grok is being used. Some people reach it through their personal X account, some through a free or paid individual plan, and some through a company-managed workspace. Each path is governed by different terms. A quick, non-punitive survey ("where do you use Grok, and for what?") usually surfaces more than a policy memo does, and it tells you which of the steps below matter most.
Check the training setting on personal accounts
On consumer accounts, training on your interactions is on unless someone turns it off. In X's settings, under Grok, there is a checkbox that allows posts and interactions, inputs and results with Grok to be used for training and fine-tuning. Unchecking it stops future use. Reporting on the setting is consistent that it is not retroactive: anything already collected and used for training cannot be pulled back out of a model. That is a reason to make the change now rather than after the next incident, and a reason to treat anything already pasted into a personal account as having left your control.
Move company work to a business plan
xAI's Grok Business and Grok Enterprise plans are the intended home for work data. xAI describes them as excluding customer data from model training, encrypting data in transit and at rest, and giving administrators controls through the xAI console: inviting users, managing access, and monitoring usage. Enterprise adds features such as single sign-on, SCIM directory sync, custom roles, and audit controls, and xAI has announced an isolated "Enterprise Vault" add-on for organizations with stricter needs. Read the current plan terms and data processing addendum yourself before you rely on any of this, since plan details change and the contract, not a summary, is what binds the vendor.
Decide what never goes in, on any plan
A business plan reduces the risk; it does not remove the need for judgment. A short rule set is easier to follow than a long policy:
- Never paste: passwords, API keys, customer personal data, health or financial records, and anything under an NDA or regulatory obligation.
- Redact first: replace client names, account numbers, and internal project names with placeholders before asking for help with a document.
- Paste the minimum: the three relevant paragraphs, not the whole contract or export.
- Check the output before it leaves: AI-drafted text can repeat details you supplied, so review anything client-facing the way you would review a human draft.
Control access and keep a record
Use single sign-on where the plan offers it so that offboarding a person removes their access the same day, and give people the smallest role that lets them do their job. Keep an inventory of who has access to which workspace, and review it on a schedule. If you connect Grok to other tools or to an API, treat the keys like any other credential: store them in a secrets manager, never in a shared document or chat, and rotate them when someone leaves.
Write it down and revisit it
One page is enough: which accounts are approved, what may never be entered, who to ask, and what to do if something sensitive was pasted by mistake. Add a date and a named owner, then review it quarterly. Vendors change their terms and their products often, and a policy that was accurate at launch drifts without someone responsible for it. The same discipline applies to any AI tool your team adopts, not only this one.