“Download my Claude Skills please.”
That sentence has started to make me want to walk into the sea.
I sound mad. If you felt called out by that, you should be madder. Not at me. At the shape of the deal you’re in.
Shorter cut went on the feed last week. This is the long version. The one with the documents.
Same week, someone was giving away a thick SEO playbook with a library of Claude Skill files. Daily ops. Enterprise Shopify. Teach the workflow, move up the value chain. Respectable people in the thread. I know the author briefly.
I still said the bore-at-a-party thing: I hope you’re on enterprise with a real ZDR agreement and a runtime that isn’t the consumer one. I doubt it.
Max-tier compute is subsidised hard. People have already run the numbers. SemiAnalysis drained every Anthropic and OpenAI tier until the weekly limits died, then priced the tokens at API list rates. Claude Max 20x at US$200/month (about A$285) came out around US$8,000 a month in equivalent usage (about A$11,400). Roughly forty times the sticker. A separate write-up put a full Max 5x week near US$500 (about A$710) against about US$25 of subscription (Saers).
You’re not buying compute. You’re buying a discounted bucket with a privacy switch on the side.
Unchecking Help Improve Claude only reaches language about training the next model. Not the thing that runs the work.
The reply, verbatim:
k but do you want the playbook or not?
I did not, in fact, want the playbook. I wanted fewer people teaching their client procedures to a product that bills them for the privilege.
But if I ever do want it, I’ll wait a quarter. If it’s any good, it’ll be baked into the product for free.
I don’t think it will be.
Couple of mates asked me to look under their “AI stacks” around the same time. Both run agencies. Mates rates. Informal. Quick suss.
There was nothing under the hood.
A couple of Claude Max seats. Some Skills. Some SOPs. Emoji energy. I’m not roasting them here. I roasted them in person. We laughed. Gravity without levity is just heavy. Levity without gravity is fucking stupid.
This is fucking stupid:
“Do not train future models on my data.”
You untick Help Improve Claude and feel clever. Your precious SOPs, your client procedures, your operating playbook, safely walled off from the training pipeline. Congrats. You’ve locked the front door and left the garage open.
That part can be true. The help text says OFF stops future model training.
Yeah nahhhhhh if you thought that was the whole deal.
The toggle covers training. It doesn’t cover the harness: the runtime that assembles context, dispatches tools, recovers from failure, and decides what the model is allowed to do.
The Privacy Policy still lists Inputs and Outputs under improve/research excluding model training. Same root word, “improve.” Different scope. That is the shape of the deal. You don’t need a warehouse tour to read a contract.
Model is bread. The runtime is the hook. You’re the fish saying sick, I love this, imma get that bread. Then you notice the line. Later you’re dinner. If you’re “moving up the value chain by teaching,” congratulations: you invited your mates to the same boat. Group platter.
I don’t think Anthropic primarily needs your chats to make Claude smarter as a model. They’ll get there. What the strategy essays actually want is workflow: how you structure tasks, chain prompts, wire tools, and run SOPs through a human-shaped intelligence layer.
You don’t ship Claude Code, then Cowork, then Design, then a surface that wires every MCP under the sun, and explain that ladder with latency graphs alone. The shipping story is inference on top of the shape. The shape doesn’t wait on it.
All you’ve got on the consumer seat is a feeding tube you pay for twice. Subscription money out. Session content in under a purpose the public switch doesn’t gate. That’s the issue.
Not a privacy lecture for its own sake. The playbook is glucose with a nice cover. The edge is moving to that runtime. That’s what eats real work and ships the average back. And that’s what the public privacy fight mostly failed to name.
I’ve written about this shape before without the vendor nouns: context window, faster buckets, perimeter. Frontier models are compute. Useful. Not the grey matter.
So I did the boring thing. I went looking for what that control actually does when you turn it off.
Not the vibe. The documents. On 2 August 2026 the live claude.ai settings URL was Cloudflare-blocked during verification, which is the sort of cosmic joke you get when you’re trying to screenshot a privacy control. Label and OFF wording below come from Anthropic’s Privacy Center how-to. The Privacy Policy came from the live legal page.
The fight was about weights. The moat moved.
For two years the fight over AI data was mostly about model training. Opt-outs. Consumer toggles. “We don’t train on your data” procurement language. Fair fight. Necessary fight. Wrong noun if you care about where advantage actually compounds.
Frontier weights are getting closer. On Together’s DeepSWE numbers, Claude Fable 5 and Kimi K3 sit roughly a point apart, and the open-weight side is a lot cheaper per rollout (Together.ai). If the model is no longer the whole product, the durable advantage sits in how the work is run.
That’s not my hot take. LangChain published a Terminal Bench jump from 52.8% to 66.5% with the model held fixed (LangChain). Others say the quiet part out loud: the runtime is the dataset; advantage is in captured trajectories (Schmid; Liu et al.).
I wrote about a quieter version of this years ago. Regression to the mean: when everyone copies the same “best practice,” you engineer a slow trip to the middle. The middle is failure with better branding.
A runtime that eats real work and ships the average back is the same mechanism, automated. Your weird edge cases, late failures, and taste become signal for something that makes everyone else’s agent a little more like everyone else’s agent. Industrialised mediocrity with a changelog.
That’s not a warehouse claim. It’s the issue. If the durable asset is trajectories, and the public switch only clearly gates model training, then the thing that averages the field may still be open under a different word for “improve.”
What none of the strategy pieces do: treat that collection as a consent question. They treat it as something to admire. Lovely.
The switch that doesn’t reach it
Anthropic’s consumer Privacy Policy §10 splits “improve the Services and conduct research” into two purposes (live Privacy Policy, re-fetched 2 August 2026):
| Purpose (verbatim) | Includes Inputs and Outputs? | Legal bases listed |
|---|---|---|
| To improve the Services and conduct research (excluding model training) | Yes | Scientific Research; Legitimate interests |
| To improve the Services and conduct research (including model training) | Yes | Scientific Research; Consent; Legitimate interests |
Now the settings language, from Anthropic’s own Privacy Center how-to (model improvement privacy settings, dated 16 March 2026):
The control is labelled Help Improve Claude.
Turning it off means Anthropic won’t use new chats and coding sessions for future model training. Same story in the retention article and the Consumer Terms update (28 August 2025).
Read those two surfaces together.
The toggle clearly stops future model training. The Privacy Policy still lists Inputs and Outputs under improve/research excluding model training. Those aren’t the same sentence.
That’s the verified disclosure finding. The excluding-training purpose is the one that can sit next to product and runtime improvement. The fight named weights. The documents still leave room for the loop that actually compounds.
“Improve” on the settings screen means something narrower than “improve” in the policy. Same word. Different job. You don’t need a warehouse leak. You need a browser and the will to be boring.
What that establishes: Inputs and Outputs sit on the excluding-training improve/research purpose. Every OFF description I retrieved is about future model training. Nothing I retrieved points the consumer toggle at the excluding-training purpose.
What it doesn’t establish: that Anthropic is stuffing opted-out Free/Pro/Max chats into a product-research corpus. Permission isn’t practice. I’m not claiming I audited their warehouses.
The shape of what is assumable under those documents:
Briefing model, not a warehouse map. Gold thread: session content can sit under improve/research excluding training, then feed runtime iteration. The toggle gates training. Feedback can reopen training for a rated chat. Average is the regression risk if that loop runs at field scale. Assumable under documents, not audited practice.
Where processing rests on legitimate interests, GDPR Article 21 still gives a right to object. Anthropic’s policy mentions that. The product doesn’t surface a control for the excluding-training row the way it surfaces Help Improve Claude. I’m in Australia; Article 21 isn’t my lever. The structural point still stands: training got a switch; the adjacent purpose got a help-centre sentence.
Feedback can reopen training. Still not the main issue.
Thumbs up/down can store the related conversation for up to five years and may be used to train models (training, retention). Policy §2 says even after opt-out, Inputs and Outputs are used for model improvement when you’ve “explicitly reported the materials to us.” Disclosure lives in a help article, not next to the thumb. The most expensive like button in SaaS. Still not the runtime question.
What not to claim
Don’t turn this into “they’re secretly reading your code through telemetry.” Claude Code’s diagnostic docs defeat that strong version: metrics and error reports, not code/prompts/paths; OpenTelemetry goes to a collector you configure (data usage, monitoring). Explicit paths send transcripts if you choose. None of that rewrites §10.
Inference still sends Inputs and Outputs under the Privacy Policy. The issue is whether the improve/research purpose that still lists those can feed the loop the strategy literature treats as the durable asset, while the only clear consumer switch gates training.
Why the mismatch matters
This next part isn’t a Tier-1 finding. It’s inference I’m willing to own. Same thesis as the feeding tube: you don’t build that product ladder unless absorbing how people work is part of how you ship.
Anthropic has shipped Claude Code (preview Feb 2025, GA May 2025), Claude Cowork (Jan 2026), and Claude Design (Apr 2026) at a pace that is hard to explain with latency graphs alone. Latency graphs do not, historically, invent three product surfaces by themselves.
People run messy jobs. Benchmarks miss the failure modes. Someone has to see those shapes to fix them. Contentful sessions. Rated chats. Support. Ship. Repeat.
Sending Inputs for inference is the service. That proves nothing about retention or secondary use. The consent question is what happens after the turn.
A careful reader will name three loops that needn’t touch an opted-out consumer chat: internal dogfood, commercial/enterprise corpora, and the Development Partner Program on the including-training side of §10. Those channels are real. They may be large. They don’t dissolve the consumer question: what Free/Pro/Max authorises under the excluding-training improve/research row, and what the toggle does and doesn’t gate.
If Anthropic publishes named exclusive channels for product research, this inference weakens. Good. Publish them. The §10 mismatch still stands on its own quotes.
I checked the instruments people wave around. None treat vendor collection of agentic operational telemetry as distinct from training data. EDPB, FTC, OAIC: still mostly about the bread. The hook is in another room.
What would change my mind
- Anthropic publishes what its product-research corpus draws from, and opted-out consumer Inputs/Outputs are excluded.
- Or DPP / commercial / dogfood are shown as the designated, sufficient channels for that iteration.
- Or the live Privacy Policy removes the two-branch §10 structure I verified on 2 August 2026.
- Or the settings label and help text are rewritten so “improve” on the screen matches “improve” in the policy, and users get an equivalent control for the excluding-training purpose.
Until then: the issue is the runtime. The verified wrong is that the public switch doesn’t clearly reach the purpose that can sit next to that improvement loop. Permission isn’t practice. Practice is what a written answer would settle.
My conflict
I own my intelligence layer. Frontier models are cheap compute underneath it, used under guardrails, not as the system of record.
A large share of the first research pass was still produced by models made by companies under examination. That cuts both ways: incentive to be soft, incentive to be theatrical. So I re-fetched the Anthropic pages that decide the argument, kept the docs that defeat the strong telemetry claim, and labelled the shipping ladder as inference.
If that sounds like a man arguing with the kitchen while cooking in it, yes.
Disclosure, one sentence:
The toggle clearly stops future model training. The Privacy Policy still lists Inputs and Outputs under improve/research excluding model training. Those aren’t the same sentence.
Issue: the runtime. Know what you’re renting. Know whether the switch reaches the loop that compounds.
Sources
There’s a longer unpublished verification brief behind this essay. It isn’t public yet. The links below are what I’m hanging the public argument on.
Subsidy math (API list-price equivalents at full use, not Anthropic’s COGS). Sticker prices are USD on claude.com/pricing (Max from US$100; Max 20x US$200; tax not included). AUD at ~1.42 mid-market USD/AUD, early Aug 2026:
- SemiAnalysis subscription drain test, June 2026 (coverage; @semianalysis_): Max 20x ~US$8,000/month equivalent (~A$11,400)
- Niklas Saers on Max weekly API value (Max 5x week ~US$523 / ~A$740)
Pages that decide the disclosure finding:
- Consumer Privacy Policy (§2, §6, §10)
- How do I change my model improvement privacy settings?
- How long do you store my data?
- Is my data used for model training?
- Updates to our Consumer Terms (28 August 2025)
- Claude Code data usage and monitoring
Related here: The Context Window, Insulation from Faster Buckets, The Physics of Agency, Regression to the Mean. Architecture of owning the layer: The Cognitive Loop.
If I publish the longer brief, the citation tiers and falsifiers go with it. Until then, this is the argument.