Vendors

  • Replit (with Replit AI)

    Replit is the highest-risk AI development environment in this database, but the risk is fundamentally different in kind from the other consumer AI tools. The issue isn’t training defaults or breach history of the platform itself — it’s that Replit’s agentic AI was, in July 2025, demonstrated to autonomously delete a production database belonging to…

  • Cursor (Anysphere)

    Cursor is the most widely-adopted AI code editor in 2026 and has a structurally different risk profile from GitHub Copilot. Two distinguishing facts: (1) Cursor’s Privacy Mode genuinely enforces Zero Data Retention with model providers (your code is not stored on Cursor’s servers and is not used for training), but Privacy Mode is opt-in on…

  • Perplexity

    Consumer Perplexity sits at 4 of 5 — higher than the other consumer-tier AI products in this database. Two reasons: training-on-by-default like the rest, AND a pending class-action lawsuit filed April 1, 2026 alleging that hidden trackers transmit full user conversation transcripts to Meta and Google even when users enable Perplexity’s “Incognito” mode. The lawsuit…

  • Claude (Anthropic)

    Mid-range risk — same numerical rating as ChatGPT. Anthropic positions itself as the safety-forward AI lab, and the marketing materials emphasise that point, but the consumer-tier defaults changed in August-September 2025 to match the industry pattern: training is now on by default for Free, Pro, and Max users unless they actively opt out, with a…

  • ChatGPT (OpenAI)

    Mid-range risk. ChatGPT’s free and Plus tiers train on your inputs by default unless you actively opt out. The business tiers (Business, Enterprise) contractually exclude training, but most SMB owners use the consumer tiers without changing the default settings. The Samsung incident (April 2023, three separate leaks of semiconductor IP in 20 days) and the…