Studio Matrx Monthly · Volume 1 · Issue 4 · September 2026
Amogh N P
 In loving memory of Amogh N P — Architect · Designer · Visionary 
Client Confidentiality & DataLesson 10.1
Claude for Architects & Designers/Module 10 · Ethics, IP, Risk & the Road Ahead

Lesson 10.1 · Ethics, IP, Risk & the Road Ahead

Client Confidentiality & Data

Before Claude sees a single brief, decide what it is allowed to see - because the moment you paste, you have made a confidentiality decision on your client's behalf.

13 min Interactive lessonFree · open lessonByAmogh N P· Architect & interior designer
The hook

The fastest way to breach a client's confidence is to paste their life into a chat window without thinking.

Every earlier module assumed you could safely put your work in front of Claude. This one checks that assumption, because it is the assumption most quietly broken in a busy office. The instant you paste a client's brief, a site address, a floor plan or a fee figure into an online tool, you have decided something about someone else's confidential information - and you decided it for them. Designers hold unusually intimate material: home layouts that reveal how a family lives and sleeps, security and access details, financial ceilings, medical needs, unbuilt ideas a competitor would pay for, and the plain fact of who is building what and where.

None of this is a reason to avoid Claude. It is a reason to use it deliberately. The good news is that the discipline is small and learnable: understand how your plan treats your data, strip what does not need to travel, and know the short list of things that should never leave your own systems. Get those three habits right and Claude becomes a safe, everyday instrument. This lesson frames all of it conservatively - your professional duty of confidentiality and your client's NDA sit above any tool's settings, and where the law bites you defer to a lawyer, not to a chatbot.

If pasting it would embarrass you with the client watching, that's your answer.

Why client data is the first thing to get right

Confidentiality is not a courtesy in a design practice; it is a professional obligation, usually written into your appointment and often reinforced by a separate non-disclosure agreement. Councils and institutes worldwide treat a member's discretion about client affairs as a bedrock of the relationship, and a client who feels exposed rarely comes back and often tells others. So the first question about Claude is not "is it clever enough?" but "what am I allowed to show it, and on whose authority?"

Think concretely about what actually passes through your hands. A residential brief can contain a family's names, their address, their income band, when the house sits empty, where the safe room is, and a child's disability. A commercial job can contain unannounced expansion plans, lease terms, or a retailer's floor efficiency. Interior work carries client budgets, supplier discounts, and the private taste of people who value their privacy precisely because they can afford to. Much of this is exactly the context that makes Claude useful - and exactly the context a client never consented to see routed through a third party.

The correct instinct is to separate the *design problem* from the *client's identity*. Claude almost never needs to know that it is the Mehta family on a particular plot; it needs to know that it is a family of five on an urban infill site with a tight budget and a security concern. You can nearly always get the help without exposing the person. The rest of this lesson is a practical method for doing that reliably, plus an honest account of how your plan treats what you do send - because settings, not good intentions, are what actually protect the data.

One framing to carry throughout: treat every paste as if it might one day be read by someone you did not choose. That is not paranoia; it is the ordinary standard of care you already apply to a client's drawings on a shared drive or an email chain. Claude is simply another place that standard has to reach.

THE PASTE DECISIONConfidential, personal,or under an NDA?NOSafe to use - butstill verify the outputYESDo not paste it raw -go down the ladderTHE LADDER1 Strip names, address, budget, security2 Move to Business / Enterprise / API3 Still sensitive? Keep it out; do by handYour NDA and professional duty sit ABOVE every tool setting.
Zoom
The paste decision as a simple gate: if the content is confidential, personal or under an NDA, you do not paste it raw - you go down the ladder (anonymise, then a properly-termed plan) and, if it is still too sensitive, keep it out and do that part by hand. Your NDA and professional duty sit above every setting.

Claude needs the design problem, not the client's name. Separate the two, every time.

The one thing that changes everything: your plan's data settings

How your data is treated depends heavily on which Claude you are using, and this is the single most important fact in the lesson. As of 2026 - and this is the kind of detail that changes, so verify it against Anthropic's current terms and your own account settings - the picture is roughly this. On consumer plans (the free tier and personal paid tiers), your conversations *may be used to help improve Claude unless you opt out*, and retention settings apply. That means the default posture on a personal account is not the right home for confidential client work until you have checked the settings and turned training off where the option exists.

Business plans (Team and Enterprise) and the API are different: usage there is generally *not used to train models by default* and comes with stronger data controls, administration and retention terms. This is why the honest recommendation for any studio doing real client work is to move that work onto a business plan or API-backed tool, rather than relying on individuals to remember to flip a switch. The difference is not about how clever the model is - it is the same Claude - it is entirely about the contract that governs your data.

Three rules follow, and they hold regardless of plan. First, check your current privacy and data-retention settings yourself; do not assume a default. Second, strip or anonymise client identifiers whenever you can - the less that travels, the less any setting has to protect. Third, when in doubt, keep it out: if a piece of information would embarrass you in front of the client were they watching you paste it, that is your answer. And remember the layer above all settings - your client's NDA and your professional duty. A tool being configured well does not override a promise you made to a client; where the two might conflict, a lawyer decides, not a checkbox. None of this is legal advice; it is a working discipline built on top of terms you must read for yourself.

Consumer = check settings + opt out. Business/Enterprise/API = stronger terms, the right home for client work.

Anonymise, redact, and the paste test

Anonymising sounds tedious; done as a habit it takes seconds and costs you nothing in usefulness. The move is to replace identity with description. "The Sharma family at Plot 42, Koramangala, budget 1.8 crore, safe room behind the master wardrobe" becomes "a family of four on an urban infill plot of about 230 square metres, upper-middle budget, wanting a secure store off the master suite." Claude gives you the same programme logic, the same spec drafting, the same option comparison - it never needed the surname, the pin code, or the exact figure to help you think.

A quick, repeatable checklist before you paste anything client-related:

text
Before you paste, remove or replace:
- Names (client, family members, staff)
- Exact address, plot number, GPS, project code
- Precise budget figures (use a band: "upper-mid")
- Security details (alarm, safe room, access, cameras)
- Anything explicitly marked confidential or under NDA
- Personal/medical details tied to a named person
Keep: the design problem, sizes, climate, constraints,
the question you actually need answered.

For drawings and PDFs the same logic applies: crop out the title block, the client name, the site plan with the address, before you upload. Claude reads what is on the sheet, so what is on the sheet is what you have disclosed.

When a task genuinely needs the raw, identifiable material - and some do, such as drafting a letter that names the client - that is the signal to be on a business or API-backed setup with terms you have checked, not on a personal free account. The decision path in the figure captures it: if the content is confidential, personal or under NDA, you do not paste it raw; you go down the ladder - anonymise, then move to a properly-termed plan, and if it is still too sensitive, keep it out and do that part by hand. This is not a counsel of fear. It is the same judgement you already exercise about who gets copied on an email; you are simply extending it to a new and very capable recipient.

ANONYMISE BEFORE YOU PASTERAW - reveals the clientSharma family, Plot 42,Koramangala; budgetRs 1.8 crore; safe roombehind master wardrobeDo not paste this.ANONYMISED - same valueA family of four on anurban infill plot, approx230 sq m; upper-midbudget; a secure storeoff the master suiteSafe - and just as useful.Claude needs the design problem, not the person. Keep sizes, climate, constraints;drop names, address, exact figures and security detail.
Zoom
Anonymising costs seconds and loses nothing. Replace identity with description: the surname, plot number, exact figure and security detail become a family of four, an urban infill plot, an upper-mid budget, a secure store. Claude solves the same design problem without ever holding your client's identity.

A one-page studio data policy

Individual good intentions do not scale; a written rule does. The most useful thing you can do after this lesson is spend twenty minutes writing your studio's one-page Claude data policy, so that a new junior on their first day knows what is allowed without having to ask. It does not need to be legalistic - it needs to be clear enough to follow when you are tired at 7 pm.

A workable policy names four things. Where client work happens: on the studio's business/Enterprise account or approved API tools, never on personal free accounts, with training turned off and settings verified. What is never pasted, even anonymised: the specific items your clients and NDAs forbid - name them. How to anonymise: the replace-identity-with-description habit, with the checklist pinned somewhere visible. And who to ask when a case is unclear - a named person, so uncertainty resolves upward rather than into a risky guess.

Two further honesty notes belong in any such policy. First, connectors and web features vary by plan and can widen what is exposed; treat any integration that reaches into your drives or the web as a decision to review, not a default to accept. Second, the policy is a living document - Claude's terms and features change, so put a review date on it and check it against Anthropic's current privacy terms periodically, exactly as this course puts a last-verified date on its own facts.

The reward for this small discipline is large: you get to use Claude across confidential work with a clear conscience and a defensible position, because you can say precisely what you did and why. Confidentiality handled well is invisible - no one notices it working. It is only ever noticed when it fails, and by then the trust it protected is already gone. Build the habit now, while the stakes of a slip are still hypothetical, and it will simply be how your studio works.

Write the one-pager: where, what-never, how-to-anonymise, who-to-ask. Pin it up. Review it.

Settings & terms you'll meet in this lesson

Consumer plan data settings

Free and personal paid tiers - training and retention controls

As of 2026, conversations may be used to improve Claude unless you opt out. Check and set this yourself; defaults change, so verify against current terms.

Business / Enterprise / API

Team accounts and programmatic use - stronger data terms and admin controls

Generally not used to train models by default. The right home for confidential client work - same Claude, better contract.

Anonymisation

Replacing client identity with neutral description before you paste

Keeps the design problem, drops the person. Cheap, fast, and it preserves nearly all of Claude's usefulness.

Connectors / web features

Plan-dependent integrations that reach drives or the web

Widen what is exposed. Treat enabling one as a decision to review against your data policy, not a default.

Hands-on workshop

Workshop — write your studio's one-page data policy

You will produce a short, usable rule that any team member could follow, plus the anonymisation habit that makes it work. Do this with a real recent project in front of you so the categories are concrete, not abstract.

Claude.ai (to check settings and test anonymisation) and a real, recent brief.

Given & goal
Goal: a one-page Claude data policy + a tested anonymisation habit
Inputs: a recent project brief + your Claude account settings
Time: ~25 minutes
  1. 1Open your Claude account and find the data / privacy settings. Note, in plain words, what your current plan does with your conversations and whether training is on or off. If you are on a personal plan doing real work, note that as a risk.
  2. 2Take a paragraph from your real brief and rewrite it anonymised: replace names, address, exact budget and any security detail with neutral descriptions. Paste the anonymised version to Claude with a normal request and confirm you got equally useful help.
  3. 3List the categories your clients and NDAs forbid you to share, even anonymised. Be specific to your kind of work (security details, unannounced schemes, supplier pricing, medical needs).
  4. 4Draft the one-pager under four headings: WHERE client work happens, WHAT is never pasted, HOW to anonymise (paste the checklist), WHO to ask when unsure.
  5. 5Add a review date and a line pointing to Anthropic's current privacy terms, so the policy stays honest as terms change.
  6. 6Share it with anyone who uses Claude on client work, and pin the anonymisation checklist where people will actually see it.

You’ll walk away with
A one-page studio data policy (where / what-never / how-to-anonymise / who-to-ask, dated and review-scheduled) plus one worked anonymised brief paragraph proving the habit costs you nothing in usefulness.

The worked example

Three altitudes on the same idea

Read the band that fits you — or all three.

For the architectClaude across the whole practice

Set the policy for the whole office, do not leave it to instinct. Put confidential project work on a business or Enterprise account with training off and retention understood, name the categories that never travel even anonymised - security details, unannounced schemes, exact budgets - and appoint someone to answer the grey cases. Your appointment and your clients' NDAs sit above any tool setting; where they might conflict, that is a question for your lawyer, not a checkbox. Treat data hygiene as part of your professional standard of care.

For the interior designerClaude for specs, client work & sourcing

Interiors data is intimate, and so is the risk. You handle client budgets, supplier and trade discounts you are contractually bound to protect, private residences, and the personal taste of people who pay for discretion. Anonymise before you draft that FF&E schedule or client narrative - a family of four on an infill plot, an upper-mid budget - and keep supplier pricing and named-client details on a properly-termed account. When you present, disclosing that you drafted with AI is fine; disclosing your client's private address into a chat window is not.

For the studentA Claude-fluent design skillset

Build the reflex now, before a real client's trust is on the line. In studio you will paste your own work freely - good, learn fast. But form the habit early of separating a design problem from a person's identity, because the day you join a practice you will be handling other people's confidences under a duty you did not write. Learn to read a tool's data settings rather than assume them, and get comfortable saying "I anonymised this before using AI." That habit will mark you out as someone safe to trust with real work.

Misconception check

Claude is private, so it is fine to paste any client material into it.

Privacy depends entirely on your plan and settings, not on a general reputation. As of 2026, consumer plans may use conversations to improve Claude unless you opt out, while business and API usage generally are not used for training by default - so "is it private?" has no single answer until you check your own account. More importantly, no setting overrides your professional duty of confidentiality or your client's NDA. The safe posture is to anonymise by default, route confidential work through a properly-termed business or API setup, and keep the genuinely sensitive out entirely. Verify current terms yourself; this is a working discipline, not legal advice.
Try it

Do it yourself

Reason these through - most need no tools.

  1. 1What is the difference, as of 2026, between how consumer plans and business/API usage typically treat your conversations?
  2. 2Give three items you would strip from a brief before pasting it, and three you would keep.
  3. 3Why does your client's NDA sit above any tool setting - and who resolves a conflict between them?
  4. 4Rewrite one sentence of a client brief so it keeps the design problem but loses the identity.
  5. 5Name the four headings of a workable one-page studio data policy.
Take this with you

The one line to carry out

Protect the client first and use the tool second: anonymise by default, route confidential work through a properly-termed plan, and keep the genuinely sensitive out - because your duty of confidentiality sits above any setting.
Take it further
References & further reading

Peer-reviewed journals & authoritative standards

  1. 01Privacy policyAnthropic, 2026.
  2. 02Consumer terms of serviceAnthropic, 2026.
  3. 03ConfidentialityWikipedia, 2026.
  4. 04Personal dataWikipedia, 2026.
  5. 05General Data Protection RegulationWikipedia, 2026.
Related lessons
Recap
Designers hold unusually private information, and pasting it into Claude is a confidentiality decision made on the client's behalf. How your data is treated depends on your plan - as of 2026 consumer plans may use conversations for improvement unless you opt out, while business and API usage generally do not train by default. The reliable disciplines are to separate the design problem from the client's identity, anonymise before you paste, route confidential work through a properly-termed account, keep the genuinely sensitive out, and write a short studio data policy. Your professional duty and the client's NDA sit above every tool setting; verify current terms and defer legal questions to a lawyer.
Carry forward →

Confidentiality protects the client from what Claude sees. The next lesson protects everyone - client and you - from what Claude says: its confident, plausible, sometimes-wrong output, and the liability that stays firmly with you.

A

The author

Amogh N P

Architect, interior designer, and creative polymath. Studio Matrx began in his notebooks — his vision of design made honest, useful, and open to everyone. Its Academy is written and taught in his memory, and free, forever.

More about Amogh →