Claims last verified 2026-07-28 22 confirmed · 6 documented · 1 stale risk verification log →

Anthropic's policies and products change frequently — always confirm current specifics with your Anthropic contact before relying on this for a compliance decision.

Receipts — the verification log

A finding is marked Confirmed only when it was checked against Anthropic's own page and the fetch was kept. This is that record. Each finding's inline (receipt R#) links here, so you can see exactly what was fetched, when, and — for the re-verified claims — the sentence that confirmed it, quoted exactly. Where a check turned up an absence rather than a sentence, that is recorded as a note in our own voice instead. A 404 row is kept too: a failed fetch is part of an honest log, not hidden.

What the banner counts

The currency banner at the top of every page counts established findings only — the claim cards inside the six modules. It does not count the How this connects card at the foot of each module: those six cards carry chips too, but they are navigational summaries rather than findings, and counting them twice would inflate the total. Nor does it count open questions, glossary entries or worked examples, none of which assert a verified fact.

So a reader who counts chips on screen will see more of them than the banner's total, and the difference is these six. We would rather say that plainly than have you find it.

A note on the log's own vocabulary: each table below is one verification round — a dated sitting in which claims were checked against Anthropic's live pages. Rounds carry internal names like CG4 ("curriculum-grade", numbered), and each fetch in a round gets a receipt number (R1, R2, …) that the finding cards cite. Where a note references a rule like "§4.4", that is the project's own review charter — the discipline the log is kept under — not an Anthropic document.

Flagged right now — 1 claim at stale risk

These are the claims the currency banner counts as stale risk. A flag here is not a mistake we are hiding — it is the verification working. Each one is either sourced to something that turned out not to support it, or contradicted by the vendor's own documentation. Treat each as a question for your Anthropic contact, not as a fact.

How to read the chips

Baseline receipts · fetched 2026-07-22

# Primary source HTTP Date Used for
R1 Use Claude Cowork safely 200 2026-07-22 Folder and desktop access findings — what Claude can reach, and what isolation does and does not limit.
R2 How long do you store my data? (consumer) 200 2026-07-22 Consumer retention — partial; the training-toggle detail was re-fetched later as R19.
R3 HIPAA-ready Enterprise plans 200 2026-07-22 HIPAA coverage findings — which plans are eligible, what a BAA covers, and what stays outside it.
R4 What are skills? 200 2026-07-22 Skills findings — what a Skill is, how it is built, and how it is shared.
R5 Models overview 200 2026-07-22 The model-availability worked example — how to check whether a named model is actually available to you.
R6 ZDR agreement: which products? 200 2026-07-22 Zero-data-retention scope — which products a ZDR arrangement covers, and that it applies per organization.
R7 API & data retention 200 2026-07-22 API retention windows, HIPAA coverage boundaries, and the model-availability example.
R8 How long do you store my organization's data? 200 2026-07-22 Organization retention, the 30-day deletion figure, and the trust & safety retention exception.
R9 Skills (docs path) 404 2026-07-22 Skills definition — attempted; the docs path had moved. Kept as a failed receipt, because an honest log records the fetches that did not work. Superseded by R22.

Re-verification · fetched 2026-07-23

Re-verification for SC4 R1 (Operation Rutter): resolved the doc's '7-day API retention' claim (now 30-day / not-retained-by-default) and relocated the moved Skills docs path. These four rows were originally labelled R2′, R7′, R8′ and R9→. Prime and arrow labels cannot be addressed by an inline '(receipt R#)' citation, so every node citing them silently resolved to the baseline row each one superseded. CG4 reissued them as R19–R22 — at the end of the sequence rather than in date order, because ids already in print are never renumbered.

# Primary source HTTP Date Confirming quote & what we checked
R20 supersedes R7 API & data retention 200 2026-07-23 “Conversation content (your prompts and Claude's outputs) is not retained by default; the exception is Covered Models, which require 30-day retention. Flagged content retained up to 2 years; scores up to 7 years.”
R21 supersedes R8 How long do you store my organization's data? 200 2026-07-23 “For Anthropic API users, we automatically delete inputs and outputs on our backend within 30 days of receipt or generation.”
R19 supersedes R2 How long do you store my data? (consumer) 200 2026-07-23 “If you allow us to use your chats or coding sessions to improve Claude, we may retain your data in a de-identified format for up to 5 years in our model training pipelines.” What we checked: Checked for a distinct automatic retention window in the toggle-OFF state: none published. Recorded as an honest absence rather than inferred.
R22 supersedes R9 Agent Skills overview (relocated path) 200 2026-07-23 “Every Skill requires a SKILL.md file with YAML frontmatter.” What we checked: Path relocated: the previously cited /agents-and-tools/skills URL was the 404 preserved as R9. This row records the fetch that superseded it.

Patient-safety round · fetched 2026-07-25

SC5 / Operation Soundings, CG2 (Wave 1 — patient safety). Nine primary-source fetches backing the Wave-1 corrections, mirrored verbatim from the currency & provenance report's '## CG2 currency round' section. Numbered as integers R10–R18: seven were taken during the round itself, and R17 and R18 were added in the post-review correction pass, after an independent reviewer showed the round had wrongly downgraded the commercial no-training claim. Two of these receipts (R15 and R16) contradict each other on the same day — that pair is itself the evidence behind a Stale-risk finding, which is why both are kept.

# Primary source HTTP Date Confirming quote & what we checked
R10 Use Claude Cowork safely 200 2026-07-25 “Isolation limits where Claude's code runs. It doesn't limit what Claude reads or does. … any local files it opens through the desktop app, is processed on Anthropic's servers rather than staying on your computer. … computer use has no sandbox between Claude and what's on your screen. … When Claude uses your computer, it asks for your permission before accessing each application. … Claude always asks before permanently deleting files, in any mode.”
R11 HIPAA-ready Enterprise plans 200 2026-07-25 “This feature is available for Enterprise plans only (both self-serve and sales-assisted). … Eligible Enterprise organizations can enable HIPAA-ready configuration directly from organization settings—no sales or legal cycle required. … This is a one-way decision. … If your organization signed a BAA for Claude API usage before December 2, 2025, that agreement only covers API usage. … Cowork is not yet covered under Anthropic's BAA.”
R12 API and data retention 200 2026-07-25 “Claude Code: Claude Code is not covered under HIPAA readiness. … Partner-operated platforms: Amazon Bedrock and Google Cloud's Agent Platform. … Claude Platform on AWS and Microsoft Foundry: HIPAA readiness is not available on these platforms. … Retained data is never used for model training without your express permission. … Do not include PHI in JSON schema definitions. … Files retained until explicitly deleted.”
R13 How long do you store my data? (consumer) 200 2026-07-25 “This article is about our consumer products such as Claude Free, Pro, Max and when accounts from those plans use Claude Code. For our commercial products such as Claude for Work and the Anthropic API, see here. … we retain data associated with that submission for 5 years.”
R14 How long do you store my organization's data? (commercial) 200 2026-07-25 “Where you have provided feedback to us (e.g. by submitting feedback through our thumbs up/down button or sent bug reports), we retain data associated with that submission for 5 years.” What we checked: Full-text check of this article for model-training language: zero occurrences of the word "train" except as the anchor text of an outbound link to the separate training article (7996868). Recorded because an earlier draft of this round used that absence to argue no commercial no-training commitment is published — which is wrong: the commitment is in article 7996868 and in the Commercial Terms (R17, R18). The absence is a true fact about THIS article only.
R15 Agent Skills overview 200 2026-07-25 “Upload your own Skills as zip files through Settings > Features. Available on Pro, Max, Team, and Enterprise plans with code execution enabled. Custom Skills are individual to each user. They are not shared organization-wide and cannot be centrally managed by admins. … Agent Skills is not covered by ZDR arrangements. … Use Skills only from trusted sources … Treat like installing software.”
R16 What are skills? (Help Center) 200 2026-07-25 “For Team and Enterprise plans, organization Owners can provision skills for all users. … Centralized management for organizations: Team and Enterprise plan Owners can provision skills organization-wide, ensuring consistent workflows across teams without requiring individual setup from each user.” What we checked: Directly contradicts R15, fetched the same day. This pair is itself the evidence behind a Stale-risk finding.
R17 Anthropic Commercial Terms of Service §B (Customer Content) 200 2026-07-25 “Anthropic may not train models on Customer Content from Services. “Inputs” means submissions to the Services by Customer or its Users and “Outputs” means responses generated by the Services to Inputs (Inputs and Outputs together are “Customer Content”).” What we checked: Fetched during the post-review correction pass, after an independent reviewer showed that this round had wrongly downgraded the commercial no-training claim on the strength of a partial search.
R18 Is my data used for model training? (commercial scope) 200 2026-07-25 “By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models. If you explicitly report feedback or bugs to us (e.g. via our thumbs up/down feedback button), or otherwise choose to allow us to use your data, then we may use your chats and coding sessions to train our models. … When you provide us feedback via our thumbs up / down button, we will store the entire related conversation, including any content, custom styles, conversation preferences, or model settings, in our secured back-end for up to 5 years.” What we checked: The article this round should have checked first. It reconciles the API documentation's conditional phrasing (“without your express permission”) with the Commercial Terms' flat prohibition: the feedback button is how express permission is given.

Credibility & provenance round · fetched 2026-07-27

SC5 / Operation Soundings, CG4 (Wave 2 — credibility, provenance, currency mechanism). Fetches taken to discharge charter §4.4 before any chip moved or any negative claim was made: a claim of the form “the source does not say X” may not stand until the document where X would live has actually been searched. Two of these fetches produced the round's blocking finding — a term this curriculum had been presenting in quotation marks as Anthropic's own is on neither primary source.

# Primary source HTTP Date Confirming quote & what we checked
R23 HIPAA-ready Enterprise plans (Help Center) 200 2026-07-27 “The HIPAA-ready Enterprise offering includes many of the features available on standard Enterprise plans—but enabling HIPAA doesn't bring every feature under your BAA. Features fall into three categories: covered by your BAA, available but not covered, and disabled. … PHI should only be processed through covered features, so it's important for administrators to know which features fall in which category and to configure their workspace accordingly. … The Implementation Guide for HIPAA Entities on the Anthropic Trust Center lists every feature's status and is the authoritative source. … Note: You'll need to request access to view the Implementation Guide. Requests from domains matching existing customer accounts are approved automatically. … Additionally, Cowork is not yet covered under Anthropic's BAA.” What we checked: Searched specifically for the phrase “Eligible Services”: NOT PRESENT on this page. This page's vocabulary is covered / available but not covered / disabled. Also searched for “beta” (absent), a feature table (absent — the page defers to the gated Implementation Guide), and any 400-error enforcement (absent; Enterprise is administrator-responsibility, not API-enforced). Freshness: the page displays the relative string “Updated this week” and no absolute date, so it is not citable as a dated source. Fidelity caveat recorded honestly: the first fetch returned a summary rather than the source and a second transcription-only pass was used; sentence-level wording was consistent across both passes, but capitalization of UI button labels is not guaranteed and is not quoted here.
R24 API and data retention (Claude Docs) 200 2026-07-27 “The following table lists which Claude API features are eligible for ZDR and HIPAA readiness arrangements. … Each eligibility column uses three values: Yes: The feature is fully eligible under the arrangement. … Yes (qualified): Your prompts and Claude's outputs are not stored, but a bounded technical artifact (named in the Details column) is retained briefly for the feature to function. No: The feature is not eligible. … Beta features: Features in beta are generally not covered under the BAA unless explicitly listed as eligible in the feature eligibility table. … Your signed BAA is the official source of truth for which features are covered. The API also enforces these restrictions automatically. When a HIPAA-enabled organization sends a request that includes a non-eligible feature, the API returns a 400 error to prevent accidental use of features not covered by your BAA … Under HIPAA readiness, the API blocks requests that include a "No" feature and returns a 400 error. Under ZDR, the API does not block these features; using one is a choice to step outside your ZDR arrangement for that specific data … Claude Fable 5 and Claude Mythos 5 are designated Covered Models … and require 30-day data retention; ZDR is therefore not available for either model.” What we checked: Searched specifically for the phrase “Eligible Services”: NOT PRESENT on this page either. Combined with R23, that phrase is on NEITHER primary source, which is the basis for retitling est_hipaa_eligible_services. Three corrections to our own prior reading, recorded because they change what we may claim: (1) the eligibility table is THREE-valued (Yes / Yes (qualified) / No), not per-feature Yes/No as an earlier pass described it; (2) the table is PUBLIC — fetched anonymously, no login — so it, not the gated Implementation Guide, is the reader's first stop on the API path; (3) the 400 enforcement is HIPAA-only and the page says so explicitly — under ZDR the API does not block. Also: the beta-features sentence must not be truncated at “explicitly listed”; the qualifier “as eligible in the feature eligibility table” is part of it. Cowork does not appear on this page at all — the “not yet covered” statement is sourced to R23 only.
R25 Statement on the US government directive to suspend access to Fable 5 and Mythos 5 (dated Jun 12, 2026) 200 2026-07-27 “The US government, citing national security authorities, has issued an export control directive to suspend all access to Fable 5 and Mythos 5 by any foreign national … we must abruptly disable Fable 5 and Mythos 5 for all our customers to ensure compliance … Our understanding is that the government believes it has become aware of a method of bypassing, or 'jailbreaking' Fable 5. … We believe this is a misunderstanding and are working to restore access as soon as possible.” What we checked: Fetched to receipt a node that had been asserting this episode from the working-group document alone. Two corrections follow from it. (1) The mechanism was stated wrongly: our node said access was suspended “under export-control review”, which describes a pending assessment; the source describes an issued export control DIRECTIVE that Anthropic complied with. (2) Searched this page — the document class where a restoration announcement would live — for a restoration date: NOT PRESENT. It says only “working to restore access as soon as possible”. Our node's “restored around July 1, 2026” is therefore unsourced as to date, though restoration itself is demonstrable from R26.
R26 Models overview (Claude Docs) 200 2026-07-27 “Claude Fable 5 is generally available on the Claude API, Amazon Bedrock, Claude Platform on AWS, Google Cloud, and Microsoft Foundry beginning June 9, 2026. Claude Mythos 5 is not generally available: it is offered in limited availability to approved customers in Project Glasswing, beginning the same day. … Claude Mythos 5 and Claude Mythos Preview are offered separately for defensive cybersecurity workflows as part of Project Glasswing. Access is invitation-only and there is no self-serve sign-up.” What we checked: Searched for any trace of the June 2026 suspension: NONE (`suspend`, `export`, `directive`, `restor` — zero hits each). That absence is the node's own teaching point — a status page shows the present, not the history — and it is now demonstrated rather than asserted. Mythos 5's limited availability is Project Glasswing, invitation-only with no self-serve sign-up, and the page states its purpose in the same sentence: defensive cybersecurity workflows. CORRECTION TO THIS RECEIPT, made at the CG4 source-check leg: an earlier draft of this row asserted that the page does NOT describe Mythos 5 as being for defensive-cybersecurity work, and the node deleted that detail on the strength of it. The page says so plainly, in the sentence immediately preceding the clause quoted above. The Project Glasswing detail is an ADDITION to what the node already had right, not a correction of it. Recorded here rather than silently repaired because a receipt that once certified a false absence is exactly the artifact a reader should be able to audit.
R27 What are skills? (Help Center) — displayed “Updated over 2 weeks ago” 200 2026-07-27 “For Team and Enterprise plans, organization Owners can provision skills for all users. Skills provisioned in this way appear automatically in every team member's skills list and can be set as enabled or disabled by default. This allows organizations to: Distribute approved workflows consistently across all employees / Ensure teams use standardized procedures and best practices / Deploy new capabilities without requiring individual uploads … Anthropic skills — These are skills created and maintained by Anthropic, such as enhanced document creation for Excel, Word, PowerPoint, and PDF files. … Skills vs. projects — Projects provide static background knowledge that's always loaded when you start chats within them. Skills provide specialized procedures that activate dynamically when needed and work everywhere across Claude. … The Skills Directory features professionally-built skills from partners like Notion, Figma, Atlassian, and others.” What we checked: Three enumerated searches, all negative and all load-bearing. (1) “skill-creator”: ZERO hits in any spelling — this page does not describe it as built-in or otherwise. (2) Security/trust language (security, untrusted, malicious, caution, third-part*): the only hit is an unrelated Related-Articles link title. This consumer-facing page introduces the third-party Skills Directory with NO caution, audit advice or trust language, while the platform documentation carries a strong warning — a documentation gap, not a contradiction. (3) “preferences”: absent; the page contrasts Skills with custom instructions, projects and MCP only. Method note: a first transcription pass silently dropped trailing clauses and an entire sub-list; these quotes come from raw HTML retrieval, which also preserved the clause “though you can attach executable scripts to custom skills for more advanced functionality” — this page's only acknowledgement that Skills execute code, presented as a feature.
R28 Agent Skills overview (Claude Docs) 200 2026-07-27 “Custom Skills are individual to each user. They are not shared organization-wide and cannot be centrally managed by admins. … claude.ai does not support centralized admin management or org-wide distribution of custom Skills. … Custom Skills are shared workspace-wide: all workspace members can access them. … Claude API: Workspace-wide. All workspace members can access uploaded Skills. … Claude Code: Personal (~/.claude/skills/) or project-based (.claude/skills/). Can also be shared through Claude Code Plugins. … Agent Skills is not covered by ZDR arrangements. Skill definitions and execution data are retained according to Anthropic's standard data retention policy. … Use Skills only from trusted sources: those you created yourself or obtained from Anthropic. Skills give Claude new capabilities through instructions and code, which also means a malicious Skill can direct Claude to invoke tools or execute code in ways that don't match the Skill's stated purpose. … Anthropic also publishes open-source Skills in the skills repository” What we checked: This page is one half of the site's documented contradiction (see R27 for the other). Both were re-fetched the same day, 2026-07-27, and both still stand — the contradiction reproduces two days after CG2 first documented it. New this round: a freshness asymmetry. R27 displays “Updated over 2 weeks ago” and links to a dedicated article, “Provision and manage skills for your organization”; this page carries no freshness string. That is a reason to suspect THIS page is the stale one — but it is a suspicion, not a finding, and neither page is dated precisely enough to settle it. Second enumerated search: “skill-creator” — ZERO hits here too. Third: searched for distribution paths that DO exist, because our curriculum was telling readers to assume a Skill reaches only its author — three are documented (API workspace-wide, Claude Code Plugins, and the enterprise Skills API), so that instruction was wrong for every surface except claude.ai.
R29 Skills for enterprise (Claude Docs) 200 2026-07-27 “The Skills API provides workspace-scoped distribution. Skills uploaded through the API are available to all workspace members. … Upload through the Skills API for workspace-wide access. … Document the Skill in your internal registry with purpose, owner, and version. … Custom Skills do not sync across surfaces. Skills uploaded to the API are not available on claude.ai or in Claude Code, and vice versa. Each surface requires separate uploads and management.” What we checked: Fetched to test whether an organization-level deployment path exists at all. It does, but only via the Skills API and only workspace-scoped; no claude.ai admin push is documented here. The cross-surface non-sync sentence is the one most likely to surprise this group: a Skill built in one place does not appear in the others.
R32 Provision and manage skills for your organization (Help Center) — displayed “May 29, 2026”, tooltip “Updated over 2 months ago” 200 2026-07-27 “This article explains how organization owners can provision skills for everyone in their organization, and how to scope skills to specific groups using plugins. … When you upload a skill through organization settings, it becomes available to everyone in your organization in Customize > Skills. Individual members no longer need to upload the same skill themselves. … Organization-wide skill management is available to Team and Enterprise plans. … Skills appear for each member in Customize > Skills, organized into three sections: Personal skills: Skills the member has created or uploaded. Shared with you: Skills colleagues have shared directly with a member. … Organization skills: Skills an owner has provisioned and skills members have shared organization-wide. … Skill sharing: Members can share a skill with specific colleagues. … Share with organization: Members can publish a skill to the organization directory, where anyone can find and install it. Both toggles are off by default. … Note: Only owners can add or remove organization-wide skills. Individual users cannot delete provisioned skills, though they can toggle them off for their own use. … Important: There's no approval workflow for org-wide sharing. If you enable Share with organization, any member can publish a skill to the directory without review. … The audit log doesn't capture the contents of shared skills—only the share event itself. There's no admin dashboard to browse or inspect the contents of skills shared between members.” What we checked: THE DOCUMENT CG4 SHOULD HAVE FETCHED AND DID NOT. Our stale-risk node asserted that “neither page draws that distinction” while its own prose named this article — as a freshness signal — without anyone opening it. That is a §4.4 violation on the round that made §4.4 its banner, and it was caught by the adversarial leg, not by us. What the page settles: the apparent contradiction is largely a CATEGORY confusion. An owner-provisioned skill (uploaded via Organization settings) and a member's personal skill are different objects, and the clause “Individual members no longer need to upload the same skill themselves” presupposes exactly the per-user world the platform documentation describes. What the page does NOT do is rescue the platform sentence: it documents a member-driven path to organization-wide distribution (“Share with organization”), so “They are not shared organization-wide” is false as stated and true only of the DEFAULT posture — both toggles ship off. “Cannot be centrally managed by admins” half-survives: no admin dashboard inspects shared-skill CONTENTS, but owners control both sharing toggles and share events reach the audit log and Compliance API. Freshness ordering, which decides which page to believe: “What are skills?” = updated ~2 weeks ago; this admin article = May 29 2026 (~2 months); the platform overview carries no freshness string at all and is the laggard.
R30 Use Claude Cowork safely (Help Center) — displayed “Updated over a week ago” 200 2026-07-27 “Local MCP servers bundled with plugins and desktop extensions run on your computer with the same permissions as any other program you run. … Desktop extensions (MCPs) and plugins expand what Claude can do, but each one introduces new ways for attacks to reach Claude. Plugins bundle together skills, connectors, and sub-agents into a single package, which means installing one can significantly expand Claude's scope of action. … Stick to verified extensions from the Claude Desktop directory, and carefully evaluate the permissions any extension or plugin requests before installing. … Important: Network egress permissions don't apply to the web fetch or web search tools or MCPs, including Claude in Chrome.” What we checked: Enumerated search for any statement that an MCP server accesses only what it has been granted and nothing more — the claim our glossary was making. Every sentence containing “grant*” or “only access” was read: six hits, none of which makes that claim about MCP servers. The page runs the OPPOSITE direction on both counts — local MCP servers run with the user's full permissions, and network-egress permissions explicitly do not apply to MCPs. The glossary claim was not merely unsourced; it was contradicted.
R31 How long do you store my data? (consumer) — displayed “Updated over 3 weeks ago” 200 2026-07-27 “This article is about our consumer products such as Claude Free, Pro, Max and when accounts from those plans use Claude Code. For our commercial products such as Claude for Work and the Anthropic API, see here. … If you allow us to use your chats or coding sessions to improve Claude, we may retain your data in a de-identified format for up to 5 years in our model training pipelines. This retention period only applies to new or resumed chats after the model training setting has been enabled. … You control your chats with Claude and can delete your conversations at any time. When you delete a conversation it's: Removed from your chat history immediately / Deleted from our back-end storage systems within 30 days … If you decide to turn off the model improvement setting, we will not use your previous or new chats or coding sessions for future model training.” What we checked: Enumerated search for a published automatic retention window in the setting-OFF state, done two ways: every duration string on the page was collected (30 days deletion purge; 5 years training-on; 2 years usage-policy-violation content; 7 years classification scores; 5 years feedback) and NONE is tied to the setting being off; and the OFF paragraph was read in full — it makes a USE statement, not a RETENTION statement. So the honest claim is “no automatic retention window for the off state is published in this article”, NOT “data is not retained when the setting is off”. One structural finding, verified in raw HTML across three independent retrievals: the page carries an H2 heading “Standard Retention Timeframe” with NO body text under it — the section that would state a default window is present as a heading and empty. Recorded because it explains the absence without excusing it.

Comprehension & craft round · fetched 2026-07-28

SC5 / Operation Soundings, CG5 (Wave 3 — comprehension & craft). Fetches taken before any graph text moved: the consumer training-toggle label, default and Claude Code scope (A1); the prebuilt-Skills surface qualifier (A2); and the multi-source chip adoption sweep (D1), where every URL added to a node's source list rests on a fetch from this round — adding one from memory is the defect the multi-source field exists to prevent. Negative claims in the checked notes state the search that grounds them (charter §4.4 as extended by amendment 5).

# Primary source HTTP Date Confirming quote & what we checked
R33 How do I change my model improvement privacy settings? (Privacy Center) — page dated “March 16, 2026” 200 2026-07-28 “Under Help Improve Claude, click the button to toggle it off/on … If you decide to turn off the model training setting, we will not use any new chats and coding sessions you have with Claude for future model training. … This article is about our consumer products such as Claude Free, Pro, Max and when accounts from those plans use Claude Code.” What we checked: The settings walkthrough names the toggle's printed label: “Help Improve Claude”, under Settings > Privacy (claude.ai/settings/data-privacy-controls). Searched the full article for “Improve Claude for everyone” — the phrase does not appear; the label this curriculum and the group's doc had been circulating is on neither this page nor the storage article (R34). Also searched this article for the toggle's default state (“default”, “by default”, “new account”) — the page gives set/unset instructions only and states no default. The off-state commitment and the article's scoping sentence both cover coding sessions from consumer accounts, which is the Claude Code scope the toggle node was missing.
R34 How long do you store my data? (consumer) — displayed “Updated over 3 weeks ago” 200 2026-07-28 “This article is about our consumer products such as Claude Free, Pro, Max and when accounts from those plans use Claude Code. … This retention period only applies to new or resumed chats after the model training setting has been enabled. … Your Incognito chats are not used to improve Claude, even if you have enabled Model Improvement in your Privacy Settings.” What we checked: Re-fetch of the R31 page one day on, for the toggle node's label and default. The retention arithmetic is unchanged (30-day back-end deletion on delete; up to 5 years de-identified while training is on; 2-year / 7-year safety windows). This page's own names for the setting are “the model training setting”, “the model improvement setting” and “Model Improvement in your Privacy Settings” — searched the article for “Improve Claude for everyone”: not present. Searched for a stated default (“default”, “by default”, “new account”): none stated. The “Standard Retention Timeframe” heading still carries no body text (checked under that heading in the returned article).
R35 Agent Skills overview (Claude platform docs) 200 2026-07-28 “Using Skills through the API requires the code execution tool, whose container Skills run in, and one beta header: skills-2025-10-02 - Enables Skills functionality. … Pre-built Agent Skills: These Skills are active when you create documents. Claude uses them with no setup required. … The pre-built document Skills (PowerPoint, Excel, Word, PDF) are not available in Claude Code … Agent Skills is not covered by ZDR arrangements. Skill definitions and execution data are retained according to Anthropic's standard data retention policy.” What we checked: Fetched for the prebuilt-Skills surface qualifier (A2) and the Skills-ZDR chip. The “no setup required” sentence sits in the claude.ai section — it is a claude.ai-surface statement, not a product-wide one. The API path has stated prerequisites (code execution tool + the skills-2025-10-02 beta header; plus files-api-2025-04-14 when files move in or out of the container). Claude Code does not carry the prebuilt document Skills at all. Pre-built Skills are also available on Claude Platform on AWS and Microsoft Foundry (on Foundry, only with a Hosted-on-Anthropic deployment).
R36 API and data retention (Claude platform docs) 200 2026-07-28 “Retained data is never used for model training without your express permission. … There are two ways to set up HIPAA-ready API access. Most organizations can enable it directly in the Claude Console with Anthropic's standard BAA; organizations that require a negotiated BAA should work with their account team. … Do I still need ZDR if I have HIPAA readiness? No. … HIPAA readiness is enforced at the organization level. If you need both HIPAA-ready and general-purpose API access, use separate organizations for each. … Claude Code: Claude Code is not covered under HIPAA readiness.” What we checked: D1 adoption-sweep fetch — this is the named-but-unchipped document behind claims on four nodes (est_hipaa_code_zdr_cowork's API-path ruling; est_hipaa_two_baa_configs' self-serve Console path, ZDR-not-also-needed answer, and org-level enforcement; est_retention_commercial_no_training's express-permission sentence; est_retention_api_zdr already chips it). Every quoted passage above was re-verified verbatim on the live page before the URL was added to any node's source list. The Console mechanics sentence ('In Claude Console > Settings > Privacy, organization admins with the HIPAA management permission see a HIPAA compliance card') and the Enterprise-with-ZDR Claude Code exception both reproduce as the nodes state them.
R37 HIPAA-ready Enterprise plans (Claude Help Center) — displayed “Updated this week” 200 2026-07-28 “Team plans and individual plans (Free, Pro, and Max) can't enable HIPAA. … Additionally, Cowork is not yet covered under Anthropic's BAA. … This feature is available for Enterprise plans only (both self-serve and sales-assisted). … Only the Primary Owner of the organization can accept the BAA and enable HIPAA.” What we checked: D1 adoption-sweep fetch — the named-but-unchipped document behind est_hipaa_never_covered's plan-eligibility and Cowork claims (the node chipped only the API docs while its title's plan claim lives here). The December 2, 2025 BAA-cutover sentences also reproduce verbatim, which re-verifies the claim behind open_hipaa_prior_baa_scope's framing.
R38 How long do you store my organization's data? (Privacy Center) — displayed “Updated over 3 weeks ago” 200 2026-07-28 “Deleted from our back-end storage systems within 30 days … This article is about our commercial products such as Claude for Work and the Anthropic API. … Where you have provided feedback to us (e.g. by submitting feedback through our thumbs up/down button or sent bug reports), we retain data associated with that submission for 5 years.” What we checked: D1 adoption-sweep fetch — the Privacy Center article behind est_retention_api_zdr's 30-day deletion figure (the R21 quote's home page, previously cited in prose but unchipped) and one of est_retention_feedback_5yr's three sources. The node's claim that the 5-year feedback sentence is identical on the commercial and consumer articles was re-verified rather than assumed: the sentence above was fetched from BOTH pages this date (this row and the consumer article) and is byte-identical — the claim stands, so nothing was 'corrected'.
R39 What are skills? (Claude Help Center) — displayed “Updated over 2 weeks ago” 200 2026-07-28 “Skills are folders of instructions, scripts, and resources that Claude loads dynamically to improve performance on specialized tasks. … These are skills created and maintained by Anthropic, such as enhanced document creation for Excel, Word, PowerPoint, and PDF files. … Anyone can create skills by writing instructions in Markdown—no coding required for simple skills, though you can attach executable scripts to custom skills for more advanced functionality.” What we checked: D1 adoption-sweep fetch — the Help Center companion est_skills_definition names in prose but did not chip. The article's own definition sentence corroborates the node's claim from the app-facing side; it does not mention SKILL.md — searched the full returned article for "SKILL.md" and the case variants "skill.md" / "Skill.md": 0 occurrences (that structural fact lives on the platform docs page, which the node already chips) — so each chip carries a distinct part of the claim.
R40 Is my data used for model training? (Privacy Center, commercial) — page dated “March 16, 2026” 200 2026-07-28 “By default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models. … If you explicitly report feedback or bugs to us (e.g. via our thumbs up/down feedback button), or otherwise choose to allow us to use your data, then we may use your chats and coding sessions to train our models. … When you provide us feedback via our thumbs up / down button, we will store the entire related conversation, including any content, custom styles, conversation preferences, or model settings, in our secured back-end for up to 5 years. … Feedback data does not include raw content from connectors (e.g. Google Drive), including remote and local MCP servers, though data may be included if it's directly copied into your conversation with Claude.” What we checked: D1 adoption-sweep fetch — the article carrying est_retention_feedback_5yr's entire-conversation scope, training permission, and connector limit (named in the node's prose, unchipped until now), and est_retention_commercial_no_training's policy statement + its feedback exception. All five claims re-verified verbatim on the live page before the URL joined either node's source list.

Text in “quotation marks” is published by the cited source, word for word. Anything labelled What we checked is our own verification note, not the source's words — including the cases where what we found was an absence. This log is derived from the working group's currency & provenance report, which is canonical and is re-verified before each Anthropic contact call. Confirm current specifics with your Anthropic contact before relying on any of this for a compliance decision.