# After a December 2023 backlash over a default-on 'third-party AI' setting, Dropbox said customer data is never used to train OpenAI's models and is deleted within 30 days > In December 2023, Dropbox users — including AWS CTO Werner Vogels — discovered a 'third-party AI' toggle turned on by default in account settings and feared their files were being fed to OpenAI as AI-training data. Dropbox responded publicly: CEO Drew Houston said no setting automatically or passively sends customer data to a third-party AI service, while a Dropbox help/FAQ page stated the data is never used to train OpenAI's internal models and is deleted within 30 days. This is an AI-data clarification/denial and settings-UX response, not a reversal of a training practice. - Verification status: pending - Case type: deployment - Provider: Dropbox, Inc. - Client: Dropbox, Inc., Cloud file storage / collaboration software; AI data-handling (named) - Sector: tech / US / marketing - Canonical URL: https://theinternetninja.com/stories/dropbox-third-party-ai-openai-toggle-backlash-data-not-used-to-train-models-2023/ - Source: The Internet Ninja (theinternetninja.com), independent verified-proof platform ## Verification method Byte-tied Wayback captures of Dropbox's first-party help/FAQ page (2023-12-14) plus three independent newsrooms — The Register (2023-12-17 capture), CNBC (2023-12-14 capture) and The Stack (2023-12-15 capture). Every load-bearing quote decoded and bound verbatim to its capture. ## Full case file ## What happened In December 2023 — months after Dropbox rolled out AI features (Dropbox AI / Dropbox Dash) — users discovered a **"third-party AI"** setting in their account options and worried their private files were being handed to OpenAI. The alarm was amplified when AWS CTO Werner Vogels weighed in: The Register reported that critics became convinced Dropbox "was by default feeding OpenAI, maker of ChatGPT and DALL•E 3, with user files as training fodder for AI models" ([source](https://www.theregister.com/2023/12/15/dropbox_ai_training/)). CNBC noted that the "third-party AI" toggle "is turned on by default in account settings" ([source](https://www.cnbc.com/2023/12/13/how-to-stop-dropbox-from-sharing-your-personal-files-with-openai.html)). ## The response Dropbox pushed back publicly. CEO Drew Houston replied directly to Vogels, writing that the toggle only gates access to Dropbox's AI features: "The third-party AI toggle in the settings menu enables or disables access to DBX AI features and functionality. Neither this nor any other setting automatically or passively sends any Dropbox customer data to a third-party AI service" ([source](https://www.theregister.com/2023/12/15/dropbox_ai_training/)). Houston added that "Third-party AI services are only used when customers actively engage with Dropbox AI features which themselves are clearly labeled" ([source](https://www.theregister.com/2023/12/15/dropbox_ai_training/)), and Vogels subsequently apologised for his critical post ([source](https://www.theregister.com/2023/12/15/dropbox_ai_training/)). On its own help/FAQ page, Dropbox set out the data-handling terms with its single named third-party AI partner, OpenAI: "Your data is never used to train their internal models, and is deleted from OpenAI's servers within 30 days" ([source](https://help.dropbox.com/view-edit/privacy-settings-dropbox-ai)). The same page stated that "All data shared with our third-party AI partners is deleted within 30 days" ([source](https://help.dropbox.com/view-edit/privacy-settings-dropbox-ai)) and that "we won't let our third-party partners train their models on our user data without consent" ([source](https://help.dropbox.com/view-edit/privacy-settings-dropbox-ai)). CNBC independently quoted the FAQ — that for OpenAI the data "is never used to train their internal models" and that documents "are stored there for up to 30 days" ([source](https://www.cnbc.com/2023/12/13/how-to-stop-dropbox-from-sharing-your-personal-files-with-openai.html)) — and The Stack quoted the same clarification ([source](https://www.thestack.technology/dropbox-openai-ai-toggle-werner-privacy/)). ## What this is — and isn't This is a **clarification / denial plus a settings-UX response**, not a confirmed reversal of a training practice. Dropbox's stated position is that it never trained models on this data, so there is no admitted before-state of training to undo. The factual friction the coverage flagged — that the toggle was on by default (CNBC) even though Dropbox says the toggle itself does not transmit data (Houston) — is about visibility and consent UX, not a settled finding that files were used for training ([source](https://www.cnbc.com/2023/12/13/how-to-stop-dropbox-from-sharing-your-personal-files-with-openai.html)). Whether Dropbox later turned the default off, or merely hid/reworded the setting, is not established on this record and is left as an open confirmation item. **Weakest load-bearing source.** The core data-handling terms — "never used to train their internal models" and "deleted within 30 days" — originate from Dropbox's own help/FAQ page (Tier 1 first-party). CNBC and The Stack (Tier 2) quote that same page rather than independently auditing OpenAI's retention behaviour, so no neutral source verifies that OpenAI actually deletes the data within 30 days; the newsrooms corroborate what Dropbox *said*, not what OpenAI *does*. The account above restates only what Dropbox and the cited newsrooms put on record. ## How this was verified - **Method:** Every quoted clause was bound verbatim to a Wayback capture of the cited source. Dropbox's first-party help/FAQ page (capture `20231214105625`), The Register (capture `20231217110126`), CNBC (capture `20231214211345`) and The Stack (capture `20231215130132`) were each decoded and searched for the exact quoted strings; all bind. First-party origin (Dropbox's help page) is not counted toward independent corroboration — the three Tier-2 newsrooms are. - **Date verified:** 2026-08-09. - **Ceiling / what green needs:** This page is held at amber `pending`. Green would require an on-the-record Dropbox confirmation (Corporate Communications / Legal) of the exact statement and of whether any default or behaviour actually changed, or an independent audit of the 30-day-deletion / no-training terms — not the subject confirming its own numbers, but the public record demanding more. No numeric client-outcome is claimed. ## Sources 1. Dropbox · "Dropbox AI and your privacy" (first-party help/FAQ page) · captured 2023-12-14 · **Tier 1** (first-party primary) · https://help.dropbox.com/view-edit/privacy-settings-dropbox-ai 2. The Register (Thomas Claburn) · "Dropbox reassures customers AI isn't pilfering their data" · 2023-12-15 · **Tier 2** (independent newsroom) · https://www.theregister.com/2023/12/15/dropbox_ai_training/ 3. CNBC · "How to stop Dropbox from sharing your personal files with OpenAI" · 2023-12-13 · **Tier 2** (independent newsroom) · https://www.cnbc.com/2023/12/13/how-to-stop-dropbox-from-sharing-your-personal-files-with-openai.html 4. The Stack · "Dropbox's AI integration with OpenAI rattles customers" · 2023-12-14 · **Tier 2** (independent newsroom) · https://www.thestack.technology/dropbox-openai-ai-toggle-werner-privacy/ ## Related case files - [Adobe added an explicit "we don't train generative AI on customer content" statement after backlash (2024)](/stories/adobe-terms-of-use-ai-training-clarification-added-after-backlash-2024/) — the closest sibling: a SaaS vendor adding a clarifying no-training statement under pressure rather than reversing a practice. - [Zoom reversed Terms-of-Service AI-training language over customer content after backlash (2023)](/stories/zoom-terms-of-service-ai-training-customer-content-reversed-after-backlash-2023/) — same month-adjacent pattern, but an actual ToS reversal rather than a clarification. - [Slack updated its AI privacy principles after user backlash over ML training (2024)](/stories/slack-ai-privacy-principles-updated-after-user-backlash-ml-training-opt-out-2024/) — the same opt-out/policy-language response in a workplace tool. - [WeTransfer removed an AI-training clause from its terms after backlash (2025)](/stories/wetransfer-ai-training-clause-terms-removed-after-backlash-2025/) — a file-transfer service walking back terms read as AI-training consent.