from line 1
11# How Claude Science works with your data
22
3> What Anthropic receives from Claude Science, what stays on members' computers, and what Enterprise organizations can retrieve through the Compliance API.
3> What Claude Science keeps on your computers, what it sends to Anthropic and how long Anthropic keeps it, who can access it, Anthropic's no-training and ownership commitments, and the controls available to your organization.
44
5Claude Science is a local-first application. Conversation history and artifacts are stored on the member's computer, and Anthropic doesn't sync them to the member's Claude account or to other devices. Anthropic does receive the prompts and responses the app exchanges with Claude, and handles them under its standard retention and Trust & Safety policies. For Enterprise organizations with the Compliance API enabled, Anthropic also retains those exchanges as session transcripts that the organization can retrieve; [Compliance API coverage](#compliance-api-coverage) explains what they contain. The following sections cover each of these, plus remote compute, connectors, and customer-managed encryption keys.
5Claude Science is client-side software that your organization installs and runs on computers it controls, and Anthropic provides the Claude models the app calls. This page covers what that means for your research data.
66
7## Model training and ownership of your work
8
9On Team and Enterprise plans the [Commercial Terms of Service](https://www.anthropic.com/legal/commercial-terms) apply. Under them Anthropic "may not train models on Customer Content from Services," and, as between the parties and to the extent permitted by applicable law, your organization "retains all rights to its Inputs" and "owns its Outputs," including the analyses, code, and results your researchers produce with Claude Science. Anthropic may use content to improve its models only when a member gives express consent, by providing feedback, which includes a copy of that conversation, or when your organization otherwise expressly chooses to allow it (see [Is my data used for model training?](https://privacy.claude.com/en/articles/7996868-is-my-data-used-for-model-training)). To turn off the ability for your researchers to provide feedback, an Owner can turn off the **Rate chats** toggle under **Organization settings** > **Data and privacy**.
10
11On Pro and Max plans the [Consumer Terms of Service](https://www.anthropic.com/legal/consumer-terms), [Anthropic Privacy Policy](https://www.anthropic.com/legal/privacy), and your Claude privacy settings in the Settings panel apply (see [Legal and compliance](/docs/claude-science/legal-and-compliance)).
12
13## Where Claude Science data lives
14
15| Where | What |
16| --------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
17| The computer running Claude Science | Conversation history, project files and artifacts, saved memory, settings, and stored credentials, in a local folder Anthropic doesn't host or sync (see [Manage Claude Science on devices](/docs/claude-science/manage-on-devices)) |
18| Anthropic | The items listed under [What Anthropic receives](#what-anthropic-receives) |
19| Services your organization or members connect | Jobs, files, and queries sent to your SSH hosts, your Modal account, scientific model endpoints, cloud storage, and the external services that local (Featured and custom) connectors, sandboxed code, and remote jobs call, directly from the computer or your own compute and without passing through Anthropic (see [Admin controls](/docs/claude-science/admin-controls#organization-settings)) |
20
21Sign-in tokens and the credentials members store for compute and cloud storage are encrypted on the computer, and the rest of the local folder relies on operating-system permissions, so apply your full-disk encryption and device management policies to it.
22
723## What Anthropic receives
824
9Each time the app calls Claude, the prompt and Claude's response travel to Anthropic's servers and are logged under Anthropic's standard retention policy for model traffic (see How long do you store my organization's data in the Privacy Center), the same policy that applies to other Claude products. If your organization uses [customer-managed encryption keys (CMEK)](https://platform.claude.com/docs/en/manage-claude/cmek), these model-call logs are encrypted under your key (see [Customer-managed encryption keys](#customer-managed-encryption-keys) below). Your organization's Custom Data Retention setting doesn't change how long these model-call logs are kept. It does apply to the session transcripts that Anthropic keeps for Enterprise organizations with the Compliance API enabled, described in [Compliance API coverage](#compliance-api-coverage). The app also sends product-usage telemetry (event counts and timings, not conversation content) and, when it runs into an error, a redacted error report (the error type and its location in Claude Science's own code, not conversation content or research data). Both are turned off by the same [device configuration](/docs/claude-science/manage-on-devices#telemetry) setting.
25The app sends the following to Anthropic, over TLS and signed in with the member's Claude account (see [Network requirements](/docs/claude-science/network-requirements#app-connections) for the domains):
1026
11## Compliance API coverage
27* **Requests to Claude** every time Claude responds, carrying the conversation so far, including the member's prompts, the contents of files Claude has read (PDFs included), code and command output, connector results, images Claude is shown, and recalled memory facts. Anthropic keeps these as model-call logs (see [What Anthropic keeps and for how long](#what-anthropic-keeps-and-for-how-long)).
28* **Web search queries**, run by Anthropic's web search service through a third-party search provider listed among [Anthropic's subprocessors](https://www.anthropic.com/subprocessors).
29* **Dictation audio**, streamed to Anthropic's speech-to-text service only while a member dictates. If the app can't use that service while Claude Science is open in a browser such as Chrome or Edge, it falls back to the browser's built-in speech recognition, and that browser's vendor then processes the audio.
30* **Feedback**, only when a member sends it, consisting of the rating, the comment, and a copy of that conversation (members are reminded before submission) with known credential formats and email addresses redacted. Not accepted from organizations with HIPAA compliance or customer-managed encryption keys.
31* **Custom skills a member publishes**, stored with the member's claude.ai skills.
32* **Usage telemetry and error reports**, which carry app, device, and timing data, plus account and organization identifiers on telemetry events, but no conversation content, file contents, or file names (see [Telemetry](/docs/claude-science/manage-on-devices#telemetry) for the device setting that turns them, and feedback, off).
33* **Calls to connectors Anthropic hosts** from your claude.ai connector directory, which pass through Anthropic's connector service as in claude.ai, plus routine account, settings, and update traffic.
1234
13If your organization is on an Enterprise plan and has the [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api) enabled, your compliance team can retrieve transcripts of members' Claude Science sessions through it. Coverage of Claude Science sessions is in beta.
35## What Anthropic keeps and for how long
1436
15Anthropic captures a session only while the Compliance API is enabled for your organization and the member is signed in with their Claude Enterprise account. Transcripts aren't available for sessions that ran before capture began for your organization, although such sessions can still appear in the session list with their content marked unavailable. Anthropic records each session on its servers as the app's requests reach the Claude API, without installing anything extra on the member's computer or capturing anything beyond the requests the app already sends to Claude. Sessions in organizations with [HIPAA compliance enabled](/docs/claude-science/enable-claude-science#hipaa-organizations) aren't captured, and [Retrieve session transcripts](https://platform.claude.com/docs/en/manage-claude/compliance-sessions) lists the other cases the Compliance API doesn't return.
37For Team and Enterprise organizations, Anthropic processes this data under the [Data Processing Addendum](https://www.anthropic.com/legal/data-processing-addendum), encrypted at rest and in transit. Model-call logs follow Anthropic's [commercial data retention policy](https://privacy.claude.com/en/articles/7996866-how-long-do-you-store-my-organization-s-data), including its longer retention for content flagged by automated trust and safety systems or required by law.
1638
17A transcript is reconstructed from what the app exchanged with Claude during the session: the member's prompts, Claude's responses, tool calls (including code and file content Claude wrote through them), and the text portions of tool results, including text from files that Claude read, subject to the size limits the Compliance API applies. Claude's extended thinking and the app's system prompt aren't included (a placeholder marks where the system prompt was), tool definitions and connector (MCP server) configuration are omitted, and images, PDFs, and other non-text content appear as placeholders. Content that never reached the Claude API, such as a local file the session never sent, isn't in the transcript.
39Requests to models designated [Covered Models](https://support.claude.com/en/articles/15425695-covered-models) are retained for 30 days to support Anthropic's safety work, as [Data retention practices for Covered Models](https://support.claude.com/en/articles/15425996-data-retention-practices-for-covered-models) describes. Feedback submissions are kept under the feedback terms in the same policy.
1840
19Anthropic keeps these transcripts for six years from capture by default. If your organization has set a Custom Data Retention period (in claude.ai under Organization settings > Data and privacy), that period applies to the transcripts instead, and when more than one retention period is set, the shortest applies. If your organization uses [customer-managed encryption keys (CMEK)](https://platform.claude.com/docs/en/manage-claude/cmek), the transcripts are encrypted under your key. The session endpoints are read-only, so transcripts can't be deleted through the API before they expire; see [Retention and deletion](https://platform.claude.com/docs/en/manage-claude/compliance-sessions#retention-and-deletion) for the current terms.
41## Who at Anthropic can access retained content
2042
21The Compliance API's [Activity Feed](https://platform.claude.com/docs/en/manage-claude/compliance-activity-feed) also records changes to your Claude Science organization settings, such as turning the product on or off. The [Compliance API reference](https://platform.claude.com/docs/en/api/compliance/activities/list) describes these events.
43Human review of model-call logs, published skills, or Compliance API transcripts requires a specific reason, such as reviewing content that automated safety systems flagged, responding to a security incident, or meeting a legal obligation, through a controlled path where access is restricted to personnel whose role requires it and logged as the [Data Processing Addendum](https://www.anthropic.com/legal/data-processing-addendum) describes, and content reviewed this way isn't used to train Claude models. Feedback a member chooses to send is handled separately, as [Model training and ownership of your work](#model-training-and-ownership-of-your-work) describes. [Access Transparency](https://platform.claude.com/docs/en/manage-claude/access-transparency) records don't cover the Claude apps, including Claude Science.
2244
23## Remote compute
45## Controls available to your organization
2446
25When a member chooses to connect the app to remote compute (an owned server or cloud account they control), the app sends code and data directly to that destination. That traffic doesn't pass through Anthropic, and Anthropic doesn't store it. For organizations that use customer-managed encryption keys, see [Customer-managed encryption keys](#customer-managed-encryption-keys). You can turn SSH hosts, Modal, and scientific model endpoints off for the organization under **Organization settings** > **Claude Science** (see [SSH hosts](/docs/claude-science/admin-controls#ssh-hosts), [Modal](/docs/claude-science/admin-controls#modal), and [Scientific model endpoints](/docs/claude-science/admin-controls#scientific-model-endpoints)). For setup details, see [Remote compute clusters](/docs/claude-science/remote-compute-clusters) and [Compute providers](/docs/claude-science/compute-providers) in the user documentation.
47* **Organization settings** for connectors, skills, the sandbox network allowlist, SSH hosts, Modal, model endpoints, and memory (see [Admin controls](/docs/claude-science/admin-controls)). There is no organization setting for web search, dictation, or telemetry.
48* **US-only inference** (usage-based Enterprise plans) runs model inference for Claude Science requests in the United States, as for your other Claude apps (see [Enable US-only inference](https://support.claude.com/en/articles/15422948-enable-us-only-inference-for-your-organization)).
49* **Device configuration** turns off telemetry, error reports, and feedback and relocates the local data folder (see [Manage Claude Science on devices](/docs/claude-science/manage-on-devices)).
50* **Running Claude Science next to your data**, on a Linux server or virtual machine you control, keeps datasets on your infrastructure, apart from what Claude reads into the conversation, while Claude's inference runs on Anthropic's service (see [Run on a remote Linux server](/docs/claude-science/run-on-remote-linux-server)).
51* **Usage analytics** show adoption and session metrics without conversation content (see [Monitor usage](/docs/claude-science/monitor-usage)).
2652
27## Connectors
53## Compliance API coverage
2854
29Directory connectors you publish as an admin are reached through Anthropic's hosted connector service, so your directory connector permissions and tunnels apply. Connectors a member adds locally (either running on their own computer or pointing at a custom URL) talk to their app directly, without routing through Anthropic. You can turn custom connectors off for the organization (see [Custom connectors](/docs/claude-science/admin-controls#custom-connectors)).
55On Enterprise plans with the [Compliance API](https://platform.claude.com/docs/en/manage-claude/compliance-api) enabled, your organization gets a record of Claude Science settings changes and its own read-only transcripts of members' Claude Science sessions (coverage is in beta), which are kept for your organization's own retention period (6 years by default) and, in organizations that use customer-managed encryption keys, encrypted under your key. [Retrieve session transcripts](https://platform.claude.com/docs/en/manage-claude/compliance-sessions) describes what a transcript contains and which sessions aren't captured, including those in organizations with HIPAA compliance enabled.
3056
3157## Customer-managed encryption keys
3258
from line 62
3662
3763In organizations with CMEK enabled, the app hides its response rating buttons and feedback form, as claude.ai does.
3864
39## What this means for you as an admin
65## What isn't available for Claude Science
4066
41Because conversations and artifacts live on members' computers, Custom Data Retention and Org Data Export don't reach that local data. For Enterprise organizations with the Compliance API enabled, Anthropic also keeps session transcripts captured from the app's model calls, which include file text the app sent to Claude, and a record of settings changes (see [Compliance API coverage](#compliance-api-coverage)). Device management is the control you have for local data: your device management software (such as your MDM or EDR) governs the app's local folder the same way it governs any other local application data. Identity controls (SSO, SCIM, roles) apply because sign-in goes through claude.ai. See [Admin controls](/docs/claude-science/admin-controls) for the organization settings that govern what members can connect the app to, and for what IP allowlisting and session duration cover.
67Zero data retention (a Claude Code zero-data-retention arrangement covers Claude Code sessions, not Claude Science), Enterprise Frontier Safeguards, coverage under Anthropic's Business Associate Agreement (keep protected health information out of Claude Science), and inference through a third-party cloud platform or your own cloud tenancy aren't available for Claude Science. See [Admin controls](/docs/claude-science/admin-controls#how-other-admin-settings-apply-to-claude-science) for how the other claude.ai admin settings apply to the app.
68
69## Related resources
70
71[Commercial Terms of Service](https://www.anthropic.com/legal/commercial-terms), [Data Processing Addendum](https://www.anthropic.com/legal/data-processing-addendum), [subprocessor list](https://www.anthropic.com/subprocessors), [Usage Policy](https://www.anthropic.com/legal/aup), the [Anthropic Trust Center](https://trust.anthropic.com) for certifications and security documentation, and [Admin controls](/docs/claude-science/admin-controls).
4272