Skip to content
Back to Setup Guides
Essential

Safe Setup Guide: Claude for Legal Work

How to configure Claude before using it for legal work in England and Wales: the model training setting, memory, projects, what not to paste, and how to check output

Setup time: 10 minutes
By Rory CollinsLast updated: 29 September 2026

Privacy & Professional Conduct Notice

This guide helps you configure Claude safely, but you remain responsible for complying with the SRA Standards and Regulations. Never input confidential client information without proper safeguards.

Overview

Claude is made by Anthropic. On the personal plans (Free, Pro and Max), Anthropic will use your chats to improve its models if you allow it, and there is a setting that controls this. On the Team and Enterprise plans it does not train on your content by default.

An earlier version of this guide said Claude never trains on conversations. That is no longer an accurate description of the personal plans. Check the setting in Step 2.

Every vendor fact below was checked against Anthropic's own pages on 29 September 2026. The pages are listed under "Sources checked" at the end of this guide. Settings and prices change, so follow the links before you rely on them.

Setup time: about 10 minutes Suitable for: sole practitioners and firms of any size, within the limits set out below


Plans and prices

Anthropic's pricing page showed prices in US dollars when viewed from the UK on 29 September 2026, and says they do not include applicable tax. No price in pounds was found on the page checked. Check the amount at checkout.

PlanPrice Anthropic publishesNotes
Free$0Personal plan. Up to five projects
Pro$17 a month on an annual subscription ($200 billed up front), or $20 billed monthlyPersonal plan
MaxFrom $100 a monthPersonal plan
TeamStandard seat: $20 per seat a month billed annually, or $25 billed monthly. Premium seat: $100 or $125For teams of 2 to 150
Enterprise$20 per seat a month, billed annually, plus usage at API ratesAdds audit logs, custom data retention controls and role-based access

What Anthropic says about your data

Free, Pro, Max (personal)Team and Enterprise
Used to train modelsYes, if you allow it in your privacy settingsNot by default
Feedback (thumbs up or down)The whole conversation is stored for up to 5 years and may be used for trainingSame, unless an owner turns off the "Rate chats" setting
Deleted conversationsRemoved from history immediately; deleted from back-end storage within 30 daysSame
Retention if training is allowedUp to 5 years, in de-identified formNot applicable by default
Flagged for a usage policy violationInputs and outputs kept for up to 2 yearsSame
Where content is storedNot stated for personal plans. Anthropic says it may process data in different countriesStored in the US. Traffic may be routed to the US, Europe, Asia and Australia by default

Two points that are easy to miss:

  • Safety review is separate from the training setting. Anthropic says conversations flagged by its safety classifiers may still be used to improve its trust and safety models, whatever your setting.
  • There is no UK or EU storage option on the pages checked. Anthropic's article on server locations says commercial customer data is stored in the US. Its article for personal plans says that when it transfers data outside the UK it relies on adequacy decisions and standard contractual clauses.

Step 1: Use a work account

  1. Create the account with your work email address, not a personal one.
  2. Keep client work out of any personal Claude account.

If your firm has a Team or Enterprise plan, use that. Owners control the organisation's data and privacy settings.


Step 2: Check the model training setting (personal plans)

On desktop or in a browser:

  1. Select your name to open the settings menu.
  2. Select Settings.
  3. Select Privacy.
  4. Under Help improve our AI models, turn the toggle off.

On mobile the path is the same: your name, Settings, Privacy.

Anthropic says that once the setting is off it will not use new chats for future model training, and will stop using previously stored chats in future training runs. Data already included in training that has started, or in models already trained, stays there.

Do not press the thumbs up or thumbs down buttons on a conversation you would not want stored for 5 years.


Step 3: Decide what to do about memory

Claude can remember context from your chats and carry it into new conversations. Anthropic says memory is on by default on Free, Pro and Max, and off by default on Team and Enterprise, where an owner can turn it on.

For legal work, memory creates a risk of information from one matter appearing in another.

  1. Go to Settings, then Memory.
  2. Turn off Generate memory from chats. You are offered two options:
    • Pause memory keeps existing memories but stops Claude using them or making new ones.
    • Reset memory permanently deletes all memories, including project memories.
  3. On paid plans, consider turning off Search and reference chats in the same place.

Step 4: Use projects to keep matters apart

A project is a self-contained workspace with its own chat history, its own knowledge base and its own instructions. Anthropic says each project has a separate memory space, and that context is not shared across chats within a project unless it has been added to the project's knowledge base.

  1. Create a project and give it a name that does not identify the client. Use a matter reference from your own system if you need one.
  2. Select Set project instructions and add the rules you want Claude to follow.
  3. On Team and Enterprise plans, choose the visibility. Keep it private limits the project to you and the members you invite.

Example project instructions:

You are assisting a solicitor in England and Wales with contract review.

- Apply the law of England and Wales unless told otherwise.
- Never invent a case, statute, rule number or quotation.
- If you are not certain an authority exists, say so and mark it "VERIFY".
- Group your findings as high, medium and low risk.
- Ask a question if the instructions are unclear.

Anthropic is rolling out a new version of projects, starting with Claude Code. Its help page says existing projects keep working as they do today.

A project separates matters from each other inside Claude. It does not change where the content is stored or who at Anthropic can access it.


Step 5: Use incognito chats for anything you do not want kept in history

Select the ghost icon at the top right when starting a new chat outside a project.

Anthropic says an incognito chat:

  • is not saved to your chat history or to Claude's memory
  • is not used for training
  • is retained for 30 days by default, or longer under an Enterprise organisation's retention setting
  • on Team and Enterprise plans, is included in the data exports available to account owners

Incognito mode is not available inside a project. An incognito chat is still sent to Anthropic and held for 30 days, so it is not a way to make confidential material safe to paste.


Your professional duties

This section summarises published rules and guidance. It is not legal advice, and it has not yet been reviewed by a solicitor.

  • Confidentiality. Paragraph 6.3 of the SRA Code of Conduct for Solicitors, RELs, RFLs and RSLs requires you to keep the affairs of current and former clients confidential unless disclosure is required or permitted by law or the client consents.
  • Competence. Paragraph 3.2 requires the service you provide to be competent, and paragraph 3.3 requires you to keep your professional knowledge and skills up to date.
  • Supervision. Under paragraph 3.5, where you supervise or manage others you remain accountable for the work carried out through them.
  • Not misleading anyone. Paragraph 1.4 says you do not mislead or attempt to mislead your clients, the court or others.
  • Responsibility for output. The SRA's Risk Outlook report on AI (20 November 2023) says you "remain responsible and accountable for the outputs from AI you are using".
  • Law Society guidance. "Generative AI – the essentials" says that if you are using a free, online generative AI service where you have no operational relationship with the vendor other than use, you should not put any confidential data into the tool. It also advises carrying out due diligence on the supplier, and being able to say where data is processed, who processes it, how and where it is stored, and who has access to it.
  • Data protection. Where a prompt contains personal data, the UK GDPR and the Data Protection Act 2018 are relevant. The Information Commissioner's Office says a restricted transfer of personal data outside the UK must be covered by UK adequacy regulations, appropriate safeguards or an exception. Anthropic says commercial customer data is stored in the US.

Follow your firm's own AI and information security policy where it is stricter than this guide.


What not to put into Claude

On a personal plan, treat Claude as a tool with which you have no contract beyond its terms of use. Do not enter:

  • client names, or facts that would identify a client or matter
  • privileged communications or advice
  • personal data about anyone, including health information and financial details
  • National Insurance numbers, passport numbers or bank account details
  • the terms of a confidential settlement
  • anything covered by a confidentiality agreement or undertaking

Anthropic's own help page recommends being thoughtful about sharing financial information, health records, passwords and confidential business or personal documents.

Use placeholders instead:

  • Identifying: "Sarah Johnson's employment with TechCorp Ltd was terminated on 1 March 2026"
  • Safer: "An employee's contract with a technology company was terminated"

On a Team or Enterprise plan, what may go in is a decision for your firm, made after due diligence on the contract and the data processing addendum.


Checking output

Claude can produce authorities that do not exist and misstate ones that do. Do not rely on it to tell you when it is unsure. Before relying on anything it produces:

  • Cases: find every case in a law report or on a service such as Westlaw UK, Lexis+ UK, BAILII or The National Archives' Find Case Law, and read it
  • Legislation: check the text and whether it is in force, for example on legislation.gov.uk
  • Jurisdiction: confirm the law is that of England and Wales, not Scotland, Northern Ireland or another country
  • Quotations: check every quotation against the source
  • Dates, names and figures: check each against your own documents
  • Currency: confirm the authority has not been overruled, amended or repealed

The Law Society's guidance says that for documents going to court you must review final versions to make sure all citations are verified, and that the court expects to impose severe sanctions for the misuse of AI in legal research or court documents other than in exceptional circumstances.

Asking Claude whether a case is real is not a check. The SRA's report says not to trust an AI system to judge its own accuracy.


If client information goes in by mistake

  1. Delete the conversation. Anthropic says it is removed from back-end storage within 30 days.
  2. If memory was on, review what was saved in Settings, then Memory.
  3. Tell the person your firm's policy names, usually the compliance officer for legal practice (COLP) or the data protection lead.
  4. Record what was entered, when, and on which plan.

The ICO says a notifiable personal data breach must be reported to it without undue delay and not later than 72 hours after you become aware of it. Whether an incident is notifiable is for your firm to assess. Paragraph 7.11 of the SRA Code requires you to be honest and open with clients if things go wrong.


Quick checklist

Before first use

  • Account created with a work email address
  • "Help improve our AI models" turned off (personal plans)
  • Memory paused or reset
  • One project per matter, named without identifying the client
  • Your firm's AI policy read

Every conversation

  • Working in the right project
  • No client names, identifying facts or personal data
  • No thumbs up or thumbs down on sensitive conversations
  • Every authority checked against its source
  • Conversation deleted when no longer needed

Sources checked

All read on 29 September 2026.

Anthropic

Rules and guidance


Need help?

If you have a question about this guide, or find that a setting has moved, contact hello@counsel.directory.

Review status: this guide has not yet been reviewed by a solicitor.


Disclaimer: This guide is general information about configuring a software product. It is not legal advice and it is not advice on your professional obligations. You remain responsible for complying with the SRA Standards and Regulations, data protection law and your firm's policies. Check with your firm's compliance and IT teams before using a new tool for client work.

Tags

claudesetupprivacysecuritybeginner
Quick Reference
Tool
Claude
Setup Time
10 minutes
Trains on Data
No (if configured)
Data Residency
US storage; processing may be routed through other regions
Enterprise Option
Available
Priority
Essential