Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

All issues

'Not training — today': lingering skepticism over Dropbox's AI data assurances

2023–2026 (ongoing)

MediumStatus: OngoingProduct: Dropbox AI / Dropbox DashYear: 2025

Dropbox repeatedly assures users that AI features do not train on their data and that content is deleted within 30 days — but because these are revocable policy promises layered over server-side access rather than technical guarantees, security commentators remain skeptical that the assurances will hold.

What happened

Since the 2023 OpenAI-toggle controversy, Dropbox has leaned on a consistent set of assurances about its AI features: that customer data shared with its AI partner is not used to train or fine-tune the partner's models, that such data is deleted within roughly 30 days, and that for Dash for Business it uses self-hosted AI by default so content stays within Dropbox's trust boundary. These statements are specific and, as far as can be verified, accurate as written.

The persistent skepticism is structural rather than an accusation of present wrongdoing. Security commentator Bruce Schneier summarized the concern in the title of his 2023 analysis — 'OpenAI Is Not Training on Your Dropbox Documents — Today' — making the point that policy commitments can change, that they are not the same as a technical guarantee, and that they sit atop Dropbox's existing server-side access to user files (Dropbox holds the keys and there is no end-to-end encryption for ordinary accounts). As Dash expands to index browser history and content across connected third-party apps, the volume and sensitivity of data covered by these revocable assurances grows, and so does the gap between 'we promise not to' and 'it is impossible for us to.' That gap — not any proven breach of the promises — is what keeps privacy-conscious users and regulators watchful.

Impact

Dropbox's AI-data assurances function only as long as the company and its partners choose to honor them and do not change the terms, which leaves privacy-conscious users dependent on trust rather than enforceable technical limits. As Dash indexes ever more — browser history, connected-app content — the consequences of any future policy change or lapse widen. The unresolved tension between Dropbox's reassurances and the absence of zero-knowledge guarantees keeps the company under scrutiny and shapes whether enterprises and individuals will entrust it with AI-grade access to their data. This is a developing, unsettled debate.

Dropbox's Response / Official Position

Dropbox states that data shared with its third-party AI partner (OpenAI) is not used to train that partner's models and is deleted within about 30 days, that Dash for Business uses self-hosted AI by default to keep data within Dropbox's trust boundary, and that data is never used to build generative AI models without explicit consent. It publishes privacy FAQs, a Dash security architecture whitepaper, and trust-center documentation describing these controls.

Sources

Related guides

Spot an error, or have a source to add?
Report an error / suggest update

Related issues

9 sources
HighApproximately 5,000 accounts; files accessed in fewer than a third (about 1,500 by 9to5Mac's arithmetic)

The 2026 Lenovo ID sign-in flaw: ~5,000 Dropbox accounts entered without a Dropbox password

A flaw in how Lenovo verified account-holder email addresses let an attacker register a Lenovo ID on a victim's email, and Dropbox's Lenovo ID sign-in link then trusted that identity without ever asking for a Dropbox password — reaching roughly 5,000 accounts.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation

In an 8-K filed May 26, 2026, Dropbox disclosed that co-founder Drew Houston would step back as CEO after 19 years, with the Board appointing Ashraf Alkarmi — its General Manager, Core — as Co-Chief Executive Officer effective that date, ahead of Alkarmi becoming sole CEO and Houston moving to executive chairman 'following a transition period.' The handoff arrives as AI upends the software era Dropbox grew up in and the company's revenue sits near flat.

Product Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox's Q1 and Q2 2026 results both kept total reported revenue growth under 1% year-over-year, the company refinanced debt and repurchased hundreds of millions of dollars in stock over the same six months, and the period closed with a co-CEO handoff, a new product chief, and a routine, tax-related insider stock disposition reported by the Motley Fool.

Pricing & Business PracticesCurrent / Ongoing Issues (2024–2026)
Read documentation

ConsentFix, an OAuth-consent phishing technique first documented by Push Security in December 2025 and reported on independently through mid-2026, delivers its Microsoft 365 lures through trusted file-hosting platforms — reporting names both Dropbox and DocSend (a Dropbox company) as hosts for the password-protected files attackers use to get past mail filters.

Security Incidents & Data BreachesCurrent / Ongoing Issues (2024–2026)
Read documentation