Dropbox Watchdog

Search issues

Search the Dropbox Watchdog archive

Common question

Does Dropbox use my files to train AI?

Dropbox's own AI Principles page says no in as many words: "We will not build generative AI models using customer content without consent." The catch, as this archive's own review of Dropbox's AI-data assurances has found, is that this is a policy promise rather than a technical impossibility — Dropbox holds the encryption keys to standard accounts and can read file content server-side — and that AI features Dropbox does turn on, like the 2023 "third-party AI" setting, do send file content to an outside company (Dropbox named OpenAI) whenever a user actually invokes them.

Dropbox publishes a standalone "AI Principles" page, last updated April 4, 2025, and its central commitment is direct: "Customer trust and the privacy of their data are our foundation. We will not build generative AI models using customer content without consent." The same page adds a second, narrower promise — "We will use AI when it helps us deliver better experiences for our customers. At no point, will we use it as a means to sell customer data" — plus a transparency pledge, "We will provide clear explanations of how our generative AI experiences work so that our customers understand how these technologies can benefit them," and a commitment that AI-powered experiences will "remain under human direction." Those are Dropbox's own words on training; the rest of the page is broader language about fairness, inclusiveness, and safety.

Dropbox's Dash AI-info page repeats the no-training line word for word — "Dropbox will not build generative AI models using customer content without consent" appears twice, once under "Data Handling" and again under "Trust & Safety Signals" — and adds two narrower claims: "Data access is limited to authorized users and permitted sources," and "Connected apps and data sources are opt-in and user-authorized." What that page does not do is name which third-party AI providers process file content, what those providers are and are not contractually permitted to do with it, or how long they retain it. The help-center page Dropbox previously published on its AI privacy settings is no longer online, and as of September 2026 this archive found no current Dropbox help page stating which providers receive file content, what they may do with it, or how long they keep it.

Where the AI toggle lives today, and what it defaults to, is likewise not documented on any Dropbox help page this archive could find in September 2026. What is documented, from this archive's own review of the episode that made the setting famous, is the history — when the control first appeared in December 2023 it was called "third-party AI," and it shipped switched on by default for most of the world, with only the EU, UK, and Canada opted out and the United States and others opted in by default. Whether today's equivalent setting still defaults to on outside those regions is not something Dropbox's current public pages state.

That December 2023 default-on setting is what put "does Dropbox train on my files" on the map in the first place. As this archive's own record of the episode lays out, the toggle governed Dropbox's experimental AI search and Q&A features, which could send file contents to OpenAI when a user actively used them; a widely shared warning post was viewed millions of times and the story was picked up by outlets including CNBC, leading many users to conclude their private documents were already being fed to OpenAI. Dropbox's response was that no data was sent "automatically or passively" — it moved only when a user invoked an AI feature — and a spokesperson said data shared with OpenAI was not used to train or fine-tune its models and was deleted within 30 days; CEO Drew Houston apologized for the confusion on X. Security commentator Bruce Schneier accepted that technical clarification but titled his own write-up "OpenAI Is Not Training on Your Dropbox Documents — Today," and this archive's assessment is that the resulting skepticism has stayed structural rather than accusatory ever since, because assurances like the 30-day deletion window are "revocable policy promises layered over server-side access rather than technical guarantees."

That server-side access is the real reason the promise can only ever be a promise. Dropbox holds the encryption keys to standard accounts and decrypts files on its own servers — a design CEO Drew Houston himself called "a trade-off between usability/convenience and security" when he responded to Edward Snowden's 2014 privacy criticism, as this archive's entry on that exchange records — and that same server-side access is what makes full-text search, previews, and any AI feature technically possible to begin with. So the accurate reading of "does Dropbox use my files to train AI" is not "it can't" — it can — it's "it says it chooses not to, and has put contracts and opt-in toggles around that choice." Those toggles are the same kind of broad, by-design access this archive's answer on the Dash Chrome extension's permissions (/questions/dash-chrome-extension-permissions) documents for a different Dropbox AI surface: wide technical reach, with user trust as the enforcement mechanism.

This answer is informational, not legal or security advice. Dropbox Watchdog is independent and not affiliated with Dropbox, Inc.

Related entries in the archive

Users discovered a 'third-party AI' setting that was switched on by default for most of the world, fueling fears that Dropbox was quietly feeding personal files to OpenAI. Dropbox said no data was passively sent and that files were not used to train models.

Privacy & Encryption ConcernsProduct Changes & User BacklashCurrent / Ongoing Issues (2024–2026)
Read documentation

Dropbox repeatedly assures users that AI features do not train on their data and that content is deleted within 30 days — but because these are revocable policy promises layered over server-side access rather than technical guarantees, security commentators remain skeptical that the assurances will hold.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)
Read documentation

Dash connects to Google Workspace, Microsoft 365, Slack, Notion and more, and routes queries through large language models — leaving users to trust Dropbox's contractual assurances that connected and indexed data is not used to train third-party AI models.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Developer, API & Platform
Read documentation

Because Dash can be downloaded and set up with 'no sales or IT required,' an individual employee can connect and index an organization's apps and browser history without administrator oversight — recreating the shadow-IT data-governance risk that earlier consumer Dropbox use posed to enterprises.

Privacy & Encryption ConcernsCurrent / Ongoing Issues (2024–2026)Account Lockouts & Support Failures
Read documentation

Responding to criticism of Dropbox's lack of zero-knowledge encryption, CEO Drew Houston framed the fact that Dropbox can access users' files as a deliberate 'trade-off between usability/convenience and security.'

Privacy & Encryption Concerns
Read documentation

Dropbox encrypts files at rest, but the encryption keys belong to Dropbox, not the user. This server-side model — chosen to enable deduplication, previews, and search — means the company can read user files, the root cause critics return to again and again.

Privacy & Encryption Concerns
Read documentation