Skip to content

Comment on Moonshot serves Claude instead of Kimi and collects exchanges for model training

Comments

The open question here is how is Anthropic retaining these exchanges?

If Moonshot is using the API, normally Anthropic would not retain the exchanges, at least that's the promise. If Anthropic is consistently retaining all exchanges from a class of customers because they're "flagged" but not notifying those customers, how can an average customer trust it won't happen to them?

If Moonshot is buying accounts and using those rather than the API, wouldn't they set the "no training on my data" flag in the settings so as to go undetected for longer? If so, we get back to the question of why would Anthropic be retaining the exchanges?

If Moonshot is buying accounts and using those rather than the API, wouldn't they set the "no training on my data" flag in the settings so as to go undetected for longer? If so, we get back to the question of why would Anthropic be retaining the exchanges?

I would like to briefly draw your attention to this part of the Terms of Service [0]:

We may use Materials to provide, maintain, and improve the Services and to develop other products and services, including training our models, unless you opt out of training through your account settings. Even if you opt out, we will use Materials for model training when: (1) you provide Feedback to us regarding any Materials, or (2) your Materials are flagged for safety review to improve our ability to detect harmful content, enforce our policies, or advance our safety research.

From the privacy policy [1]:

We use your personal data for the following purposes:
To prevent and investigate fraud, abuse, and violations of our Usage Policy, unlawful or criminal activity, unauthorized access to or use of personal data or Anthropic systems and networks, to protect our rights and the rights of others, to protect your safety or that of any other person, and to meet legal, governmental and institutional policy obligations;

Anthropic does offer a truly no data retention service, which is their "zero-data retention" agreement, which you have to sign and provide more documentation for than simply using either a normal consumer or API account. I doubt Moonshot did that, so by their terms, they can retain your data and use it for training if it's part of abuse prevention.

[0]: https://www.anthropic.com/legal/consumer-terms

[1]: https://www.anthropic.com/legal/privacy

Notably, those are the consumer terms. The commercial terms [1] are much stricter about what Anthropic can do. That's one of the main draws of the Team plans over the individual plans (in addition to a couple dashboards, shared skills, etc). And as you mention, you can go even stricter as an enterprise customer with a zero-data retention agreement.

If Moonshot is using thousands of accounts through some proxy service those are most likely consumer accounts governed by the weaker ToS

1: https://www.anthropic.com/legal/commercial-terms

I'm aware of that language in the terms, but I think most of us were under the (likely mistaken) impression that the safety review flagging focused on harmful content and safety (e.g., individuals discussing threatened real-world violence), not "safety" of Anthropic's intellectual property. And that it would likely result in retention of a handful of a customer's interactions, not all of them.

If the criteria for retention justifiable as safety at Anthropic are cast very broadly in actual practice, then it opens cans of worms for a lot of customers in complying with privacy regimes, customer IP protection, etc. It also raises the question of whether at least some subset of customers from certain geos (e.g., China likely, but perhaps other geos) may just automatically have everything flagged for retention, despite the terms, based on collective abuse risk flagging of their geo.

While ZDR is available, it's not available to all types of customers and is priced at a higher tier. Undoubtedly though this may be a wakeup call to some customers who didn't realize they may need ZDR to get on the ZDR bandwagon.

While ZDR is available, it's not available to all types of customers and is priced at a higher tier.

This doesn’t match my experience with their API, they turned it on with some paperwork but it wasn’t fundamentally an issue of price. It’s the same API pricing either way.

AboutSource Built by g1lg1l

Hackerly is an independent reader for Hacker News, built on the public HN API. Not affiliated with Y Combinator.