Trust

AI data handling

How AI features process customer content — which providers see what, for how long, and what you can switch off.

The short version

Content is sent to an AI provider only when a user actively clicks an AI feature. Nothing is sent in the background.

No AI provider trains on Agendaflow customer content — excluded by the providers' API/commercial terms.

Providers may retain API inputs/outputs up to ~30 days for abuse monitoring, then delete. We state this openly rather than hiding it.

Uploaded files (e.g. a strategy pre-read) are never sent to AI providers; they stay in our EU database. Only agenda text a user actively submits is processed.

AI can be switched off per agenda. The switch is enforced server-side, before any provider call — a disabled agenda's content cannot reach any AI provider.

Our AI telemetry stores metadata only (feature, model, token counts, duration) — never prompt or response content.

Providers

AnthropicPrimary

Used forAll AI text generation
Training on content?No — excluded by commercial API terms
RetentionUp to ~30 days (abuse monitoring), then deleted

OpenAI

Used forEmbeddings only (semantic exercise search) — query text, never full agendas
Training on content?No — API data excluded from training
RetentionUp to ~30 days

OpenRouterFailover only

Used forRoutes requests to Anthropic models only if Anthropic's API is unavailable
Training on content?No — account-level Zero-Data-Retention routing blocks providers that retain or train
RetentionZero retention on compliant endpoints

Controls available to your organisation

Per-agenda AI disable

Finer-grained than account-level switches.

Usage caps and rate limits

AI usage caps per plan; all AI endpoints rate-limited.

EU residency for stored content

Supabase, Frankfurt. AI processing is transient, per-request, US-based under Standard Contractual Clauses.