AI data handling
How AI features process customer content — which providers see what, for how long, and what you can switch off.
The short version
Content is sent to an AI provider only when a user actively clicks an AI feature. Nothing is sent in the background.
No AI provider trains on Agendaflow customer content — excluded by the providers' API/commercial terms.
Providers may retain API inputs/outputs up to ~30 days for abuse monitoring, then delete. We state this openly rather than hiding it.
Uploaded files (e.g. a strategy pre-read) are never sent to AI providers; they stay in our EU database. Only agenda text a user actively submits is processed.
AI can be switched off per agenda. The switch is enforced server-side, before any provider call — a disabled agenda's content cannot reach any AI provider.
Our AI telemetry stores metadata only (feature, model, token counts, duration) — never prompt or response content.
Providers
AnthropicPrimary
OpenAI
OpenRouterFailover only
| Provider | Used for | Training on content? | Retention |
|---|---|---|---|
| AnthropicPrimary | All AI text generation | No — excluded by commercial API terms | Up to ~30 days (abuse monitoring), then deleted |
| OpenAI | Embeddings only (semantic exercise search) — query text, never full agendas | No — API data excluded from training | Up to ~30 days |
| OpenRouterFailover only | Routes requests to Anthropic models only if Anthropic's API is unavailable | No — account-level Zero-Data-Retention routing blocks providers that retain or train | Zero retention on compliant endpoints |
Controls available to your organisation
Per-agenda AI disable
Finer-grained than account-level switches.
Usage caps and rate limits
AI usage caps per plan; all AI endpoints rate-limited.
EU residency for stored content
Supabase, Frankfurt. AI processing is transient, per-request, US-based under Standard Contractual Clauses.