Skip to content

Data Privacy & Training Policies ​

Control how your data is handled by AI providers with transparent training and retention policies.

Overview ​

Different AI providers have different policies regarding:

  • Whether they use API data to train their models
  • How long they retain your prompts and responses
  • Whether you can opt out of data usage

VeriPrompt tracks these policies for each provider, enabling you to:

  • Filter providers based on privacy requirements
  • Document compliance for audits
  • Make informed decisions about data handling

Data Training Policy ​

Each provider/model is classified by how it handles training data:

PolicyDescriptionExample
NO_TRAININGProvider never uses API data for trainingAnthropic API
OPT_OUT_AVAILABLETraining is default but can be disabledOpenAI (with org settings)
OPT_OUT_REQUIREDMust explicitly opt out per requestSome enterprise tiers
TRAINING_ENABLEDData may be used for trainingConsumer-tier APIs
UNKNOWNPolicy not verifiedNew or unverified providers

Privacy Tiers ​

Data retention is classified into tiers:

TierDescriptionTypical Use Case
ZERO_RETENTIONNo data stored after responseHighest security workloads
MINIMAL_RETENTIONBrief storage for abuse monitoringPrivacy-sensitive applications
STANDARD_RETENTIONTypical 30-day retentionGeneral business use
EXTENDED_RETENTIONLonger retention for complianceAudit trail requirements
UNKNOWNRetention not verifiedNew providers

Provider Fields ​

Each provider and model configuration includes:

FieldDescription
dataTrainingPolicyTraining data usage classification
privacyTierData retention classification
dataRetentionDaysSpecific retention period (if known)
privacyPolicyUrlLink to provider's privacy policy
trainingOptOutUrlLink to opt-out instructions

Use Cases ​

1. Compliance Filtering ​

Route sensitive prompts only to NO_TRAINING providers:

json
{
  "hardConstraints": {
    "privacy": {
      "dataTrainingPolicy": ["NO_TRAINING"],
      "maxRetentionDays": 0
    }
  }
}

2. Healthcare/HIPAA Workloads ​

Ensure data is never used for training:

json
{
  "geoFenceRules": {
    "allow": { "countries": ["US"] }
  },
  "hardConstraints": {
    "privacy": {
      "dataTrainingPolicy": ["NO_TRAINING", "OPT_OUT_AVAILABLE"],
      "privacyTier": ["ZERO_RETENTION", "MINIMAL_RETENTION"]
    }
  }
}

3. Privacy-First Routing ​

Prioritize providers with better privacy practices:

json
{
  "softPreferences": {
    "privacyWeight": 0.8
  }
}

Known Provider Policies ​

ProviderTraining PolicyTypical Retention
AnthropicNO_TRAININGMinimal
OpenAI (API)OPT_OUT_AVAILABLE30 days
Google GeminiVaries by tierVaries
Azure OpenAINO_TRAININGConfigurable

Note: Policies change. Always verify with the provider's current documentation.

Best Practices ​

  1. Verify Policies: Check provider documentation for current policies
  2. Default to Restrictive: When in doubt, assume UNKNOWN policies use data
  3. Document Decisions: Keep records of which providers were used for compliance
  4. Regular Audits: Review provider policies quarterly
  5. Use Routing Policies: Automate privacy requirements in routing rules

Viewing Provider Privacy Settings ​

In the VeriPrompt dashboard:

  1. Navigate to Settings > AI Providers
  2. Click on any provider to view details
  3. Check the Privacy & Compliance section
  4. Review training policy and retention settings

Updating Provider Policies ​

Admins can update provider privacy settings:

  1. Go to Settings > AI Providers
  2. Select the provider to edit
  3. Update the privacy fields:
    • Data Training Policy
    • Privacy Tier
    • Retention Days
    • Policy URLs
  4. Save changes

Learn More ​