Appearance
Data Privacy & Training Policies
Control how your data is handled by AI providers with transparent training and retention policies.
Overview
Different AI providers have different policies regarding:
- Whether they use API data to train their models
- How long they retain your prompts and responses
- Whether you can opt out of data usage
VeriPrompt tracks these policies for each provider, enabling you to:
- Filter providers based on privacy requirements
- Document compliance for audits
- Make informed decisions about data handling
Data Training Policy
Each provider/model is classified by how it handles training data:
| Policy | Description | Example |
|---|---|---|
| NO_TRAINING | Provider never uses API data for training | Anthropic API |
| OPT_OUT_AVAILABLE | Training is default but can be disabled | OpenAI (with org settings) |
| OPT_OUT_REQUIRED | Must explicitly opt out per request | Some enterprise tiers |
| TRAINING_ENABLED | Data may be used for training | Consumer-tier APIs |
| UNKNOWN | Policy not verified | New or unverified providers |
Privacy Tiers
Data retention is classified into tiers:
| Tier | Description | Typical Use Case |
|---|---|---|
| ZERO_RETENTION | No data stored after response | Highest security workloads |
| MINIMAL_RETENTION | Brief storage for abuse monitoring | Privacy-sensitive applications |
| STANDARD_RETENTION | Typical 30-day retention | General business use |
| EXTENDED_RETENTION | Longer retention for compliance | Audit trail requirements |
| UNKNOWN | Retention not verified | New providers |
Provider Fields
Each provider and model configuration includes:
| Field | Description |
|---|---|
dataTrainingPolicy | Training data usage classification |
privacyTier | Data retention classification |
dataRetentionDays | Specific retention period (if known) |
privacyPolicyUrl | Link to provider's privacy policy |
trainingOptOutUrl | Link to opt-out instructions |
Use Cases
1. Compliance Filtering
Route sensitive prompts only to NO_TRAINING providers:
json
{
"hardConstraints": {
"privacy": {
"dataTrainingPolicy": ["NO_TRAINING"],
"maxRetentionDays": 0
}
}
}2. Healthcare/HIPAA Workloads
Ensure data is never used for training:
json
{
"geoFenceRules": {
"allow": { "countries": ["US"] }
},
"hardConstraints": {
"privacy": {
"dataTrainingPolicy": ["NO_TRAINING", "OPT_OUT_AVAILABLE"],
"privacyTier": ["ZERO_RETENTION", "MINIMAL_RETENTION"]
}
}
}3. Privacy-First Routing
Prioritize providers with better privacy practices:
json
{
"softPreferences": {
"privacyWeight": 0.8
}
}Known Provider Policies
| Provider | Training Policy | Typical Retention |
|---|---|---|
| Anthropic | NO_TRAINING | Minimal |
| OpenAI (API) | OPT_OUT_AVAILABLE | 30 days |
| Google Gemini | Varies by tier | Varies |
| Azure OpenAI | NO_TRAINING | Configurable |
Note: Policies change. Always verify with the provider's current documentation.
Best Practices
- Verify Policies: Check provider documentation for current policies
- Default to Restrictive: When in doubt, assume UNKNOWN policies use data
- Document Decisions: Keep records of which providers were used for compliance
- Regular Audits: Review provider policies quarterly
- Use Routing Policies: Automate privacy requirements in routing rules
Viewing Provider Privacy Settings
In the VeriPrompt dashboard:
- Navigate to Settings > AI Providers
- Click on any provider to view details
- Check the Privacy & Compliance section
- Review training policy and retention settings
Updating Provider Policies
Admins can update provider privacy settings:
- Go to Settings > AI Providers
- Select the provider to edit
- Update the privacy fields:
- Data Training Policy
- Privacy Tier
- Retention Days
- Policy URLs
- Save changes
Learn More
- Compliance Tools - Regulatory compliance features
- Geofencing - Geographic access control
- Intelligent Routing - How routing policies work
- BYOK - Bring your own API keys
- Chat Privacy - The chat-specific visibility badge and disclosure notice
