Including the parts most AI vendors leave vague. Every claim on this page is specific enough for you to check, and dated where the date matters.
We resell AI capability, which means your data passes through third-party model providers. Each has its own default posture, and the defaults are not all the same. Rather than make one blanket claim, here is each provider and exactly where it stands. Last reviewed July 30, 2026.
| Provider | What it powers | Training on your content | Status |
|---|---|---|---|
| Anthropic | The assistant, agents, summaries — most AI in the product | Contractually restricted from training on your content under their commercial terms | Verified |
| OpenAI | Voice, dictation, some responses | Contractually restricted under their business terms | Verified |
| Gemini — image generation and editing, research | Paid API tier, where Google's terms state it does not use prompts or responses to improve its products | Verified | |
| AssemblyAI | Meeting transcription and speaker labels | Permitted training by default. We opted out, confirmed July 29, 2026. Audio and transcripts are also deleted from their systems on a 30-day timer | Opted out |
| ElevenLabs | Text-to-speech voices | Permitted training by default. We opted out at the workspace level, confirmed July 30, 2026 | Opted out |
| Voyage AI | Embeddings for private document and memory search | Permitted training by default. We opted out, confirmed July 30, 2026, which also gives zero-day retention of what we send | Opted out |
| Your browser'sspeech recognition | Our in-app note-taker, and dictation when real-time voice is unavailable | Audio goes to your browser vendor — for Chrome, Google — under their consumer terms, not any agreement we hold, so we cannot opt out on your behalf. It is a fallback path only, and we can disable it for your workspace on request | Not ours to control |
If a provider's posture affects your decision to use a particular feature, ask us and we'll tell you plainly, in writing — and where a feature can be disabled for your workspace, we'll do that instead.
Why these providers and not the rest of the list. This table covers every provider that creates something from the content you put in — text, audio, images, embeddings — because those are the ones where "could they train on my work?" is a real question. The rest of our subprocessors either hold your data without generating anything from it, or never see your content at all. They're in the next section, under a different heading, because "could this vendor train on my work?" and "who touches my data?" are different questions.
Grouped by what each one actually sees — because a hosting provider holding an encrypted file and a search vendor receiving your domain name are not the same exposure, and lumping them together would hide that.
| What they see | Providers |
|---|---|
| AI model providerscreate output from your content | All listed individually in section 1 above, with each one's training posture and date. |
| Hold your contentstore it, generate nothing from it | Cloudflare (hosting, network, the agent runtime, AI gateway, browser rendering) · Supabase (database, authentication, file storage, serverless functions) |
| Receive specific contentonly when you use that feature | GitHub (prototype code when an AI Partners administrator promotes Studio work) · Resend and Mailgun (transactional email such as sign-in links and notifications) · Browserbase (pages rendered on your behalf) · the third-party service behind an individual app, where one is used (only the files or data you submit to that app) |
| Identifiers or metadata onlynever your content | Moz · SpyFu · Similarweb · InLinks · SerpAPI · Microsoft Bing Search · Google Search Console · Google PageSpeed (your domain and keywords) · Stripe (payment token — card details never touch our servers) · jsDelivr (your browser's IP address and user agent when it loads two shared libraries) |
We don't sell customer data, and subprocessors may only process it to provide their service to us. When we add or change a provider in a way that materially affects how your data is processed, we update this page and give notice.
This list is regenerated from an audit of every outbound network call in our codebase, not from memory. Last audited July 30, 2026.
Every company gets its own workspace. Row-level security policies in the database are the primary isolation control and cover essentially every customer table; those policies are captured in our committed migration history and mirrored in a reviewable snapshot of the live database. A small number of server-side paths — private document search, assistant memory, and agent workflows — enforce the same company boundary in reviewed server code rather than in database policy.
Role-based controls govern who sees what. Billing statements and cost data are restricted to administrators and enforced server-side. Each person's assistant memory is scoped to them rather than shared across the company by default.
Background agent workflows route external calls through a central tool layer that validates inputs and applies a trust-boundary gate: a workflow that reads untrusted external content cannot use action-taking tools unless explicitly marked otherwise. Every external page render is recorded with the requesting company, user, and destination. Sensitive actions can be held for human approval.
On spend: every workspace ships with an always-on rolling seven-day cap on assistant and app chat — at 80% we automatically downgrade to a cheaper model, at 100% chat pauses until the window rolls forward. Voice, dictation, and transcription run on weekly minute caps; background agents on daily token budgets with a kill switch. A fixed calendar-month hard cutoff is armed by default for new companies and available to any workspace on request.
Database schema and policy changes ship as versioned migrations. We run a documented, recurring internal security review of those policies and access paths, with a findings ledger and fixes tracked to closure. Production health is independently monitored around the clock.
Recording is started deliberately, shows an on-screen indicator while it runs, and produces a transcript and notes delivered into your workspace. Audio is never retained — it goes to the transcription provider and is deleted from our systems as soon as the transcript is produced. We keep a server-side copy of each transcript alongside its usage record for billing and re-delivery; ask and we'll export or permanently delete any transcript, including that copy, within five business days.
One obligation sits with you. Recording laws vary by state and some require every participant's consent. Under our terms, giving notice and obtaining consent is the customer's responsibility. The product shows a reminder to the person recording and an on-screen indicator — it does not collect or verify consent from participants. If you operate across state lines, this is worth a conversation with your own counsel.
Two things worth knowing about how we handle AI generally. First, AI output can be wrong, and our terms say so directly rather than burying it — anything that matters should be checked before you rely on it. Second, for decisions that affect people — hiring, housing and tenant screening, lending, insurance — our terms require a qualified human to review before the decision is final. That isn't boilerplate; it's a constraint our AI providers require us to pass on to you, and we agree with it.
Questions, a security report, or a vendor review to complete? Write to dave@ai-p.ai — a human reads it, and we'll answer specifics in writing.