Trust & Data Handling
Where your data goes, and what we commit to.
Last Updated: August 4, 2026
Our software is built on automated and machine learning systems, which means customer data passes through providers we do not own. This page says which ones, and what we commit to. It is written for the person at a customer who has to sign off on that.
What We Commit To
Your content is not training material in identifiable form. We use your drawings, records, and other content to provide the service you have engaged us for. We do not train models on it in a form that could surface it to another customer, and we do not make it available to other customers.
We do learn from the work, in aggregate — including by training on it. We create derived data: statistics and artifacts drawn from customer content that have been de-identified or aggregated so they do not identify a customer, an individual, or a customer’s customers, suppliers, or projects. We use derived data to operate, secure, benchmark, and improve our products, including to train and evaluate our models. That is how the software gets better for everyone using it.
We do not publish or share derived data in any form attributable to a customer without that customer’s written consent.
We tell you who processes your data. The AI providers we use are listed below and kept current. If we become aware that a provider’s terms permit it to train on inputs, we notify affected customers, who may direct that their data not be processed by that provider.
We do not accept regulated data. Our agreements prohibit sending us payment card or cardholder data, financial account or routing numbers, government-issued identification numbers, protected health information, or biometric data.
Outputs are reviewed by you. Our software assists your work; it does not replace your review. Programs, drafts, and other output are generated by automated systems, may contain errors, and are yours to verify before you rely on them.
These commitments come from the agreements we sign. This page describes them; the agreement governs.
AI Providers
These are the AI providers that may process customer content:
| Provider | Used for | Processing location |
|---|---|---|
| Anthropic | Large language model inference | United States |
We may add, remove, or substitute providers as the technology changes. Any provider we use must operate under terms that do not permit it to train generally available models on our inputs. Customers may request the current list at any time, and this page is where it is published.
Retention by Providers
AI providers commonly retain inputs and outputs for a limited period for security, abuse detection, legal compliance, and service operation. That is standard across the industry and is permitted under our agreements. It is not the same as training, and it does not make your data available to anyone else.
Questions
If you need something this page does not answer — a security questionnaire, a subprocessor notification arrangement, or a data processing agreement — write to us.