Data transparency
Where does my data go?
This is a product feature, not just a legal page: every run trace shows which provider processed each step, where, and what it cost. This FAQ is generated from the same model catalogue, so it can't drift out of sync with what the product actually does.
Which AI providers do you use, and can I choose?
Claude (Anthropic) is our reference model — every preset is built and evaluated on it first. But the model gateway behind every agent supports multiple providers, and every agent profile can route to a different one, including European and open-weight options. The table below is generated from the same catalogue the product uses, so it stays in sync with what you can actually pick.
| Models | Hosted by | Data region | Retention | Training use | Verification |
|---|---|---|---|---|---|
Anthropic Claude Opus 5, Claude Sonnet 5, Claude Haiku 4.5 | Anthropic API | US | 30 days | Not used for training | Verified 2026-08-22 |
OpenAI GPT-5.1, GPT-5 mini | OpenAI API / OpenRouter | US | 30 days (API policy) | Not used for training (API) | To be verified |
Gemini 2.5 Flash | OpenRouter | US | Per provider policy | Not used for training (paid API) | To be verified |
xAI Grok 4.1 Fast | OpenRouter | US | Per provider policy | Not used for training (API) | To be verified |
Mistral AI Mistral Large | Mistral AI (France) | EU | 30 days | Not used for training | To be verified |
Alibaba Qwen3 235B | OpenRouter (open weights; EU self-hosting possible) | CN-made, routed via US | Per upstream policy | Per upstream policy | To be verified |
DeepSeek DeepSeek Chat | DeepSeek API (CN) or OpenRouter | CN / US routing | Unspecified | May be used for training (direct API) | To be verified |
Zhipu AI · Moonshot AI GLM 4.6, Kimi K2 | OpenRouter | CN-made, routed via US | Per upstream policy | Per upstream policy | To be verified |
Rows marked 'to be verified' are seed data: every claim is re-checked against the provider's current terms before it appears in customer-facing contracts. Your workspace's 'Allowed data regions' policy controls which of these models can actually be selected — an EU-only workspace never sends data to US or CN rows.
Do Chinese models send my data to China?
Only if you pick the version hosted by the maker's own cloud (for example, DeepSeek or Qwen's own API). The same open-weight models are also available from EU or US hosts we contract with directly, and the model picker labels each option by who's actually hosting it — the maker, or an EU/US host — so this is a choice you make, not a default we hide.
Is my data used to train models?
Not by us. For each provider, the catalogue states their training policy, and we only enable a provider once we've confirmed a no-training commitment for API traffic — see the "Verified on" column above. Providers we haven't reviewed yet are marked "to be verified" and stay disabled until that review is done.
Where are my documents, recordings and results stored?
In our own database and file storage, separate from whichever model provider processed a given step — a provider only ever sees the content of one request, not your account. For European customers we host in an EU region. Retention defaults to 90 days for inputs and outputs and is configurable per workspace, with a hard-delete option on request.
Who else processes my data?
Our sub-processor list covers the model providers you've enabled, our infrastructure host, Stripe for payments, and — once the Phone agent ships — telephony and speech-to-text/text-to-speech vendors. The full, current list lives in our Data Processing Agreement, available on request while we're pre-launch.
What does each provider cost me?
Credit rates differ by model and are shown before you run — the estimate breaks down cost per provider (for example, "Claude Opus 5: 1,240 credits · Qwen 3 (EU host): 180 credits") and the actual cost after a run comes from the trace, not a guess. See pricing for how credits translate to euros.
Can I restrict to EU-only processing?
Yes. A workspace-level data policy — EU only, EU + US, or Any — is set by the workspace owner. It filters which models show up in the picker, blocks a per-run override that would break the policy, and defaults new EU workspaces to "EU + US" with a warning before anyone switches it to "Any."
What happens with my API keys and integration credentials?
API keys are random, shown to you exactly once, and stored on our side only as a hash — we can't read them back either. Credentials for your own integrations (ERP, accounting software, calendars) sit in an encrypted secrets store and are never sent to a model provider; only the specific tool call that needs one gets to use it.