LLM Processing Privacy Policy

Data flow, network boundaries & privacy protection


Summary

This policy describes where data sits, what crosses network boundaries and how privacy is protected when Context Is Everything uses Large Language Models and AI tools. A Large Language Model, or LLM, is an AI model that reads and generates text. The policy applies to all Context Is Everything LLM and AI tool usage.


LLM data flow

Data path overview

graph TD subgraph "Local Environment" A[Developer Workstation] B[Local Files & Code] C[Environment Variables] D[Configuration Files] E[Git Repository] end subgraph "Network Boundary" F[Corporate Firewall] G[VPN Gateway] H[TLS Encryption Layer] end subgraph "External LLM Services" I[Anthropic Claude Code] J[OpenAI API Services] K[Other AI Providers] end subgraph "Data Processing" L[AI Model Processing] M[Response Generation] N[Temporary Storage] O[Analytics & Logging] end A --> F B --> I C -.->|"Protected by Default"| A D --> I E --> I F --> H G --> H H --> I H --> J H --> K I --> L J --> L K --> L L --> M M --> N M --> O N -.->|"Temporary Only"| L style A fill:#f0fdf4,color:#000 style C fill:#fefce8,color:#000 style H fill:#fefce8,color:#000 style L fill:#fdf2f8,color:#000 style N fill:#fefce8,color:#000

Data location matrix

STAYS LOCAL

Protected

  • SSH keys and certificates
  • Database credentials
  • API keys and secrets
  • Personal identification data
  • Proprietary algorithms, unless you share them

Local Processing

  • File system metadata
  • Local configuration preferences
  • Cached responses
  • Development environment settings
  • Git history and branches

CROSSES NETWORK

Transmitted to LLM Services

  • Source code files, when read
  • Natural language prompts
  • Error messages and logs
  • File structure information
  • Development context data

May Be Sensitive

  • Business logic and algorithms
  • Custom implementations
  • Client-specific code
  • Internal processes
  • Architecture patterns

REMOTE PROCESSING

AI Provider Infrastructure

  • LLM model processing
  • Response generation
  • Temporary data storage
  • Usage analytics
  • Error reporting

Retention Periods

  • 30-day standard retention
  • Zero retention options available
  • Processing memory only
  • No permanent model training

Network boundary

What crosses the corporate network

Network flow

Outbound Data Flows

sequenceDiagram participant Dev as Developer participant Local as Local Machine participant Corp as Corporate Network participant Internet as Internet participant LLM as LLM Provider Dev->>Local: Execute AI command Local->>Local: Read local files Local->>Corp: Encrypt data packet Corp->>Corp: Firewall & security checks Corp->>Internet: Forward through VPN Internet->>LLM: TLS encrypted transmission Note over Corp: Corporate security controls apply Note over Internet: Data encrypted in transit Note over LLM: Processed on remote servers LLM-->>Internet: Encrypted response Internet-->>Corp: Return through VPN Corp-->>Local: Security validated response Local-->>Dev: Display results

Network Security Layers

Layer Protection Data state Controls
Local Machine OS-level permissions Plaintext files File system access controls
Corporate Firewall Network filtering Encrypted packets Traffic monitoring & filtering
VPN Gateway Network tunneling Encrypted tunnel Corporate network policies
Internet Transit TLS encryption Encrypted in transit Certificate validation
LLM Provider Provider security Processed remotely Provider privacy policies

Network boundary risks and controls

Data exposure risks

Internet Transmission

  • All prompts and code travel over the internet
  • Network interception is possible
  • All AI features depend on an external service
  • A service provider can suffer a data breach

Corporate Visibility

  • Network logs may capture metadata
  • Firewall logs show connection patterns
  • VPN logs record data transfer volumes
  • Security teams can monitor AI tool usage

Service Provider Logging

  • LLM providers track usage patterns
  • Error logs may contain sensitive context
  • Providers collect analytics data

Protection measures

Encryption

  • TLS 1.3 encryption for all transmissions
  • Certificate pinning where supported
  • Regular security protocol updates

Access Controls

  • Multi-factor authentication
  • API key rotation and management
  • Network access restrictions
  • User permission management

Monitoring & Auditing

  • Usage logging
  • Regular security assessments
  • Compliance monitoring
  • Incident response procedures

Service provider data handling

Anthropic Claude Code

Anthropic data processing

Data Handling Practices

  • Default policy: No training on user code or conversations
  • Retention: Automatic deletion from backend systems after 30 days
  • Local storage: Up to 30 days on user devices for session resumption
  • Zero retention: Available for enterprise customers with special API keys

Security Measures

  • Encryption: TLS encryption for all data in transit
  • Access controls: Server-side access limitations
  • Processing: Temporary processing memory only, no persistent storage
  • Compliance: SOC 2 Type II compliance and regular security audits

Data Locations

  • Primary processing: United States. Specific regions may vary
  • Backup systems: Geographic redundancy for service reliability
  • Legal jurisdiction: Governed by Anthropic's terms of service
  • Data residency: Confirm with Anthropic for specific regulatory requirements

Other LLM providers

OpenAI services

Data Handling as of 2024

  • Training policy: API data is not used for model training by default
  • Retention: 30-day retention period for abuse monitoring
  • Zero retention: Available for enterprise customers
  • Location: US-based processing in most cases

Security Features

  • TLS encryption in transit
  • SOC 2 Type II compliance
  • Regular security assessments

Cloud provider LLMs

Enterprise Options

  • AWS Bedrock: Data stays within your AWS account
  • Google Vertex AI: Processed within Google Cloud infrastructure
  • Azure OpenAI: Data remains in your Azure tenant

Added Control

  • Customer-managed encryption keys
  • VPC or private network connectivity
  • Detailed audit logging
  • Regional data residency options

User rights & privacy controls

Individual privacy rights

Your data rights

Access and Control

  • Right to know: What data is collected and how it is used
  • Right to access: Review data that providers hold about you
  • Right to delete: Request deletion of your data from provider systems
  • Right to correct: Update or correct inaccurate information
  • Right to export: Download your data in portable formats

Opt-Out Mechanisms

  • Telemetry opt-out: Disable usage analytics and error reporting
  • Training opt-out: Confirm data is not used for model training
  • Retention opt-out: Use zero retention services where available
  • Service opt-out: Stop using AI services

Implementation controls

Technical controls

Environment Configuration

# Disable telemetry across all tools
export DISABLE_TELEMETRY=true
export DISABLE_ERROR_REPORTING=true
export DISABLE_BUG_COMMAND=true

# Use zero retention API keys
export ANTHROPIC_API_KEY="zero-retention-key"
export OPENAI_API_KEY="enterprise-zero-retention-key"

File Access

Run AI tools from the project directory you intend them to read. Review the files in that directory before you start a session.

Policy controls

Organizational Policies

  • AI tool usage guidelines
  • Data classification and handling procedures
  • Approval workflows for sensitive projects
  • Regular privacy impact assessments

User Training

  • Privacy awareness training
  • Data handling procedures
  • Incident reporting procedures
  • Policy updates and reviews

Compliance & regulation

Privacy regulations

GDPR in the European Union

graph TD A[EU Personal Data] --> B{GDPR Assessment} B -->|Personal Data Identified| C[GDPR Protections Required] B -->|No Personal Data| D[Standard Processing] C --> E[Lawful Basis Required] C --> F[Data Subject Rights] C --> G[Data Protection Impact Assessment] E --> H[Legitimate Interest/Consent] F --> I[Access, Rectification, Erasure] G --> J[Risk Mitigation Measures] style A fill:#f0f9ff,color:#000 style C fill:#fefce8,color:#000 style D fill:#f0fdf4,color:#000

GDPR Requirements for LLM Usage

  • Personal data: Any information relating to an identified or identifiable individual
  • Processing basis: AI processing needs a legitimate interest or explicit consent
  • Data subject rights: You must provide access, correction and deletion mechanisms
  • Cross-border transfers: Special requirements apply to data leaving the EU or EEA
  • Impact assessments: Required for high-risk AI processing activities

Industry-specific regulations

Healthcare HIPAA

High Risk

  • PHI cannot be sent to most LLM providers
  • Requires HIPAA-compliant AI services
  • Business Associate Agreements needed
  • Access controls and audit trails required

Mitigation

  • Use HIPAA-compliant AI services
  • Anonymize data before processing
  • Use private cloud deployments
  • Regular compliance audits

Financial SOX and PCI

Moderate Risk

  • Financial data requires special handling
  • Audit trail requirements
  • Access control documentation
  • Change management procedures

Controls

  • Separate environments for financial systems
  • Added logging and monitoring
  • Regular security assessments
  • Compliance documentation

Government and defense

Highest Risk

  • Classified data cannot use external LLMs
  • Data residency requirements apply
  • Security clearance implications
  • FedRAMP compliance needed

Requirements

  • On-premises or government cloud only
  • Security clearance for all personnel
  • Continuous monitoring
  • Regular security assessments

Security guidance

Implementation guidelines

Security framework

Organizational Level

  1. Data classification: Identify and classify all data types before AI processing
  2. Risk assessment: Regular evaluation of AI tool risks and benefits
  3. Policy development: Set rules for AI tool usage and data handling
  4. Training programs: Train staff on privacy and security
  5. Incident response: Prepare procedures for privacy and security incidents

Individual Level

  1. Data awareness: Know what data you share with AI tools
  2. Tool configuration: Configure privacy and security settings
  3. Access controls: Use strong authentication and limit tool access
  4. Reviews: Review your AI tool usage and data exposure at regular intervals
  5. Incident reporting: Report suspected privacy or security issues at once

Technical implementation

Recommended practices

Network Security

  • Use the corporate VPN for all AI tool access
  • Monitor and log network traffic
  • Apply security updates and patches
  • Use certificate pinning where possible

Data Management

  • Regular data classification reviews
  • Detect sensitive data with automated tools
  • Follow secure deletion procedures
  • Plan backup and recovery

Access Control

  • Multi-factor authentication
  • Role-based access controls
  • Regular access reviews
  • API key rotation

Practices to avoid

Security Risks

  • Using AI tools on unsecured networks
  • Sharing API keys between team members
  • Processing sensitive data without classification
  • Ignoring privacy settings and defaults

Compliance Issues

  • Lack of data processing documentation
  • Insufficient impact assessments
  • Missing consent mechanisms
  • Inadequate data subject rights implementation

Monitoring & audit

Continuous monitoring

What we monitor

Usage

  • AI tool access patterns and frequency
  • Data volume and type
  • User compliance
  • Service provider usage

Security

  • Network traffic to AI services
  • Anomalies in usage patterns
  • Security incidents
  • Regular vulnerability assessments

Compliance

  • Privacy policy adherence
  • Regulatory requirements
  • Data retention policy enforcement
  • User rights request handling

Audit requirements

Audit schedule

Quarterly Reviews

  • AI tool usage patterns
  • Privacy policy compliance
  • Security control effectiveness
  • User training completion

Annual Assessments

  • Privacy impact assessment
  • Security posture evaluation
  • Regulatory compliance review
  • Third-party service provider evaluation

Documentation

Required Records

  • Data processing activities
  • Privacy impact assessments
  • Security incident reports
  • User consent and opt-out records

Audit Trails

  • AI tool access logs
  • Data transfer records
  • Configuration changes
  • Policy updates and communications

Reporting

Reports

  • Monthly usage summaries
  • Quarterly compliance reports
  • Annual privacy assessments
  • Incident response summaries

Recipients

  • Executive dashboard
  • Team training reports
  • Client privacy notifications
  • Regulatory filings

Privacy support & contacts

Privacy questions & support

Context Is Everything Privacy Team
General Privacy Questions: hello@context-is-everything.com
Data Subject Rights Requests: hello@context-is-everything.com
Privacy Impact Assessments: hello@context-is-everything.com

Privacy Incident Reporting
Immediate Response: hello@context-is-everything.com
Security Breaches: hello@context-is-everything.com

External Resources
Anthropic Privacy Center: https://privacy.anthropic.com
OpenAI Privacy Policy: https://openai.com/privacy
GDPR Information: https://gdpr.eu

Related policies: IP Ownership Framework

made with bernard

Cookie settings