LLM Processing Privacy Policy
Data flow, network boundaries & privacy protection
Summary
This policy describes where data sits, what crosses network boundaries and how privacy is protected when Context Is Everything uses Large Language Models and AI tools. A Large Language Model, or LLM, is an AI model that reads and generates text. The policy applies to all Context Is Everything LLM and AI tool usage.
LLM data flow
Data path overview
Data location matrix
STAYS LOCAL
Protected
- SSH keys and certificates
- Database credentials
- API keys and secrets
- Personal identification data
- Proprietary algorithms, unless you share them
Local Processing
- File system metadata
- Local configuration preferences
- Cached responses
- Development environment settings
- Git history and branches
CROSSES NETWORK
Transmitted to LLM Services
- Source code files, when read
- Natural language prompts
- Error messages and logs
- File structure information
- Development context data
May Be Sensitive
- Business logic and algorithms
- Custom implementations
- Client-specific code
- Internal processes
- Architecture patterns
REMOTE PROCESSING
AI Provider Infrastructure
- LLM model processing
- Response generation
- Temporary data storage
- Usage analytics
- Error reporting
Retention Periods
- 30-day standard retention
- Zero retention options available
- Processing memory only
- No permanent model training
Network boundary
What crosses the corporate network
Network flow
Outbound Data Flows
Network Security Layers
| Layer | Protection | Data state | Controls |
|---|---|---|---|
| Local Machine | OS-level permissions | Plaintext files | File system access controls |
| Corporate Firewall | Network filtering | Encrypted packets | Traffic monitoring & filtering |
| VPN Gateway | Network tunneling | Encrypted tunnel | Corporate network policies |
| Internet Transit | TLS encryption | Encrypted in transit | Certificate validation |
| LLM Provider | Provider security | Processed remotely | Provider privacy policies |
Network boundary risks and controls
Data exposure risks
Internet Transmission
- All prompts and code travel over the internet
- Network interception is possible
- All AI features depend on an external service
- A service provider can suffer a data breach
Corporate Visibility
- Network logs may capture metadata
- Firewall logs show connection patterns
- VPN logs record data transfer volumes
- Security teams can monitor AI tool usage
Service Provider Logging
- LLM providers track usage patterns
- Error logs may contain sensitive context
- Providers collect analytics data
Protection measures
Encryption
- TLS 1.3 encryption for all transmissions
- Certificate pinning where supported
- Regular security protocol updates
Access Controls
- Multi-factor authentication
- API key rotation and management
- Network access restrictions
- User permission management
Monitoring & Auditing
- Usage logging
- Regular security assessments
- Compliance monitoring
- Incident response procedures
Service provider data handling
Anthropic Claude Code
Anthropic data processing
Data Handling Practices
- Default policy: No training on user code or conversations
- Retention: Automatic deletion from backend systems after 30 days
- Local storage: Up to 30 days on user devices for session resumption
- Zero retention: Available for enterprise customers with special API keys
Security Measures
- Encryption: TLS encryption for all data in transit
- Access controls: Server-side access limitations
- Processing: Temporary processing memory only, no persistent storage
- Compliance: SOC 2 Type II compliance and regular security audits
Data Locations
- Primary processing: United States. Specific regions may vary
- Backup systems: Geographic redundancy for service reliability
- Legal jurisdiction: Governed by Anthropic's terms of service
- Data residency: Confirm with Anthropic for specific regulatory requirements
Other LLM providers
OpenAI services
Data Handling as of 2024
- Training policy: API data is not used for model training by default
- Retention: 30-day retention period for abuse monitoring
- Zero retention: Available for enterprise customers
- Location: US-based processing in most cases
Security Features
- TLS encryption in transit
- SOC 2 Type II compliance
- Regular security assessments
Cloud provider LLMs
Enterprise Options
- AWS Bedrock: Data stays within your AWS account
- Google Vertex AI: Processed within Google Cloud infrastructure
- Azure OpenAI: Data remains in your Azure tenant
Added Control
- Customer-managed encryption keys
- VPC or private network connectivity
- Detailed audit logging
- Regional data residency options
User rights & privacy controls
Individual privacy rights
Your data rights
Access and Control
- Right to know: What data is collected and how it is used
- Right to access: Review data that providers hold about you
- Right to delete: Request deletion of your data from provider systems
- Right to correct: Update or correct inaccurate information
- Right to export: Download your data in portable formats
Opt-Out Mechanisms
- Telemetry opt-out: Disable usage analytics and error reporting
- Training opt-out: Confirm data is not used for model training
- Retention opt-out: Use zero retention services where available
- Service opt-out: Stop using AI services
Implementation controls
Technical controls
Environment Configuration
# Disable telemetry across all tools
export DISABLE_TELEMETRY=true
export DISABLE_ERROR_REPORTING=true
export DISABLE_BUG_COMMAND=true
# Use zero retention API keys
export ANTHROPIC_API_KEY="zero-retention-key"
export OPENAI_API_KEY="enterprise-zero-retention-key"
File Access
Run AI tools from the project directory you intend them to read. Review the files in that directory before you start a session.
Policy controls
Organizational Policies
- AI tool usage guidelines
- Data classification and handling procedures
- Approval workflows for sensitive projects
- Regular privacy impact assessments
User Training
- Privacy awareness training
- Data handling procedures
- Incident reporting procedures
- Policy updates and reviews
Compliance & regulation
Privacy regulations
GDPR in the European Union
GDPR Requirements for LLM Usage
- Personal data: Any information relating to an identified or identifiable individual
- Processing basis: AI processing needs a legitimate interest or explicit consent
- Data subject rights: You must provide access, correction and deletion mechanisms
- Cross-border transfers: Special requirements apply to data leaving the EU or EEA
- Impact assessments: Required for high-risk AI processing activities
Industry-specific regulations
Healthcare HIPAA
High Risk
- PHI cannot be sent to most LLM providers
- Requires HIPAA-compliant AI services
- Business Associate Agreements needed
- Access controls and audit trails required
Mitigation
- Use HIPAA-compliant AI services
- Anonymize data before processing
- Use private cloud deployments
- Regular compliance audits
Financial SOX and PCI
Moderate Risk
- Financial data requires special handling
- Audit trail requirements
- Access control documentation
- Change management procedures
Controls
- Separate environments for financial systems
- Added logging and monitoring
- Regular security assessments
- Compliance documentation
Government and defense
Highest Risk
- Classified data cannot use external LLMs
- Data residency requirements apply
- Security clearance implications
- FedRAMP compliance needed
Requirements
- On-premises or government cloud only
- Security clearance for all personnel
- Continuous monitoring
- Regular security assessments
Security guidance
Implementation guidelines
Security framework
Organizational Level
- Data classification: Identify and classify all data types before AI processing
- Risk assessment: Regular evaluation of AI tool risks and benefits
- Policy development: Set rules for AI tool usage and data handling
- Training programs: Train staff on privacy and security
- Incident response: Prepare procedures for privacy and security incidents
Individual Level
- Data awareness: Know what data you share with AI tools
- Tool configuration: Configure privacy and security settings
- Access controls: Use strong authentication and limit tool access
- Reviews: Review your AI tool usage and data exposure at regular intervals
- Incident reporting: Report suspected privacy or security issues at once
Technical implementation
Recommended practices
Network Security
- Use the corporate VPN for all AI tool access
- Monitor and log network traffic
- Apply security updates and patches
- Use certificate pinning where possible
Data Management
- Regular data classification reviews
- Detect sensitive data with automated tools
- Follow secure deletion procedures
- Plan backup and recovery
Access Control
- Multi-factor authentication
- Role-based access controls
- Regular access reviews
- API key rotation
Practices to avoid
Security Risks
- Using AI tools on unsecured networks
- Sharing API keys between team members
- Processing sensitive data without classification
- Ignoring privacy settings and defaults
Compliance Issues
- Lack of data processing documentation
- Insufficient impact assessments
- Missing consent mechanisms
- Inadequate data subject rights implementation
Monitoring & audit
Continuous monitoring
What we monitor
Usage
- AI tool access patterns and frequency
- Data volume and type
- User compliance
- Service provider usage
Security
- Network traffic to AI services
- Anomalies in usage patterns
- Security incidents
- Regular vulnerability assessments
Compliance
- Privacy policy adherence
- Regulatory requirements
- Data retention policy enforcement
- User rights request handling
Audit requirements
Audit schedule
Quarterly Reviews
- AI tool usage patterns
- Privacy policy compliance
- Security control effectiveness
- User training completion
Annual Assessments
- Privacy impact assessment
- Security posture evaluation
- Regulatory compliance review
- Third-party service provider evaluation
Documentation
Required Records
- Data processing activities
- Privacy impact assessments
- Security incident reports
- User consent and opt-out records
Audit Trails
- AI tool access logs
- Data transfer records
- Configuration changes
- Policy updates and communications
Reporting
Reports
- Monthly usage summaries
- Quarterly compliance reports
- Annual privacy assessments
- Incident response summaries
Recipients
- Executive dashboard
- Team training reports
- Client privacy notifications
- Regulatory filings
Privacy support & contacts
Privacy questions & support
Context Is Everything Privacy Team
General Privacy Questions: hello@context-is-everything.com
Data Subject Rights Requests: hello@context-is-everything.com
Privacy Impact Assessments: hello@context-is-everything.com
Privacy Incident Reporting
Immediate Response: hello@context-is-everything.com
Security Breaches: hello@context-is-everything.com
External Resources
Anthropic Privacy Center: https://privacy.anthropic.com
OpenAI Privacy Policy: https://openai.com/privacy
GDPR Information: https://gdpr.eu
Related policies: IP Ownership Framework