All documentation

Documentation Settings: Account

Governance: models and data

Every line in the Models & data card: which providers and models may run, zero data retention, training, privacy level, EU-only calls, masking and analytics.

Models & data

The third card of part 1. Choose which providers are available and set the team's data preferences. The lines under the Data privacy sub-heading change where prompts go and what is kept.

Where to find it. Mac: Settings → Account → Governance → 1 · Policy, Access & Data. Web: Settings → Governance (part 1). iPhone: Settings → Governance → Rules → 1 of 3. Owner or admin edits.

Some lines carry a Managed seats chip. Those reach seats on Our Keys, Free Key and guests, the calls our servers make for you. A seat on a member's own key or CLI talks to its provider directly, and those lines cannot follow it there.

The policies, top to bottom

PolicyDefaultWhat it doesWhen to turn it on
Providersall onSwitch cards for Claude, ChatGPT, Gemini, Grok and the OpenRouter catalogue. A blocked provider is refused by our servers on every seat and hidden from each app's menus.When a provider is not on your approved vendor list.
Blocked modelsnoneModel IDs, one per line, refused on every seat and left off the menus.When one model is not approved but its maker is.
Require zero data retentionoffOn Our Keys, every call goes through the router to an endpoint under a zero-retention agreement. A model with no such endpoint sits the round out.When contracts say providers may keep nothing.
Exceptions to zero data retentionnoneModel IDs allowed even though their provider keeps prompts for abuse review. Under zero retention, own-key, CLI and Free Key seats are off unless their model is listed.When one retaining model is worth the trade.
Exclude providers that train on promptsoffMembers cannot seat a free account whose provider learns from what it is sent, and managed calls refuse endpoints that train. Ollama and paid keys are unaffected.Almost always.
Least private a member's Mac discussion may beSynced (each member's choice)Synced copies discussions to the account. At least a private live view keeps nothing on our servers; a paired phone watches through end-to-end encrypted messages. Kept on the Mac sends nothing anywhere but to each seat's AI. Above Synced, discussions are off the team board and do not use Our Keys.When code must never touch a third server.
Managed model calls are served inAnywhereThe EU only sends every managed call to the router's EU address and never to a vendor's own API; a call with no EU route is refused. Where discussions are stored is separate.When data must be processed in the EU.
Mask personal data before a prompt leavesoffEmails, phone numbers, card numbers and SSNs go to models as placeholders and come back as themselves. Names are not attempted.When customer data appears in tickets and logs.
No product analytics for this teamoffEvery app stops sending product analytics for members. Billing and audit events keep flowing.When your privacy notice promises no analytics.
Settings → Account → Governance → Policy, Access & Data on the Mac: the Models & data card with its Data privacy lines
Settings → Account → Governance → Policy, Access & Data on the Mac: the Models & data card with its Data privacy lines

When not to use it. Zero data retention and the EU-only route bench some models and refuse others outright. Expect fewer seats to be filled and the occasional refused call.

Further reading. Regulation (EU) 2024/1689, the AI Act, European Parliament and Council, 2024. NIST AI 600-1, Generative AI Profile, NIST, 2024.

See also

Not what you were looking for? The help centre answers one question at a time, and the support page says how to reach a person.