Model data policies
Records Labs sends the relevant parts of your knowledge to an AI model to write each answer. The Data retention policy setting decides which model providers are allowed to handle that data, based on what they do with it.
Records Labs does not train models on your content unless an Owner turns on Help improve the platform under Settings → Security → Data. Whether model providers may train on it is what the setting below controls.
The setting
Open Settings → Answering, go to the Models tab, and find Data retention policy at the top. Owners and Admins can change it.
Allow training — providers that may train on your data are allowed. Some models cost less.
No training — providers may not use your data to train models. This is the default.
Zero data retention — only providers that store none of your data. It can cost more, limits which models you can use, and may degrade some model features and services.
Pick the strictest option your organization needs. Every model in the catalog has at least one provider that honors No training.
How it is enforced
Chat, agents, Council, and the AI features inside the app reach model providers through OpenRouter, a routing service that can serve the same model from several providers. Every request carries your organization's policy as a routing rule: providers that collect data for training are excluded under No training, and only providers on OpenRouter's zero-retention list are eligible under Zero data retention. A request that no eligible provider can serve is refused by the router rather than sent somewhere looser.
If reading the setting ever fails, requests do not fall back to a looser policy; they reuse the last known value or run under zero retention.
Which providers qualify for zero retention is read live from OpenRouter, not fixed in Records Labs, so it can change as providers update their terms.
What changes when you choose Zero data retention
Models no zero-retention provider serves move to a group labeled Unavailable with zero data retention in the model list, and are removed from your organization's allowed models when you save.
Models that cost more under this policy show a costs N× more tag.
If any agent used a model that is now unavailable, you are asked to pick a replacement for each. Until you do, those agents' answers fall back to the Records Labs default model.
Every change to this setting is written to the audit log.
What the setting does not cover
A few steps run against vendors directly rather than through your policy's routing rule, under those vendors' own API terms:
Document extraction and OCR for PDFs that contain tables, figures, drawings, or scanned pages, and for images. When any page of a PDF needs this, the whole file can be sent to the vendor, even though only those pages are read.
Embeddings and reranking, which turn text and images into search vectors.
Audio and video transcription.
Web search, when an agent has Public web search turned on. The search queries go to a search provider.
These vendors are listed in Subprocessors.
Other data-use controls
Data use under Settings → Security → Data: Improve our own experience keeps citation clicks and feedback as private signals for your own search ranking. Help improve the platform (off by default, Owners only) shares query text and document excerpts from a small sample of searches to improve ranking for all customers.
Private chat keeps a conversation out of chat history; the usage record keeps placeholders instead of the question and answer text. It is still answered by the model under the same retention policy.
Secrets pasted into chat, such as API keys, tokens, and private keys, are replaced with a placeholder before the message is stored or sent to a model.