The disclosures AI products need that ordinary policies miss
If your product sends user input to a model provider, that is a transfer of personal data to a third party and it belongs in your policy by name — OpenAI, Anthropic, Google or a self-hosted model. Users also want to know one specific thing: whether their prompts are used for training. Answer it explicitly, either way.
Retention deserves the same clarity. Model providers may retain API payloads for a limited abuse-monitoring window even when training is disabled; say what your own retention period is and what the provider's is.
- Named model providers and the regions they process in
- Whether prompts, uploads or outputs are used to train models
- Retention of conversation history and how users delete it
- Human review of conversations, if it happens
- Accuracy limits of generated output