Skip to content
Call, 0511 – 47 55 58 11

Are our inputs used as training data?

The question is decided by the provider terms, not by the technology. It belongs before procurement, because it can hardly be corrected afterwards.

The biggest difference on this question sits between consumer services and business offerings. Same brand, same model, and yet different terms. Looking at the right version of the terms is therefore the first step.

What to settle before procurement

No training does not mean no storage

The assurance that inputs are not used for training is often taken to answer the confidentiality question. It is only part of it.

Providers distinguish three things: use for training, retention for a limited period, and access by their own staff. Retention to check for misuse is common, often thirty days, combined with the possibility of access where there is a suspicion. For the protection of a trade secret it is exactly that access which counts, not the training question alone.

All three points therefore have to be asked about, along with how they are secured contractually. Processing without retention is offered by several providers, but it has to be agreed separately and does not apply to every product in their range.

Using inputs for training also shifts the roles. As long as the provider merely delivers the service it is a processor. Where it uses inputs for its own training it pursues its own purposes to that extent and is a controller for them. A processing agreement then no longer covers that part.

How we support you

We review the provider terms in the version that applies to you, negotiate the commitments needed and draft the internal policy for it. Where a commitment cannot be obtained, we tell you which content then has to stay out.

Confidential material in the prompt?

We settle what the provider may do with your inputs.

Have the terms reviewed

Frequently asked questions

Do we lose trade secret protection?

Statutory protection presupposes reasonable steps to keep information secret. Anyone entering confidential information into a service allowed to reuse inputs puts precisely that precondition at risk. Protection then does not fall away in litigation but was never established. That is why the question belongs in the usage policy rather than in individual discretion.

Is an opt-out in the settings enough?

Only where it is contractually secured and applies to all accounts in use. A setting that can be changed unilaterally at any time and that individual staff can switch back does not carry a confidentiality strategy. It becomes robust with a contractual commitment and a centrally managed configuration.

The provider does not train. Are our inputs gone then?

No, those are two different assurances. It is common for inputs to be retained for a limited period to check for misuse, often thirty days, with access available to the provider staff. Anyone who needs confidentiality therefore has to ask about retention and access, not only about training. Processing without retention is available from several providers, but it has to be agreed separately.

Is the provider our processor?

For delivering the service, as a rule yes. As soon as it uses inputs for its own training or to improve its products it pursues its own purposes to that extent and is a controller for them. A processing agreement then no longer covers that part. That is precisely why excluding further use is not only a question of confidentiality but also one of roles.

What if inputs contain personal data?

Then the data protection level is added: legal basis, purpose limitation, information duties and the question of how data subject rights are to be met within a trained model at all. In practice it is usually easier to remove personal data before input than to control processing inside the model afterwards.

Related