AI Providers & Model Disclosures
We use third-party AI services to power features like recommendations, moderation assistance, and creative tools. This page explains who they are, what data may flow, and your choices.
1) Scope & purpose
“AI Providers” means external model vendors and APIs we may call to deliver features across Breathe Connective (e.g., content tools, search/ranking assistance, safety checks, translations, summarization). We treat these vendors as sub-processors or independent controllers depending on the integration. This page serves as our AI sub-processor register.
2) Our principles
- Minimize data: Only the fields needed for the task are sent; where feasible, we mask, hash, or truncate.
- No vendor training by default: We request that prompts/outputs are not used to train vendor models where an opt-out is available.
- Prefer local/on-prem: We run certain models via on-prem infrastructure (e.g., Ollama) so data never leaves our servers for those tasks.
- Human review moments: AI suggestions are assistive, not authoritative. You stay in control.
- Consent & cookies: Non-essential AI features respect your cookie/consent settings.
3) Current & prospective AI providers
| Provider | Example Use | Data Categories Sent | Region / Processing | Training Use | Status |
|---|---|---|---|---|---|
| OpenAI External API | Text generation, summarization, coding assist, moderation assist | Prompts & instructions; minimal user metadata where required (e.g., role/permissions), system context | Vendor cloud (region per vendor routing) | Requested: no training on our content when opt-out supported | In use / opt-in by feature |
| Anthropic External API | Safe completions, summarization, Q&A | Prompts, attachments where needed; PII minimized/filtered | Vendor cloud | Requested: no training when supported | In use / opt-in by feature |
| xAI (Grok) External API | Generative responses, creative ideation | Prompts; attachments if you provide them | Vendor cloud | Requested: no training when supported | Planned / limited pilots |
| Local models (Ollama) On-prem | Drafting, embeddings, lightweight vision tasks without sending data offsite | Prompts/attachments processed locally | Our servers | Not used for vendor training | In use for select features |
| Future vendors (e.g., Mistral, Google AI Studio, Stability, Cohere) | Specialized tasks such as translation, image, or long-context | Task-dependent; always minimized | Vendor cloud or EU endpoints if available | Requested: no training where supported | Under evaluation |
Note: Exact vendor lineup may change as we improve reliability, safety, cost, and latency.
4) What data we may send
- Prompts/instructions: the text you type or select for an AI action.
- Context: snippets needed for the task (e.g., a post you’re summarizing). We try to strip usernames, emails, and IDs unless they’re necessary.
- Attachments (optional): only if you explicitly attach files/images for analysis.
- Operational metadata: non-sensitive IDs, feature flags, or role scopes to enforce permissions.
We avoid sending passwords, payment details, or government IDs. If a task requires sensitive data, we’ll try to keep it on-prem or request explicit consent.
5) Lawful basis & roles
- GDPR / UK GDPR: We act as Controller for Breathe accounts and as Controller or Processor for AI outputs depending on feature. Vendors are our sub-processors or independent controllers per their terms.
- Legitimate interests / consent: Non-essential AI features will observe your consent choices; essential safety processing may rely on legitimate interests.
6) Retention & vendor training
We store prompts/outputs in our logs only as long as needed to operate, debug, and improve the feature set. When a vendor offers a “no training” or “data-opt-out” control, we request it. Vendors may store short-term logs for abuse prevention or service quality per their policies.
7) Safety & limitations
- Fallibility: AI can be wrong or biased. Treat outputs as suggestions, not facts. Verify before acting.
- Moderation: We use a combination of human review and automated checks. AI moderation assistance doesn’t replace human judgment.
- Pro content rules: Our Community Guidelines apply to AI-generated content too.
8) Your controls
- Cookies & consent: Manage non-essential categories at /cookies/. AI features classified as “analytics/marketing/functional” will respect those settings.
- Opting out of AI features: For specific tools (e.g., AI summarizer), look for an in-feature toggle or contact privacy@breatheconnective.com.
- Data rights: Access/erasure/objection requests: see Privacy Policy.
9) Security & incidents
We secure API keys and vendor credentials; we rotate and scope them per service. If we learn of a breach affecting AI data processed on our behalf, we’ll notify impacted users per applicable law and our internal response plan. Contact: security@breatheconnective.com.
10) Changes & notifications
We update this register when we add or remove AI vendors or materially change integrations. For material changes, we’ll post a notice and update the effective date. A rolling changelog is maintained below.
Changelog (AI Sub-processor Register)
- 2025-11-09: Initial publication. Providers listed: OpenAI, Anthropic, xAI (Grok), Local (Ollama). Future vendors noted.