1) Scope & purpose

“AI Providers” means external model vendors and APIs we may call to deliver features across Breathe Connective (e.g., content tools, search/ranking assistance, safety checks, translations, summarization). We treat these vendors as sub-processors or independent controllers depending on the integration. This page serves as our AI sub-processor register.

2) Our principles

  • Minimize data: Only the fields needed for the task are sent; where feasible, we mask, hash, or truncate.
  • No vendor training by default: We request that prompts/outputs are not used to train vendor models where an opt-out is available.
  • Prefer local/on-prem: We run certain models via on-prem infrastructure (e.g., Ollama) so data never leaves our servers for those tasks.
  • Human review moments: AI suggestions are assistive, not authoritative. You stay in control.
  • Consent & cookies: Non-essential AI features respect your cookie/consent settings.

3) Current & prospective AI providers

Provider Example Use Data Categories Sent Region / Processing Training Use Status
OpenAI External API Text generation, summarization, coding assist, moderation assist Prompts & instructions; minimal user metadata where required (e.g., role/permissions), system context Vendor cloud (region per vendor routing) Requested: no training on our content when opt-out supported In use / opt-in by feature
Anthropic External API Safe completions, summarization, Q&A Prompts, attachments where needed; PII minimized/filtered Vendor cloud Requested: no training when supported In use / opt-in by feature
xAI (Grok) External API Generative responses, creative ideation Prompts; attachments if you provide them Vendor cloud Requested: no training when supported Planned / limited pilots
Local models (Ollama) On-prem Drafting, embeddings, lightweight vision tasks without sending data offsite Prompts/attachments processed locally Our servers Not used for vendor training In use for select features
Future vendors (e.g., Mistral, Google AI Studio, Stability, Cohere) Specialized tasks such as translation, image, or long-context Task-dependent; always minimized Vendor cloud or EU endpoints if available Requested: no training where supported Under evaluation

Note: Exact vendor lineup may change as we improve reliability, safety, cost, and latency.

4) What data we may send

  • Prompts/instructions: the text you type or select for an AI action.
  • Context: snippets needed for the task (e.g., a post you’re summarizing). We try to strip usernames, emails, and IDs unless they’re necessary.
  • Attachments (optional): only if you explicitly attach files/images for analysis.
  • Operational metadata: non-sensitive IDs, feature flags, or role scopes to enforce permissions.

We avoid sending passwords, payment details, or government IDs. If a task requires sensitive data, we’ll try to keep it on-prem or request explicit consent.

5) Lawful basis & roles

  • GDPR / UK GDPR: We act as Controller for Breathe accounts and as Controller or Processor for AI outputs depending on feature. Vendors are our sub-processors or independent controllers per their terms.
  • Legitimate interests / consent: Non-essential AI features will observe your consent choices; essential safety processing may rely on legitimate interests.

6) Retention & vendor training

We store prompts/outputs in our logs only as long as needed to operate, debug, and improve the feature set. When a vendor offers a “no training” or “data-opt-out” control, we request it. Vendors may store short-term logs for abuse prevention or service quality per their policies.

7) Safety & limitations

  • Fallibility: AI can be wrong or biased. Treat outputs as suggestions, not facts. Verify before acting.
  • Moderation: We use a combination of human review and automated checks. AI moderation assistance doesn’t replace human judgment.
  • Pro content rules: Our Community Guidelines apply to AI-generated content too.

8) Your controls

  • Cookies & consent: Manage non-essential categories at /cookies/. AI features classified as “analytics/marketing/functional” will respect those settings.
  • Opting out of AI features: For specific tools (e.g., AI summarizer), look for an in-feature toggle or contact privacy@breatheconnective.com.
  • Data rights: Access/erasure/objection requests: see Privacy Policy.

9) Security & incidents

We secure API keys and vendor credentials; we rotate and scope them per service. If we learn of a breach affecting AI data processed on our behalf, we’ll notify impacted users per applicable law and our internal response plan. Contact: security@breatheconnective.com.

10) Changes & notifications

We update this register when we add or remove AI vendors or materially change integrations. For material changes, we’ll post a notice and update the effective date. A rolling changelog is maintained below.

Changelog (AI Sub-processor Register)

  • 2025-11-09: Initial publication. Providers listed: OpenAI, Anthropic, xAI (Grok), Local (Ollama). Future vendors noted.
Questions? Email privacy@breatheconnective.com for data protection queries, or support@breatheconnective.com for feature-level help.