Last Reviewed: September 10, 2026

At a Glance

“GLM” refers to the AI models; “Z.AI” is the company that developed them. The GLM AI models are software (large language models) that generate responses to your prompts. Z.AI — the international brand (since July 2025) of Beijing Zhipu Huazhang Technology Co., Ltd. — is based in Beijing, China.

Bells Up AI uses two U.S.-hosted inference routes for GLM: Amazon Bedrock and Fireworks AI. The route that processes your request depends on the model you select. Z.AI itself never receives your prompts, documents, or the models’ responses.

Across both routes, your prompts and responses stay within U.S. infrastructure and are not disclosed to Z.AI. Neither provider trains on your content under the terms described below. Model output censorship concerns and regulatory considerations — including the developer’s U.S. export-control status, discussed below — persist regardless of hosting.

At a glance: GLM (via Amazon Bedrock and Fireworks AI) privacy practices
QuestionAnswer
Which inference route processes your request?Amazon Bedrock: GLM 5, GLM 4.7, and GLM 4.7 Flash, in a U.S. region. Fireworks AI: GLM 5.3 and GLM 5.3 Flash, through its U.S.-only endpoint.
Can Z.AI access your prompts or documents?No — Z.AI never receives them
Can Z.AI train AI on your prompts or documents?No — Z.AI has zero access
Can Z.AI employees or contractors review your data?No — Z.AI has zero access
How long does Z.AI retain your data?N/A — Z.AI never receives your data
How does each route retain inference content?Amazon Bedrock: zero data retention by default. Fireworks AI: zero data retention for inference; prompt-cache data may remain in volatile memory for several minutes, but is not logged to persistent storage.
Does the infrastructure provider train AI on your data?No — prohibited by contract for both
How do the routes handle safety and abuse?Amazon Bedrock: automated classifiers may scan content; its zero operator access (ZOA) model prevents AWS operators from accessing inputs or outputs. Fireworks AI: its terms allow safety-screening tools. (Bedrock details; Fireworks details)
Can provider personnel review prompts or responses?Amazon Bedrock: its ZOA model bars operator access; apparent CSAM may be reviewed for confirmation and reporting. Fireworks AI: its terms say it will not log content for human review, except as required by law or to provide the service or support.
US government restrictions on GLM?The developer (Zhipu) is on the U.S. Commerce Department Entity List — an export-control measure; no ban on private or commercial use of the models (details)
Is this disclosure legal advice?No. Bells Up AI does not provide legal advice. Attorneys should exercise independent professional judgment regarding model selection.

Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Amazon Web Services and Fireworks AI — the platforms that run the models and where your prompts are processed — each hold SOC 2 and ISO 27001 certifications.


Summary of What You Need to Know About Using GLM Through Bells Up AI

Bells Up AI gives customers access to a range of AI tools and the information needed to make informed professional decisions about their use. Model selection remains the attorney’s professional judgment call.

The model developer does not receive your data. Bells Up AI accesses the GLM models through Amazon Bedrock and Fireworks AI. Z.AI (Beijing Zhipu Huazhang Technology Co., Ltd.) — the company that develops and trains the GLM models — does not receive the prompts, documents, or responses you submit through Bells Up AI, does not store them, and cannot train on them. Processing stays within U.S. infrastructure. See Z.AI (Zhipu): The Model Developer and Fireworks AI: Infrastructure Provider for Fireworks-Hosted GLM Models for the basis of each statement.

Model behavior is unaffected by hosting. Output censorship and bias arise from the trained model and are not changed by running GLM on Z.AI’s servers, Amazon’s, or Fireworks AI’s. A PNAS Nexus study of an older ChatGLM generation found the lowest refusal rate among the Chinese models tested, while also finding deflection or omissions on topics including Taiwan’s political status, ethnic minorities, and pro-democracy figures. We have not located a dedicated public study of a GLM model available through Bells Up AI. We identify that gap rather than infer findings from the older model. See What U.S.-Hosted Inference Does and Does Not Address for the full analysis.

Regulatory context. Zhipu is on the U.S. Commerce Department’s Entity List. On January 16, 2025, the Bureau of Industry and Security (BIS) added Beijing Zhipu Huazhang Technology Co., Ltd. and several affiliated entities to the list (90 Fed. Reg. 4617). An Entity List designation requires a license, subject to a presumption of denial, to export U.S.-origin items to the listed entity.

By its terms, the designation restricts what may be shipped to Zhipu; it does not prohibit U.S. persons or platforms from hosting or serving GLM models. We are not aware of a provision barring end users from querying the models, although the Export Administration Regulations include knowledge-based catch-all provisions. Attorneys with export-control exposure should assess how the designation bears on their matters. Zhipu has not been designated by the Department of Defense under Section 1260H. Texas added Zhipu (Z.AI) to its state prohibited-technology list in January 2026; that restriction applies to state-government devices and networks, not private or commercial use. As of the Last Reviewed date, Bells Up AI has not identified a U.S. restriction on private or commercial use of GLM. The proposed “No Adversarial AI Act” (H.R. 4142 / S. 2177) would apply to federal-agency procurement only; it remains in committee and has not been enacted. Z.AI’s Entity List status remains subject to change. See Chinese-Origin Model Considerations for the full analysis.

Practice considerations. GLM runs on U.S. infrastructure. Z.AI does not receive your prompts, documents, or responses, and the infrastructure providers do not train on them under the terms described below. Model output and Z.AI’s regulatory posture require separate consideration. Verify GLM responses on politically sensitive topics. Attorneys working with government, defense, or government-contractor clients should consider Z.AI’s Entity List status and its potential relevance to the matter. They may also wish to consider how use of a Chinese-origin model developed by an Entity-Listed company could be perceived by clients, opposing counsel, or a court.


The Parties Involved

When you use the GLM family of AI models through Bells Up AI, the following parties are involved in processing your request:

  1. Z.AI is the Model Developer — the company that created and trained the GLM family of AI models. Beijing Zhipu Huazhang Technology Co., Ltd., operating internationally under the brand Z.AI, develops and maintains these models.
  2. Amazon and Fireworks AI are the Infrastructure Providers. Amazon provides cloud computing services (servers, storage, networking) under the brand “Amazon Web Services” or “AWS”; it hosts some GLM models through a service called “Amazon Bedrock,” and also hosts the Bells Up AI application. Fireworks AI is an independent U.S. inference platform that hosts the other GLM models. The At a Glance table lists which provider hosts each model.
  3. Bells Up AI (“we” or “us”) — We built and operate the application you are using.

Each party operates under contractual obligations that protect your data. Below, we explain what each party can and cannot do with your data, with citations to the governing contracts.


Z.AI (Zhipu): The Model Developer

What Z.AI Does: Beijing Zhipu Huazhang Technology Co., Ltd. — a 2019 spinout of Tsinghua University’s Knowledge Engineering Group, operating internationally under the brand Z.AI since July 2025 — develops and trains the GLM family of AI models. Z.AI provides the trained model weights for deployment on infrastructure it does not control. Every GLM model available through Bells Up AI is open-weight under its published license — meaning the model weights are publicly available. Z.AI has no proprietary access channel to the copies of these models deployed on Amazon Bedrock or Fireworks AI.

“Open weights” means the trained model can be downloaded and run by anyone — including us, on infrastructure the developer cannot access. It does not mean the training data or methods are disclosed. How any modern AI model was trained, open-weight or proprietary, cannot be independently verified from the model itself. In practical terms, the open-weight structure is what makes it possible to host GLM on infrastructure that Z.AI itself cannot reach — it is the reason the isolation described below is available at all.

What Z.AI Cannot Do

Z.AI cannot access your prompts, documents, or GLM’s responses when you use GLM through Bells Up AI. For the GLM models hosted on Amazon Bedrock, this is a technical restriction: Z.AI has no access to the Amazon infrastructure where those models are deployed. For the Fireworks-hosted GLM models, the basis is contractual and is described in Fireworks AI: Infrastructure Provider for Fireworks-Hosted GLM Models.

On Amazon Bedrock, Amazon does not provide Z.AI with access to your prompts, documents, or responses. In order to run AI models like the GLM models you access through Bells Up AI, Amazon maintains “Model Deployment Accounts”, which model developers like Z.AI do not have access to:

“Model providers don’t have any access to those accounts. After delivery of a model from a model provider to [Amazon], Amazon Bedrock will perform a deep copy of a model provider’s inference and training software into those accounts for deployment. Because the model providers don’t have access to those accounts, they don’t have access to Amazon Bedrock logs or to customer prompts and completions.”

— Amazon Bedrock Data Protection Documentation

No Training on Your Data

Amazon Bedrock prohibits both Amazon and third-party model providers from using your prompts, documents, or model responses for training:

Amazon does not use your prompts and responses to train its own models, and does not share them with the model provider. AWS states that retained inputs and outputs (for the limited set of models that require retention) are “stored and processed by AWS and are not shared with third-party model providers.”

— Amazon Bedrock Abuse Detection Documentation

Z.AI’s own international service (z.ai) is Singapore-routed and governed by Singapore law. By default it trains on individual/consumer content and takes a broad content license, though its API/business tier carves out no-store and no-train-without-consent options for those customers. Bells Up AI runs GLM on Amazon Bedrock or Fireworks AI infrastructure, and Z.AI does not receive your data.


Chinese-Origin Model Considerations

Beijing Zhipu Huazhang Technology Co., Ltd. is headquartered in Beijing, China. As a Chinese company, Z.AI is subject to Chinese national security and data laws. Attorneys should understand what these laws require, and why U.S.-hosted inference matters in this context.

Chinese Laws That Apply to Z.AI

National Intelligence Law (2017, amended 2018):

“All organizations and citizens shall support, assist, and cooperate with national intelligence efforts in accordance with law.”

— National Intelligence Law of the PRC, Article 7 (China Law Translate)

Data Security Law (2021): Classifies data and imposes handling requirements on Chinese companies. Compels data disclosure to authorities under national security provisions.

Personal Information Protection Law (PIPL, 2021): China’s data protection framework, with explicit carve-outs for national security and public interest that allow government access to personal data held by Chinese companies.

Why U.S.-Hosted Inference Changes the Analysis

These laws allow Chinese authorities to compel Z.AI to disclose data. Z.AI does not possess your inference data — your prompts, documents, and GLM’s responses never reach Z.AI’s systems. Chinese authorities cannot compel disclosure of data Z.AI does not have.

Z.AI’s own services and U.S.-hosted GLM use different data flows:

Comparison of data privacy risks: U.S.-hosted inference versus direct Z.AI API
Concern Direct Z.AI API Through Bells Up AI (U.S.-hosted)
Z.AI receives prompt dataYesNo
Data stored outside the United StatesYes — Singapore (international z.ai product; China-domestic product’s storage not independently verified)No — processed in the United States
Chinese gov’t can compel data disclosureYes, via Z.AINo data for Z.AI to disclose
Data used for model trainingYes, by default (per z.ai consumer terms)No (prohibited by contract)

This comparison addresses the Bedrock-hosted GLM models. For the Fireworks-hosted GLM models, see Fireworks AI: Infrastructure Provider for Fireworks-Hosted GLM Models.

What U.S.-Hosted Inference Does and Does Not Address

U.S.-hosted inference prevents:

It does not address:

September 2026 federal advisory. On September 8, 2026, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation issued a joint cybersecurity advisory, AA26-251A, titled “China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies.” The advisory names six China-based AI companies — DeepSeek, Moonshot AI, Alibaba, Z.AI, MiniMax, and StepFun — that it states extracted training data from U.S. frontier models. It states that by mid-2026, Z.AI “had distilled billions of tokens of GPT-5.5 data and Claude Opus 4.8 data to develop the CoT reasoning capabilities of its model.” The advisory directs its recommendations to U.S. AI developers, on detecting and responding to distillation. It imposes no restriction, obligation, or requirement on companies or individuals that use these models. It concerns how these models were trained, not how your prompts and responses are handled when you use them; the data-handling protections described in this disclosure are unaffected.

Amazon: Infrastructure Provider for Bedrock-Hosted GLM Models

Amazon provides two distinct services relevant to how your data is handled:

Amazon Bedrock (The AI Service)

What Amazon Bedrock Does: Amazon Bedrock is the service that hosts and runs the Bedrock-hosted GLM models. When you submit a prompt to one of these models, Bells Up AI sends it to Amazon Bedrock, which processes it through GLM and returns the response.

Prompt Improvement Tool

The optional “Improve my prompt” tool sends the draft prompt to Amazon Bedrock’s prompt-optimization service, not to Fireworks AI or the selected model. The tool sends your draft prompt to Amazon Bedrock regardless of the model you select. Conversations, documents, and workflow runs are not sent to this service.

Amazon Bedrock’s Core Commitments:

No Storage of Your Prompts or Responses:

“Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output. Also, Amazon Bedrock uses a zero data retention (ZDR) data security model. This means that by default, Amazon Bedrock does not store model inputs or outputs.”

— Amazon Bedrock Abuse Detection Documentation

No Training on Your Data:

Amazon does not use your prompts and responses to train its own models, and does not share them with the model provider. AWS states that retained inputs and outputs (for the limited set of models that require retention) are “stored and processed by AWS and are not shared with third-party model providers.”

— Amazon Bedrock Abuse Detection Documentation

Data Stays in Region: Your data remains in the Amazon data center region where the request is processed. Bells Up AI processes all Bedrock-hosted GLM requests in the United States AWS region us-east-1 (Northern Virginia). This is a U.S. region; your requests are not routed outside the United States.

Automated Abuse Detection

Amazon Bedrock runs automated content scanning on data processed through the service. If that scanning flags apparent child sexual abuse material, the AWS Service Terms provide:

“If we detect apparent child sexual abuse material (“CSAM”), you agree and instruct that we may: (a) review the flagged input or output to determine if it is CSAM, and (b) report the incident to the National Center for Missing and Exploited Children or other authority.”

— Amazon Web Services Service Terms, Section 50.12.2.1 (September 1, 2026)

The Service Terms also provide that, for certain models identified on Amazon’s Bedrock abuse-detection documentation, Amazon Bedrock stores inputs and outputs for up to 30 days to detect terms-of-service violations and may review them if a potential violation is detected. None of the models available through Bells Up AI are identified on that list as of this review.

Apart from these provisions, Amazon’s abuse-detection documentation describes the following data-security model:

“Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output.”

— Amazon Bedrock Abuse Detection Documentation

What this means:

This automated scanning is narrower in scope than the abuse monitoring systems used by direct API providers like OpenAI or Google, which retain data for up to 30 or 55 days and may involve human review of flagged content. Amazon Bedrock’s abuse detection operates at the infrastructure level and does not involve the model provider (Z.AI).

What Metadata Z.AI May Receive

While Z.AI never receives the content of your prompts or responses, Amazon may share non-content usage information with third-party model providers:

“We may share information, that does not include Your Content, about your use of a third-party model with the provider of that third-party model.”

— Amazon Web Services Service Terms, Section 50.12.5 (September 1, 2026)

This metadata may include identifiers such as Bells Up AI’s AWS Account ID, the AWS region, the model used, request counts, token usage, and timestamps. It contains no content from your prompts, documents, or responses.

Amazon Web Services Infrastructure (Servers and Storage)

What This Means: Separately from Amazon Bedrock, the Bells Up AI application itself runs on Amazon’s cloud infrastructure. This includes:

Can Amazon Access This Data?

Amazon operates the physical servers and storage infrastructure we use. Amazon’s access to data stored on its infrastructure is governed by contract and verified by independent audits, which test whether Amazon’s actual practices match its contractual commitments:

“AWS will not access or use, or disclose to any third party, any Customer Data, except, in each case, as necessary to maintain or provide the Services, or as necessary to comply with the law or a valid and binding order of a governmental body (such as a subpoena or court order).”

— Amazon Web Services Data Processing Addendum

This prohibits Amazon from using your data to develop Amazon’s own AI or other products, or from providing your data to others for such purposes.

Amazon’s SOC 2 Type II certification provides independent verification that Amazon maintains and follows these access controls.

Technical Protections:

Technical protections: encryption and access controls
Protection Implementation
Encryption in transitTLS 1.2+ for all communications
Encryption at restAES-256 for all stored data
Server storageEncrypted at the hardware level
Access controlsCredentials managed through Amazon’s identity system; no hardcoded passwords

Governing Agreements

Bells Up AI’s use of Amazon services is governed by:

Under the Data Processing Addendum, Amazon acts as a “data processor” — meaning Amazon processes data on our behalf according to our instructions, rather than controlling or owning the data.

Compliance Certifications

Amazon Bedrock and the underlying infrastructure maintain the following certifications:

See: Amazon Bedrock Security & Compliance


Fireworks AI: Infrastructure Provider for Fireworks-Hosted GLM Models

Bells Up AI runs some GLM models through Fireworks AI, an independent U.S. inference platform, on Fireworks’ U.S.-only endpoint, rather than on Amazon Bedrock. The At a Glance table lists which models use each route.

Zero Data Retention

Fireworks’ binding Terms of Service commit to a zero-data-retention policy for inference:

“We have adopted a ‘Zero Data Retention’ policy, which means that we will not, unless otherwise required by Applicable Law (or to provide the Service or support to you): (i) log your Content for human review; or (ii) retain your Content, beyond the time it takes to generate Output and deliver that Output to you.”

— Fireworks AI Terms of Service, Section 3.6 (July 10, 2026)

Fireworks’ Data Processing Addendum states the same obligation in binding contract terms:

“Except as described below, Company shall not retain Customer’s prompt inputs or model outputs beyond the lifecycle of the applicable request.”

— Fireworks AI Data Processing Addendum, Section 4.5

Fireworks’ zero-retention commitment applies to standard inference. Two Fireworks features handle data beyond the request itself. Its Response API retains data unless the caller sets the request to non-storing (“store=false”); Bells Up AI sends “store=false”. Prompt caching is enabled by default on all Fireworks models and cannot be turned off. Fireworks states that when caching is active, some prompt data and the associated key-value caches “can be stored in volatile memory for several minutes,” and that prompt and generation data “are not logged into any persistent storage.” Serverless deployments maintain a separate cache for each Fireworks account. Fireworks’ zero-retention policy carves out what is necessary to provide the service (Section 3.6), and its Data Processing Addendum identifies prompt caching as such a feature (Section 4.5), so Fireworks-hosted GLM traffic runs under the zero-retention commitment as Fireworks defines it. Fireworks’ Terms of Service also reserve the right to use “safety screening tools on the Content as [Fireworks] deem[s] appropriate” (Section 3.6).

No Training on Your Data

Fireworks’ Terms of Service provide that “We will not use your Content to train our own models or to improve the Service,” and its Data Processing Addendum separately prohibits “using Covered Data to train, fine-tune, or otherwise improve any shared or foundational model” (Section 4.3(f)) — language not limited to Fireworks’ own models.

U.S.-Only Routing

Bells Up AI runs all Fireworks-hosted GLM inference through Fireworks’ US-only Serverless endpoint, the Fireworks product that “serves inference exclusively from the US.” See US-only Serverless, Fireworks AI documentation.

The Model Developer (Z.AI) Does Not Receive Your Data

Z.AI does not receive your prompts, documents, or the Fireworks-hosted GLM models’ responses, because Fireworks’ Data Processing Addendum restricts processing of your data to its authorized sub-processors, and neither Z.AI nor its parent company is one (Section 6.2 and Schedule 4).


Verify These Claims

We encourage you to review the source documents:

Source documents for verifying privacy claims
Document What It Covers Link
Amazon Bedrock Data Protection No-storage, no-training, no-access commitments (Bedrock-hosted GLM models) View
Amazon Web Services Service Terms Bedrock-specific terms (Section 50.12), abuse detection, metadata sharing View
Amazon Web Services Data Processing Addendum Amazon’s role as processor, access limitations View
Fireworks AI Terms of Service Zero-data-retention policy (Section 3.6); no training on your content (Fireworks-hosted GLM models) View
Fireworks AI Data Processing Addendum Retention limits (Section 4.5), prohibited uses (Section 4.3(f)), authorized sub-processors (Schedule 4) View
Amazon Bedrock Security & Compliance Certifications (SOC, ISO, HIPAA) View
Federal Register: Addition of Entities to the Entity List (90 FR 4617) BIS Entity List designation of Zhipu-affiliated entities (Jan. 16, 2025) View
China’s National Intelligence Law (English translation) Legal obligations on Chinese organizations View
NCSC/DNI Bulletin on PRC Laws US intelligence community analysis of Chinese data laws View

Questions?

If you have questions about how your data is protected when using GLM through Bells Up AI, contact us at info@bellsup.ai.


This disclosure covers GLM models accessed through Amazon Bedrock and Fireworks AI. It does not cover Z.AI’s direct services. See each model family’s disclosure for information about other models available through Bells Up AI.

This disclosure is provided for informational purposes. Bells Up AI does not provide legal advice to our customers, and attorneys selecting AI models should exercise their independent professional judgment regarding model selection. We believe prudent AI risk management practices include considering the risks of using particular models and assessing the applicability of specific regulatory and contracting requirements.

The regulatory and policy landscape for Chinese-origin AI models is evolving. Bells Up AI reviews this disclosure periodically, but attorneys should independently verify current regulatory requirements. The “Last Reviewed” date above reflects when this document was last updated.