Last Reviewed: September 10, 2026

At a Glance

Bells Up AI has enabled xAI’s Zero Data Retention (ZDR) for its Grok API use. Under ZDR, xAI does not retain your prompts or responses after your request is answered, does not use them to train its models, and does not derive “de-identified data” from them.

At a glance: xAI (Grok) privacy practices
QuestionAnswer
Does xAI retain your prompts or documents?No — under the Zero Data Retention arrangement Bells Up AI has enabled, xAI does not retain your content after the request is answered (details)
Can xAI train AI on your prompts or documents?No — prohibited by contract, and under ZDR your content is not retained to train on (details)
Can xAI create “de-identified data” from your content?No — the de-identified-data provision expressly excludes ZDR traffic (details)
Can xAI employees or contractors review your data?Under ZDR your content is not retained for review; xAI still applies automated safety screening while generating the response (details)
Can Amazon employees or contractors review your data?Limited — Amazon provides only the hosting infrastructure and does not process your Grok requests (details)

Your data is encrypted in transit (TLS) and at rest (AES-256). xAI, which processes your prompts, is SOC 2 Type 2 compliant; Amazon Web Services, which hosts the Bells Up AI application, holds SOC 2 and ISO 27001 certifications.


The Three Parties Involved

When you use xAI Grok models through Bells Up AI, three parties are involved in processing your request:

  1. xAI is the Model Developer and Service Operator — the company that created and trained the Grok family of AI models and operates the API infrastructure that processes your requests. SpaceX acquired xAI in a transaction that closed February 2, 2026; xAI now operates as a wholly owned SpaceX subsidiary under the legal name “SpaceXAI LLC,” and in turn owns X Corp. (formerly Twitter), which operates the consumer X platform. Your Grok requests through Bells Up AI are governed by xAI’s Enterprise API terms, which remain distinct from the consumer X and Grok services described below.
  2. Amazon is Bells Up AI’s Infrastructure Provider. Amazon Web Services (AWS) provides the servers, storage, and networking that host the Bells Up AI application. Chats, workflows, and document analysis go directly from our application to xAI’s servers; they do not use Amazon’s AI services. The optional “Improve my prompt” tool sends the draft prompt to Amazon Bedrock’s prompt-optimization service. The tool sends your draft prompt to Amazon Bedrock regardless of the model you select. Conversations, documents, and workflow runs are not sent to that service.
  3. Bells Up AI (“we” or “us”) — We built and operate the application you are using.

Each party operates under contractual obligations that protect your data. Below, we explain what each party can and cannot do with your data, with citations to the governing contracts.


xAI: The Model Developer and Service Operator

What xAI Does: xAI develops the Grok family of AI models and operates the API infrastructure that processes your requests. When you submit a prompt through Bells Up AI, it is sent directly to xAI’s servers for processing. Bells Up AI’s use of the Grok API is governed by the xAI Enterprise Terms of Service, most recently updated August 14, 2026; this disclosure reflects those terms.

Zero Data Retention

Bells Up AI uses xAI’s Zero Data Retention (ZDR) option for its Grok API access. xAI does not retain prompts or model responses after it answers the request. ZDR applies to Grok traffic sent through Bells Up AI.

xAI’s Enterprise Terms expressly exclude ZDR from the provision allowing xAI to derive “de-identified data” from customer usage:

“Except when Customer elects to use SpaceXAI’s Zero Data Retention-enabled APIs (‘ZDR-Enabled API’ or ‘ZDR’), SpaceXAI may create and use, for any lawful purpose, de-identified and/or aggregated data derived from Customer’s use of the Services …”

— xAI Enterprise Terms of Service

xAI returns an x-zero-data-retention header on each API response indicating whether ZDR was in effect.

The retention, de-identified-data, and review provisions below describe xAI’s default, non-ZDR API traffic. They do not apply to Grok traffic sent through Bells Up AI.

No Training on Your Data

xAI’s Enterprise Terms of Service separately prohibit using your data to train AI models. The Enterprise Terms state:

“SpaceXAI will not use any User Content to train any foundation models, large language models, or other artificial intelligence systems or to develop any new products, services, or features, subject to disclosures to Customer and Customer-controlled user settings.”

— xAI Enterprise Terms of Service

xAI’s Enterprise FAQ also states:

“No, we do not use your business data, including inputs (prompts) or outputs (answers), for training our models.”

— xAI Enterprise FAQ

The FAQ permits xAI to offer free credits in exchange for permission to train on a customer’s business data. Bells Up AI does not participate in that arrangement.

Bells Up AI accesses Grok through the xAI Enterprise API, so this no-training commitment applies to use through our platform.

Consumer Grok services on grok.com and X have different terms. xAI may use consumer-service data for training unless users opt out. Bells Up AI uses the Enterprise API.

De-Identified Data

For customers that do not use ZDR, xAI’s Enterprise Terms permit xAI to derive “de-identified data” from customer usage for its own business purposes. The provision does not apply to xAI’s ZDR-Enabled API. Bells Up AI uses that API, so xAI does not create de-identified data from Grok traffic sent through our platform.

For non-ZDR customers, the terms define “de-identified” as data that is “irreversibly anonymized using industry-standard techniques, cannot be re-identified, and neither contains nor reveals any User Content or Confidential Information.” Earlier versions of the terms did not state this standard.

Content Ownership

The xAI Enterprise Terms address ownership in Section 3.2:

“Customer (a) retains all right, title, and interest (including all intellectual-property rights) in and to the Input; and (b) owns all right, title, and interest in the Output in perpetuity and, to the fullest extent possible under applicable law, SpaceXAI hereby assigns to Customer all of its right, title, and interest in such Output (but excluding, for clarity, the SpaceXAI Technology (defined below)).”

— xAI Enterprise Terms of Service, Section 3.2

Your rights:

Data Retention Under the Default (Non-ZDR) Terms

The following describes xAI’s default retention terms for API customers that have not enabled ZDR. Bells Up AI has enabled ZDR, so this handling does not apply to Grok traffic sent through our platform; we include it for completeness.

Under the default terms, xAI retains API content temporarily for safety and compliance purposes: User Content is automatically deleted no later than 30 days after the end of the interaction, except where longer retention is agreed in an order form, required by law, or reasonably necessary for safety, security, compliance, moderation, abuse prevention, or investigating suspected violations — in which case xAI states it retains only the minimum data necessary and deletes it promptly once the justification no longer applies. This default retention is for safety and compliance, not for training.

Automated Safety Screening

xAI runs automated content classifiers and safety tools on API traffic to enforce its Acceptable Use Policy and Terms of Service:

“SpaceXAI may use automated content classifiers and safety tools to better understand how our services are used and to ensure our Terms of Service and Acceptable Use Policy are not being violated.”

— xAI Enterprise FAQ

This screening happens as the request is processed. Under ZDR, your content is not retained afterward, so it is not held for later human review.

Who Can Access Your Data at xAI

xAI’s enterprise terms limit human access to customer data to specific circumstances:

“A limited number of authorized SpaceXAI personnel may review your data when legally required, such as investigating security incidents and potential misuse of our services.”

— xAI Enterprise FAQ

Because Bells Up AI uses ZDR, your prompts and responses are not retained after the request, so there is no stored content for xAI personnel to review after the fact. xAI does not sell your data or share it with third parties for marketing or advertising purposes (Enterprise FAQ).

Data Sharing

xAI explicitly prohibits selling or sharing your data:

“No. We do not sell your data or share it with third parties for marketing or advertising purposes.”

— xAI Enterprise FAQ

Technical Protections

xAI’s security documentation describes their infrastructure protections:

Technical protections: encryption and access controls
Protection Implementation
Encryption in transitTLS encryption for all API communications
Encryption at restSSE-S3 (AES-256) for customer data stored in S3
Access controlsRole-based access, single sign-on, hardware MFA
InfrastructureDedicated datacenter with 24/7 security personnel and monitoring
LoggingSecurity logs retained 180 days; data access logs retained 365 days

“Customer archive data stored in S3 is encrypted at rest using server-side encryption with Amazon S3 managed keys (SSE-S3). The SpaceXAI web application and enterprise API are configured to use the TLS encryption protocol to encrypt communication sessions.”

— xAI Security

Compliance Frameworks

xAI supports compliance with multiple regulatory frameworks:

SOC 2 Type 2:

“We are SOC 2 Type 2 compliant. Customers with a signed NDA can refer to our Trust Center for up-to-date information on our certifications and data governance.”

— xAI Security FAQ

GDPR and Privacy Laws:

“Yes, if you submit personal data to our Services, our Data Processing Addendum (DPA) applies and is automatically incorporated into our Enterprise Terms of Service.”

— xAI Enterprise FAQ

Note on protected health information (PHI): Under the current Enterprise Terms, PHI may be submitted only by a customer that has both entered into a Business Associate Agreement (BAA) with xAI and uses xAI’s ZDR-Enabled API to submit that data. Bells Up AI does not have a BAA with xAI. Accordingly, if you are a HIPAA covered entity or business associate and your use of Grok through Bells Up AI would involve creating, receiving, maintaining, or transmitting PHI, the required HIPAA business associate agreement is not in place, and you should not submit that PHI to Grok through Bells Up AI. Whether this restriction applies turns on your own status and obligations under HIPAA, not on a limitation specific to Grok.

Consumer Grok Regulatory Activity

The consumer Grok product (grok.com and X platform integration) has been the subject of regulatory scrutiny in multiple jurisdictions. These proceedings concern the consumer product’s data practices — including image generation, training data, and privacy impact assessments — and do not affect the Enterprise API terms that govern Bells Up AI’s access. All matters listed below are ongoing and unresolved unless otherwise noted.

Separately, beyond the consumer product, xAI has litigated against new state AI laws. xAI sued to block the Colorado AI Act; the U.S. Department of Justice intervened on xAI’s side (April 2026), and enforcement of that law was stayed. xAI also challenged California’s AI training-data transparency law (AB 2013); a court denied xAI’s request for a preliminary injunction (March 2026), and the case has since moved to the federal court of appeals.

These matters reflect the broader regulatory environment around xAI. Bells Up AI monitors xAI’s regulatory landscape as part of our ongoing vendor assessment.

Governing Agreements

Bells Up AI’s use of the xAI API is governed by:

Note: xAI’s general Privacy Policy explicitly states it “does not apply to data that we process on behalf of customers of our business offerings, such as the SpaceXAI API.” API data handling is governed by the Enterprise Terms and DPA instead.


Amazon: Bells Up AI’s Infrastructure Provider

What Amazon Does NOT Do

When you use Grok models through Bells Up AI, your prompts travel directly from our application to xAI’s servers. Amazon does not process your AI requests.

Amazon’s Role is Limited to Infrastructure

Amazon provides the computing resources and storage that our application uses. Under the AWS Shared Responsibility Model:

Can Amazon Access Bells Up AI’s Infrastructure?

Amazon operates the physical servers and storage infrastructure we use. Amazon’s access to data stored on its infrastructure is governed by contract and verified by independent audits:

“[Amazon] will not access or use Customer Data except as necessary to maintain or provide the Services, or as necessary to comply with the law or a binding order of a governmental body.”

— Amazon Web Services Data Processing Addendum

This prohibits Amazon from using your data to develop Amazon’s own AI or other products, or from providing your data to others for such purposes.

Amazon’s SOC 2 Type II certification provides independent verification that Amazon maintains and follows these access controls.

Technical Protections

Technical protections: encryption and access controls
Protection Implementation
Encryption in transitTLS 1.2+ for all communications
Encryption at restAES-256 for all stored data
Server storageEncrypted at the hardware level
Access controlsCredentials managed through Amazon’s identity system; no hardcoded passwords

Governing Agreements

Bells Up AI’s use of Amazon services is governed by:

Under the Data Processing Addendum, Amazon acts as a “data processor” — meaning Amazon processes data on our behalf according to our instructions, rather than controlling or owning the data.


Verify These Claims

We encourage you to review the source documents:

Source documents for verifying privacy claims
Document What It Covers Link
xAI Enterprise Terms of Service Zero Data Retention, no-training commitment, content ownership, data retention, license grants View
xAI Enterprise FAQ Training commitments, data retention, human review, compliance View
xAI Security FAQ Zero Data Retention configuration and verification, SOC 2 compliance View
xAI Acceptable Use Policy Prohibited uses, content guidelines View
xAI Data Processing Addendum GDPR/CCPA compliance, data processing obligations, security measures View
AWS Data Processing Addendum Amazon’s data handling, confidentiality commitments View

Questions?

If you have questions about how your data is protected when using Grok models through Bells Up AI, contact us at info@bellsup.ai.


This document describes data handling for xAI Grok models accessed via the xAI Enterprise API. Other models available through Bells Up AI have different data flows; see the privacy information page for each model family.

This disclosure is for informational purposes. Bells Up AI does not provide legal advice to our customers, and attorneys selecting AI models should exercise their independent professional judgment regarding model selection. We believe prudent AI risk management practices include considering the risks of using particular models and assessing the applicability of specific regulatory and contracting requirements.