Bells Up AI has enabled xAI’s Zero Data Retention (ZDR) for its Grok API use. Under ZDR, xAI does not retain your prompts or responses after your request is answered, does not use them to train its models, and does not derive “de-identified data” from them.
| Question | Answer |
|---|---|
| Does xAI retain your prompts or documents? | No — under the Zero Data Retention arrangement Bells Up AI has enabled, xAI does not retain your content after the request is answered (details) |
| Can xAI train AI on your prompts or documents? | No — prohibited by contract, and under ZDR your content is not retained to train on (details) |
| Can xAI create “de-identified data” from your content? | No — the de-identified-data provision expressly excludes ZDR traffic (details) |
| Can xAI employees or contractors review your data? | Under ZDR your content is not retained for review; xAI still applies automated safety screening while generating the response (details) |
| Can Amazon employees or contractors review your data? | Limited — Amazon provides only the hosting infrastructure and does not process your Grok requests (details) |
Your data is encrypted in transit (TLS) and at rest (AES-256). xAI, which processes your prompts, is SOC 2 Type 2 compliant; Amazon Web Services, which hosts the Bells Up AI application, holds SOC 2 and ISO 27001 certifications.
When you use xAI Grok models through Bells Up AI, three parties are involved in processing your request:
Each party operates under contractual obligations that protect your data. Below, we explain what each party can and cannot do with your data, with citations to the governing contracts.
What xAI Does: xAI develops the Grok family of AI models and operates the API infrastructure that processes your requests. When you submit a prompt through Bells Up AI, it is sent directly to xAI’s servers for processing. Bells Up AI’s use of the Grok API is governed by the xAI Enterprise Terms of Service, most recently updated August 14, 2026; this disclosure reflects those terms.
Bells Up AI uses xAI’s Zero Data Retention (ZDR) option for its Grok API access. xAI does not retain prompts or model responses after it answers the request. ZDR applies to Grok traffic sent through Bells Up AI.
xAI’s Enterprise Terms expressly exclude ZDR from the provision allowing xAI to derive “de-identified data” from customer usage:
“Except when Customer elects to use SpaceXAI’s Zero Data Retention-enabled APIs (‘ZDR-Enabled API’ or ‘ZDR’), SpaceXAI may create and use, for any lawful purpose, de-identified and/or aggregated data derived from Customer’s use of the Services …”
xAI returns an x-zero-data-retention header on each API response indicating whether ZDR was in effect.
The retention, de-identified-data, and review provisions below describe xAI’s default, non-ZDR API traffic. They do not apply to Grok traffic sent through Bells Up AI.
xAI’s Enterprise Terms of Service separately prohibit using your data to train AI models. The Enterprise Terms state:
“SpaceXAI will not use any User Content to train any foundation models, large language models, or other artificial intelligence systems or to develop any new products, services, or features, subject to disclosures to Customer and Customer-controlled user settings.”
xAI’s Enterprise FAQ also states:
“No, we do not use your business data, including inputs (prompts) or outputs (answers), for training our models.”
The FAQ permits xAI to offer free credits in exchange for permission to train on a customer’s business data. Bells Up AI does not participate in that arrangement.
Bells Up AI accesses Grok through the xAI Enterprise API, so this no-training commitment applies to use through our platform.
Consumer Grok services on grok.com and X have different terms. xAI may use consumer-service data for training unless users opt out. Bells Up AI uses the Enterprise API.
For customers that do not use ZDR, xAI’s Enterprise Terms permit xAI to derive “de-identified data” from customer usage for its own business purposes. The provision does not apply to xAI’s ZDR-Enabled API. Bells Up AI uses that API, so xAI does not create de-identified data from Grok traffic sent through our platform.
For non-ZDR customers, the terms define “de-identified” as data that is “irreversibly anonymized using industry-standard techniques, cannot be re-identified, and neither contains nor reveals any User Content or Confidential Information.” Earlier versions of the terms did not state this standard.
The xAI Enterprise Terms address ownership in Section 3.2:
“Customer (a) retains all right, title, and interest (including all intellectual-property rights) in and to the Input; and (b) owns all right, title, and interest in the Output in perpetuity and, to the fullest extent possible under applicable law, SpaceXAI hereby assigns to Customer all of its right, title, and interest in such Output (but excluding, for clarity, the SpaceXAI Technology (defined below)).”
Your rights:
The following describes xAI’s default retention terms for API customers that have not enabled ZDR. Bells Up AI has enabled ZDR, so this handling does not apply to Grok traffic sent through our platform; we include it for completeness.
Under the default terms, xAI retains API content temporarily for safety and compliance purposes: User Content is automatically deleted no later than 30 days after the end of the interaction, except where longer retention is agreed in an order form, required by law, or reasonably necessary for safety, security, compliance, moderation, abuse prevention, or investigating suspected violations — in which case xAI states it retains only the minimum data necessary and deletes it promptly once the justification no longer applies. This default retention is for safety and compliance, not for training.
xAI runs automated content classifiers and safety tools on API traffic to enforce its Acceptable Use Policy and Terms of Service:
“SpaceXAI may use automated content classifiers and safety tools to better understand how our services are used and to ensure our Terms of Service and Acceptable Use Policy are not being violated.”
This screening happens as the request is processed. Under ZDR, your content is not retained afterward, so it is not held for later human review.
xAI’s enterprise terms limit human access to customer data to specific circumstances:
“A limited number of authorized SpaceXAI personnel may review your data when legally required, such as investigating security incidents and potential misuse of our services.”
Because Bells Up AI uses ZDR, your prompts and responses are not retained after the request, so there is no stored content for xAI personnel to review after the fact. xAI does not sell your data or share it with third parties for marketing or advertising purposes (Enterprise FAQ).
xAI explicitly prohibits selling or sharing your data:
“No. We do not sell your data or share it with third parties for marketing or advertising purposes.”
xAI’s security documentation describes their infrastructure protections:
| Protection | Implementation |
|---|---|
| Encryption in transit | TLS encryption for all API communications |
| Encryption at rest | SSE-S3 (AES-256) for customer data stored in S3 |
| Access controls | Role-based access, single sign-on, hardware MFA |
| Infrastructure | Dedicated datacenter with 24/7 security personnel and monitoring |
| Logging | Security logs retained 180 days; data access logs retained 365 days |
“Customer archive data stored in S3 is encrypted at rest using server-side encryption with Amazon S3 managed keys (SSE-S3). The SpaceXAI web application and enterprise API are configured to use the TLS encryption protocol to encrypt communication sessions.”
xAI supports compliance with multiple regulatory frameworks:
SOC 2 Type 2:
“We are SOC 2 Type 2 compliant. Customers with a signed NDA can refer to our Trust Center for up-to-date information on our certifications and data governance.”
GDPR and Privacy Laws:
“Yes, if you submit personal data to our Services, our Data Processing Addendum (DPA) applies and is automatically incorporated into our Enterprise Terms of Service.”
Note on protected health information (PHI): Under the current Enterprise Terms, PHI may be submitted only by a customer that has both entered into a Business Associate Agreement (BAA) with xAI and uses xAI’s ZDR-Enabled API to submit that data. Bells Up AI does not have a BAA with xAI. Accordingly, if you are a HIPAA covered entity or business associate and your use of Grok through Bells Up AI would involve creating, receiving, maintaining, or transmitting PHI, the required HIPAA business associate agreement is not in place, and you should not submit that PHI to Grok through Bells Up AI. Whether this restriction applies turns on your own status and obligations under HIPAA, not on a limitation specific to Grok.
The consumer Grok product (grok.com and X platform integration) has been the subject of regulatory scrutiny in multiple jurisdictions. These proceedings concern the consumer product’s data practices — including image generation, training data, and privacy impact assessments — and do not affect the Enterprise API terms that govern Bells Up AI’s access. All matters listed below are ongoing and unresolved unless otherwise noted.
Separately, beyond the consumer product, xAI has litigated against new state AI laws. xAI sued to block the Colorado AI Act; the U.S. Department of Justice intervened on xAI’s side (April 2026), and enforcement of that law was stayed. xAI also challenged California’s AI training-data transparency law (AB 2013); a court denied xAI’s request for a preliminary injunction (March 2026), and the case has since moved to the federal court of appeals.
These matters reflect the broader regulatory environment around xAI. Bells Up AI monitors xAI’s regulatory landscape as part of our ongoing vendor assessment.
Bells Up AI’s use of the xAI API is governed by:
Note: xAI’s general Privacy Policy explicitly states it “does not apply to data that we process on behalf of customers of our business offerings, such as the SpaceXAI API.” API data handling is governed by the Enterprise Terms and DPA instead.
When you use Grok models through Bells Up AI, your prompts travel directly from our application to xAI’s servers. Amazon does not process your AI requests.
Amazon provides the computing resources and storage that our application uses. Under the AWS Shared Responsibility Model:
Amazon operates the physical servers and storage infrastructure we use. Amazon’s access to data stored on its infrastructure is governed by contract and verified by independent audits:
“[Amazon] will not access or use Customer Data except as necessary to maintain or provide the Services, or as necessary to comply with the law or a binding order of a governmental body.”
This prohibits Amazon from using your data to develop Amazon’s own AI or other products, or from providing your data to others for such purposes.
Amazon’s SOC 2 Type II certification provides independent verification that Amazon maintains and follows these access controls.
| Protection | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all communications |
| Encryption at rest | AES-256 for all stored data |
| Server storage | Encrypted at the hardware level |
| Access controls | Credentials managed through Amazon’s identity system; no hardcoded passwords |
Bells Up AI’s use of Amazon services is governed by:
Under the Data Processing Addendum, Amazon acts as a “data processor” — meaning Amazon processes data on our behalf according to our instructions, rather than controlling or owning the data.
We encourage you to review the source documents:
| Document | What It Covers | Link |
|---|---|---|
| xAI Enterprise Terms of Service | Zero Data Retention, no-training commitment, content ownership, data retention, license grants | View |
| xAI Enterprise FAQ | Training commitments, data retention, human review, compliance | View |
| xAI Security FAQ | Zero Data Retention configuration and verification, SOC 2 compliance | View |
| xAI Acceptable Use Policy | Prohibited uses, content guidelines | View |
| xAI Data Processing Addendum | GDPR/CCPA compliance, data processing obligations, security measures | View |
| AWS Data Processing Addendum | Amazon’s data handling, confidentiality commitments | View |
If you have questions about how your data is protected when using Grok models through Bells Up AI, contact us at info@bellsup.ai.
This document describes data handling for xAI Grok models accessed via the xAI Enterprise API. Other models available through Bells Up AI have different data flows; see the privacy information page for each model family.
This disclosure is for informational purposes. Bells Up AI does not provide legal advice to our customers, and attorneys selecting AI models should exercise their independent professional judgment regarding model selection. We believe prudent AI risk management practices include considering the risks of using particular models and assessing the applicability of specific regulatory and contracting requirements.