"Llama" refers to the AI models; "Meta" is the company that developed them. The Llama AI models are software (large language models) that generate responses to your prompts. Meta is based in the United States.
Bells Up AI runs the Llama AI models on Amazon's servers in the United States. Meta itself never receives your prompts, your documents, or the models' responses.
Your data never leaves Amazon's infrastructure. Meta has zero access to your prompts or responses.
| Question | Answer |
|---|---|
| Can Meta access your prompts or documents? | No — Meta never receives them |
| Can Meta train AI on your prompts or documents? | No — Meta has zero access |
| Can Meta employees or contractors review your data? | No — Meta has zero access |
| How long does Meta retain your data? | N/A — Meta never receives your data |
| Does Amazon Bedrock store your prompts or documents? | No — Amazon Bedrock applies zero data retention by default (not stored) |
| Does Amazon train AI on your data? | No — prohibited by contract |
| Does Amazon scan your data for abuse? | Yes — automated scanning under AWS's zero operator access (ZOA) model; no operators can access your inputs or outputs (details) |
| Can Amazon employees or contractors review your prompts or responses? | No — under AWS's zero operator access (ZOA) model, no operators can access your inputs or outputs; content flagged as apparent CSAM may be reviewed for confirmation and reporting, and flagged traffic for a short list of models (none offered by Bells Up AI) may also be reviewed. Access to data stored on Amazon's infrastructure is separately limited (details) |
Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Amazon Web Services — the cloud provider that runs the model and where your prompts are processed — holds SOC 2 and ISO 27001 certifications.
When you use the Llama family of AI models through Bells Up AI, three parties are involved in processing your request:
Each party operates under contractual obligations that protect your data. Below, we explain what each party can and cannot do with your data, with citations to the governing contracts.
What Meta Does: Meta develops and trains the Llama family of AI models. Meta distributes the trained model weights under the Llama Community License Agreement, and Amazon deploys those weights on Amazon's own infrastructure.
Meta cannot access your prompts, documents, or Llama's responses. This is a technical restriction — Meta has no access to the Amazon infrastructure where Llama is deployed, and no runtime connection to the inference process.
Because Llama is an open-weight model, Meta's involvement is limited to distributing the model weights. Once Amazon deploys those weights into its infrastructure, Meta has no mechanism to receive, intercept, or monitor inference data. In order to run AI models like the Llama models you access through Bells Up AI, Amazon maintains "Model Deployment Accounts", which model developers like Meta do not have access to:
"Model providers don't have any access to those accounts. After delivery of a model from a model provider to [Amazon], Amazon Bedrock will perform a deep copy of a model provider's inference and training software into those accounts for deployment. Because the model providers don't have access to those accounts, they don't have access to Amazon Bedrock logs or to customer prompts and completions."
Meta cannot train on your data because Meta never receives it. Amazon Bedrock explicitly commits that neither Amazon nor third-party model providers use customer data for training:
"AWS and the third-party model providers will not use any inputs to or outputs from Amazon Bedrock to train Amazon Nova, Amazon Titan, or any third-party models."
The Llama models available through Bells Up AI are Llama 4 Scout and Llama 4 Maverick, licensed under the Llama 4 Community License (April 5, 2025), and Llama 3.3 70B, offered as a legacy option and licensed under the Llama 3.3 Community License (December 6, 2024). Both licenses are weight-distribution licenses — they grant rights to use, reproduce, and modify the model — and both are materially identical on data handling. Amazon is retiring several older Llama model families from Amazon Bedrock: Llama 3.1 405B and the Llama 3.2 family reach end of life on July 7, 2026. None of those models were ever offered through Bells Up AI. Each license contains:
The license does not restrict using Llama outputs to train other models. It imposes only an attribution requirement — any AI model trained or improved using Llama outputs must include "Llama" at the beginning of its name. This requirement governs the licensee's conduct and grants Meta no access to your prompts, documents, or the model's responses.
Attorneys evaluating trust should be aware of Meta's corporate privacy history. Meta (formerly Facebook) has accumulated over $7 billion in privacy-related fines and settlements, among the most of any technology company:
| Year | Event | Amount |
|---|---|---|
| 2019 | FTC settlement — Cambridge Analytica / privacy violations | $5 billion |
| 2023 | Irish DPC — unlawful EU-to-US data transfers (largest GDPR fine ever) | €1.2 billion |
| 2024 | Texas AG — unlawful biometric data collection (settlement finalized; being paid in installments through 2028) | $1.4 billion |
| 2024 | Irish DPC — 2018 Facebook breach (29M users) | €251 million |
| Various | Additional Irish and UK fines for transparency and data minimization | €500M+ collectively |
Pending and preliminary matters (not fines): Two additional matters involving Meta remain unresolved as of July 7, 2026. On April 29, 2026, the European Commission issued preliminary findings that Meta breached the Digital Services Act's protections for minors. This is a preliminary stage: Meta may respond, and no final decision or fine has been issued. Separately, the U.S. Federal Trade Commission has moved to reopen and modify its 2020 privacy consent order with Meta; that proceeding is currently stayed and remains unresolved.
All of these enforcement actions involved Meta's own consumer platforms — Facebook, Instagram, WhatsApp — where Meta directly processes user data. They reflect a corporate pattern of prioritizing data monetization over user privacy on platforms Meta controls.
Via Amazon Bedrock, Meta is not in the data path. Meta does not process, receive, store, or have access to your prompts, documents, or Llama's responses. The trust relationship for data handling is between you and AWS, not between you and Meta. Meta's privacy record is relevant context for evaluating the company, but the architectural isolation means it does not create a direct data risk for Bedrock users.
Amazon provides two distinct services relevant to how your data is handled:
What Amazon Bedrock Does: Amazon Bedrock is the service that hosts and runs the Llama AI models. When you submit a prompt, Bells Up AI sends it to Amazon Bedrock, which processes it through Llama and returns the response.
Amazon Bedrock's Core Commitments:
No Storage of Your Prompts or Responses:
"Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output. Also, Amazon Bedrock uses a zero data retention (ZDR) data security model. This means that by default, Amazon Bedrock does not store model inputs or outputs."
No Training on Your Data:
Amazon does not use your prompts and responses to train its own models, and does not share them with the model provider. AWS states that retained inputs and outputs (for the limited set of models that require retention) are "stored and processed by AWS and are not shared with third-party model providers."
Data Stays in the United States: Bells Up AI accesses Llama through a US cross-region inference profile on Amazon Bedrock. Each request is processed in one of the profile's US regions — us-east-1 (Northern Virginia), us-east-2 (Ohio), or us-west-2 (Oregon) — as AWS selects for capacity. Your data is not routed outside the United States; data stored at rest remains in the source region.
The optional “Improve my prompt” tool sends the draft prompt to Amazon Bedrock’s prompt-optimization service. The tool sends your draft prompt to Amazon Bedrock regardless of the model you select. Conversations, documents, and workflow runs are processed by the model you selected.
Amazon Bedrock runs automated content scanning on data processed through the service. If that scanning flags apparent child sexual abuse material, the AWS Service Terms provide:
"If we detect apparent child sexual abuse material ("CSAM"), you agree and instruct that we may: (a) review the flagged input or output to determine if it is CSAM, and (b) report the incident to the National Center for Missing and Exploited Children or other authority."
The Service Terms also provide that, for certain models identified on Amazon's Bedrock abuse-detection documentation, Amazon Bedrock stores inputs and outputs for up to 30 days to detect terms-of-service violations and may review them if a potential violation is detected. None of the models available through Bells Up AI are identified on that list as of this review.
Apart from these provisions, Amazon's abuse-detection documentation describes a zero operator access (ZOA) model:
"Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output."
What this means:
This automated scanning is narrower in scope than the abuse monitoring systems used by direct API providers like OpenAI or Google, which retain data for up to 30 or 55 days and may involve human review of flagged content. Amazon Bedrock's abuse detection operates at the infrastructure level and does not involve the model provider (Meta).
While Meta never receives the content of your prompts or responses, Amazon may share non-content usage information with third-party model providers:
"We may share information, that does not include Your Content, about your use of a third-party model with the provider of that third-party model."
This metadata may include identifiers such as Bells Up AI's AWS Account ID, the AWS region, the model used, request counts, token usage, and timestamps. It contains no content from your prompts, documents, or responses.
What This Means: Separately from Amazon Bedrock, the Bells Up AI application itself runs on Amazon's cloud infrastructure. This includes:
Can Amazon Access This Data?
Amazon operates the physical servers and storage infrastructure we use. Amazon's access to data stored on its infrastructure is governed by contract and verified by independent audits, which test whether Amazon's actual practices match its contractual commitments:
"AWS will not access or use, or disclose to any third party, any Customer Data, except, in each case, as necessary to maintain or provide the Services, or as necessary to comply with the law or a valid and binding order of a governmental body (such as a subpoena or court order)."
This prohibits Amazon from using your data to develop Amazon's own AI or other products, or from providing your data to others for such purposes.
Amazon's SOC 2 Type II certification provides independent verification that Amazon maintains and follows these access controls.
Technical Protections:
| Protection | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all communications |
| Encryption at rest | AES-256 for all stored data |
| Server storage | Encrypted at the hardware level |
| Access controls | Credentials managed through Amazon's identity system; no hardcoded passwords |
Bells Up AI's use of Amazon services is governed by:
Under the Data Processing Addendum, Amazon acts as a "data processor" — meaning Amazon processes data on our behalf according to our instructions, rather than controlling or owning the data.
Amazon Bedrock and the underlying infrastructure maintain the following certifications:
We encourage you to review the source documents:
| Document | What It Covers | Link |
|---|---|---|
| Llama Community License Agreement | Model weight distribution terms, no data collection provisions | View |
| Amazon Bedrock Data Protection | No-storage, no-training, no-access commitments | View |
| Amazon Web Services Service Terms | Bedrock-specific terms (Section 50.12), abuse detection, metadata sharing | View |
| Amazon Web Services Data Processing Addendum | Amazon's role as processor, access limitations | View |
| Amazon Bedrock Security & Compliance | Certifications (SOC, ISO, HIPAA) | View |
If you have questions about how your data is protected when using Llama through Bells Up AI, contact us at info@bellsup.ai.
This document describes data handling for Meta Llama models accessed via Amazon Bedrock. Other models available through Bells Up AI have different data flows — see the privacy information page for each model family.
This disclosure is provided for informational purposes. Bells Up AI does not provide legal advice to our customers, and attorneys selecting AI models should exercise their independent professional judgment regarding model selection. We believe prudent AI risk management practices include considering the risks of using particular models and assessing the applicability of specific regulatory and contracting requirements.