Last Reviewed: September 7, 2026

At a Glance

Your data is processed on OpenAI's servers. OpenAI may retain your data for up to 30 days, and content flagged by OpenAI's automated abuse detection systems may be reviewed by OpenAI employees or contractors.

At a glance: OpenAI privacy practices
QuestionAnswer
Can OpenAI access your prompts?Yes — retained up to 30 days (details)
Can OpenAI train AI on your data?No — prohibited by contract
Can OpenAI employees review your data?Potentially — if flagged by automated systems (details)
How long does OpenAI retain data?Up to 30 days for abuse monitoring
Can Amazon employees review your data?Limited (details)

Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). OpenAI, which processes your prompts, and Amazon Web Services, which hosts the Bells Up AI application, each hold SOC 2 and ISO 27001 certifications.


The Three Parties Involved

When you use OpenAI models (GPT-5, GPT-4.1, GPT-4o, etc.) through Bells Up AI, three parties are involved in processing your request:

  1. OpenAI is the Model Developer and Service Operator — the company that created and trained the GPT family of AI models and operates the API infrastructure that processes your requests.
  2. Amazon is Bells Up AI’s Infrastructure Provider. Amazon Web Services (AWS) provides the servers, storage, and networking that host the Bells Up AI application. Chats, workflows, and document analysis go directly from our application to OpenAI’s servers; they do not use Amazon’s AI services. The optional “Improve my prompt” tool sends the draft prompt to Amazon Bedrock’s prompt-optimization service. The tool sends your draft prompt to Amazon Bedrock regardless of the model you select. Conversations, documents, and workflow runs are not sent to that service.
  3. Bells Up AI ("we" or "us") — We built and operate the application you are using.

Each party operates under contractual obligations that protect your data. Below, we explain what each party can and cannot do with your data, with citations to the governing contracts.


OpenAI: The Model Developer and Service Operator

What OpenAI Does: OpenAI develops the GPT family of AI models and operates the API infrastructure that processes your requests. When you submit a prompt through Bells Up AI, it is sent directly to OpenAI's servers for processing.

No Training on Your Data

OpenAI's Services Agreement limits how OpenAI may use your data, and bars using it to develop or improve OpenAI's services unless you explicitly agree:

"OpenAI will only use Customer Content as necessary to provide Customer with the Services, comply with applicable law, enforce the OpenAI Policies, and prevent abuse. OpenAI will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees to such use."

— OpenAI Services Agreement, Section 4.2 (effective January 1, 2026)

"Develop or improve the Services" includes training OpenAI's AI models. Bells Up AI has not agreed to any such use of your data.

This is reinforced in OpenAI's enterprise privacy documentation:

"By default, we do not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers, or our API platform—including inputs or outputs—for training or improving our models."

— OpenAI Business Data Privacy

Why this applies to you: Bells Up AI uses the OpenAI API (not consumer ChatGPT), so this no-training commitment applies to your usage through our platform.

Content Ownership

The OpenAI Services Agreement is clear on ownership:

"As between Customer and OpenAI, to the extent permitted by applicable law, Customer: (a) retains all ownership rights in Input; and (b) owns all Output. OpenAI hereby assigns to Customer all OpenAI's right, title, and interest, if any, in and to Output."

— OpenAI Services Agreement, Section 4.1

Your rights:

Data Retention: The 30-Day Window

OpenAI retains API data temporarily for abuse monitoring purposes:

"OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse. After 30 days, API inputs and outputs are removed from our systems, unless we are legally required to retain them."

— OpenAI Enterprise Privacy

What this means:

Automated Processing of Your Data

OpenAI runs automated content classification systems on all API data:

"We may run any business data submitted to OpenAI's services through automated content classifiers and safety tools, including to better understand how our services are used. The classifications created are metadata about the business data but do not contain any of the business data itself."

— OpenAI Enterprise Privacy

What OpenAI's automated classifiers look for:

Based on OpenAI's public Moderation API documentation, automated classifiers detect content in these categories:

What this means for legal work:

These classifiers generate flags based on content patterns, not context. A contract describing fraud allegations, a litigation memo discussing violent crimes, or a healthcare privacy agreement referencing medical conditions could trigger classifier flags—even though the content is legitimate legal work.

The classifier creates metadata (flags, severity scores) but does not copy your actual content into the metadata. However, if content is flagged, it may be subject to further review (see below).

Who Can Access Your Data at OpenAI

OpenAI's enterprise terms limit human access to your data to specific circumstances:

"Our access to API business data stored on our systems is limited to (1) authorized employees that require access for engineering support, investigating potential platform abuse, and legal compliance and (2) specialized third-party contractors who are bound by confidentiality and security obligations, solely to review for abuse and misuse."

— OpenAI Enterprise Privacy

Personnel permitted to access data and under what circumstances
WhoPermitted AccessUnder What Circumstances
Authorized employeesEngineering supportAs required to support service delivery
Authorized employeesAbuse investigationWhen automated systems flag potential policy violations
Authorized employeesLegal complianceWhen required by law or legal process
Third-party contractorsAbuse and misuse reviewTo review content flagged for policy violations (under confidentiality obligations)

OpenAI's Services Agreement further provides that content determined to violate OpenAI's policies ("Abusive Customer Content") may be retained beyond the standard 30-day retention period — including after account termination — "as required by law, or as reasonably necessary to protect the Services or any third party from harm" (Services Agreement, Section 11.3).

Contractual restrictions: OpenAI's Services Agreement prohibits using your data to train or improve AI models unless you explicitly agree (Section 4.2). Access is limited to personnel with a need to know, bound by confidentiality obligations at least as restrictive as those in the Services Agreement (Section 7.3).

As noted above, automated content classifiers may flag legitimate legal work. Flagged content is subject to review by OpenAI personnel or contractors under these access provisions.

Technical Protections

Technical protections: encryption and access controls
ProtectionImplementation
Encryption in transitTLS 1.2+ for all API communications
Encryption at restAES-256 during the retention period
Access controlsLimited to authorized personnel with confidentiality obligations
ComplianceSOC 2 Type 2, ISO 27001/27017/27018/27701 certified

Governing Agreements

Bells Up AI's use of the OpenAI API is governed by:

Under the Data Processing Addendum, OpenAI commits to:

Compliance Certifications

OpenAI maintains the following certifications:

See: OpenAI Trust Portal


Amazon: Our Infrastructure Provider

What Amazon Does: Amazon provides the cloud infrastructure where the Bells Up AI application runs. This includes:

What Amazon Does NOT Do

When you use OpenAI models through Bells Up AI, your prompts travel directly from our application to OpenAI's servers. Amazon does not process your AI requests.

Amazon's Role is Limited to Infrastructure

Amazon provides the computing resources and storage that our application uses. Under the AWS Shared Responsibility Model:

Can Amazon Access Bells Up AI's Infrastructure?

Amazon operates the physical servers and storage infrastructure we use. Amazon's access to data stored on its infrastructure is governed by contract and verified by independent audits:

"[Amazon] will not access or use Customer Data except as necessary to maintain or provide the Services, or as necessary to comply with the law or a binding order of a governmental body."

— Amazon Web Services Data Processing Addendum

This prohibits Amazon from using your data to develop Amazon's own AI or other products, or from providing your data to others for such purposes.

Amazon's SOC 2 Type II certification provides independent verification that Amazon maintains and follows these access controls.

Technical Protections

Technical protections: encryption and access controls
ProtectionImplementation
Encryption in transitTLS 1.2+ for all communications
Encryption at restAES-256 for all stored data
Server storageEncrypted at the hardware level
Access controlsCredentials managed through Amazon's identity system; no hardcoded passwords

Governing Agreements

Bells Up AI's use of Amazon services is governed by:

Under the Data Processing Addendum, Amazon acts as a "data processor" — meaning Amazon processes data on our behalf according to our instructions, rather than controlling or owning the data.


Verify These Claims

We encourage you to review the source documents:

Source documents for verifying privacy claims
DocumentWhat It CoversLink
OpenAI Services AgreementMaster contract: no-training commitment, content ownership, data handlingView
OpenAI Enterprise PrivacyData retention, access controls, privacy commitmentsView
OpenAI Service TermsFeature-specific terms for particular OpenAI products, separate from the Services AgreementView
OpenAI Data Processing AddendumGDPR/CCPA compliance, data handling obligationsView
OpenAI Business Data PrivacyTraining commitments, encryption, certificationsView
OpenAI Trust PortalSecurity certifications and complianceView
AWS Data Processing AddendumAmazon's data handling, confidentiality commitmentsView

Questions?

If you have questions about how your data is protected when using OpenAI models through Bells Up AI, contact us at info@bellsup.ai.


This document describes data handling for OpenAI models accessed via the OpenAI API. Other models available through Bells Up AI have different data flows — see the privacy information page for each model family.

This disclosure is provided for informational purposes. Bells Up AI does not provide legal advice to our customers, and attorneys selecting AI models should exercise their independent professional judgment regarding model selection. We believe prudent AI risk management practices include considering the risks of using particular models and assessing the applicability of specific regulatory and contracting requirements.