Your data is processed on OpenAI's servers. OpenAI may retain your data for up to 30 days, and content flagged by OpenAI's automated abuse detection systems may be reviewed by OpenAI employees or contractors.
| Question | Answer |
|---|---|
| Can OpenAI access your prompts? | Yes — retained up to 30 days (details) |
| Can OpenAI train AI on your data? | No — prohibited by contract |
| Can OpenAI employees review your data? | Potentially — if flagged by automated systems (details) |
| How long does OpenAI retain data? | Up to 30 days for abuse monitoring |
| Can Amazon employees review your data? | Limited (details) |
Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). OpenAI, which processes your prompts, and Amazon Web Services, which hosts the Bells Up AI application, each hold SOC 2 and ISO 27001 certifications.
When you use OpenAI models (GPT-5, GPT-4.1, GPT-4o, etc.) through Bells Up AI, three parties are involved in processing your request:
Each party operates under contractual obligations that protect your data. Below, we explain what each party can and cannot do with your data, with citations to the governing contracts.
What OpenAI Does: OpenAI develops the GPT family of AI models and operates the API infrastructure that processes your requests. When you submit a prompt through Bells Up AI, it is sent directly to OpenAI's servers for processing.
OpenAI's Services Agreement limits how OpenAI may use your data, and bars using it to develop or improve OpenAI's services unless you explicitly agree:
"OpenAI will only use Customer Content as necessary to provide Customer with the Services, comply with applicable law, enforce the OpenAI Policies, and prevent abuse. OpenAI will not use Customer Content to develop or improve the Services, unless Customer explicitly agrees to such use."
"Develop or improve the Services" includes training OpenAI's AI models. Bells Up AI has not agreed to any such use of your data.
This is reinforced in OpenAI's enterprise privacy documentation:
"By default, we do not use data from ChatGPT Enterprise, ChatGPT Business, ChatGPT Edu, ChatGPT for Healthcare, ChatGPT for Teachers, or our API platform—including inputs or outputs—for training or improving our models."
Why this applies to you: Bells Up AI uses the OpenAI API (not consumer ChatGPT), so this no-training commitment applies to your usage through our platform.
The OpenAI Services Agreement is clear on ownership:
"As between Customer and OpenAI, to the extent permitted by applicable law, Customer: (a) retains all ownership rights in Input; and (b) owns all Output. OpenAI hereby assigns to Customer all OpenAI's right, title, and interest, if any, in and to Output."
Your rights:
OpenAI retains API data temporarily for abuse monitoring purposes:
"OpenAI may securely retain API inputs and outputs for up to 30 days to provide the services and to identify abuse. After 30 days, API inputs and outputs are removed from our systems, unless we are legally required to retain them."
What this means:
OpenAI runs automated content classification systems on all API data:
"We may run any business data submitted to OpenAI's services through automated content classifiers and safety tools, including to better understand how our services are used. The classifications created are metadata about the business data but do not contain any of the business data itself."
What OpenAI's automated classifiers look for:
Based on OpenAI's public Moderation API documentation, automated classifiers detect content in these categories:
What this means for legal work:
These classifiers generate flags based on content patterns, not context. A contract describing fraud allegations, a litigation memo discussing violent crimes, or a healthcare privacy agreement referencing medical conditions could trigger classifier flags—even though the content is legitimate legal work.
The classifier creates metadata (flags, severity scores) but does not copy your actual content into the metadata. However, if content is flagged, it may be subject to further review (see below).
OpenAI's enterprise terms limit human access to your data to specific circumstances:
"Our access to API business data stored on our systems is limited to (1) authorized employees that require access for engineering support, investigating potential platform abuse, and legal compliance and (2) specialized third-party contractors who are bound by confidentiality and security obligations, solely to review for abuse and misuse."
| Who | Permitted Access | Under What Circumstances |
|---|---|---|
| Authorized employees | Engineering support | As required to support service delivery |
| Authorized employees | Abuse investigation | When automated systems flag potential policy violations |
| Authorized employees | Legal compliance | When required by law or legal process |
| Third-party contractors | Abuse and misuse review | To review content flagged for policy violations (under confidentiality obligations) |
OpenAI's Services Agreement further provides that content determined to violate OpenAI's policies ("Abusive Customer Content") may be retained beyond the standard 30-day retention period — including after account termination — "as required by law, or as reasonably necessary to protect the Services or any third party from harm" (Services Agreement, Section 11.3).
Contractual restrictions: OpenAI's Services Agreement prohibits using your data to train or improve AI models unless you explicitly agree (Section 4.2). Access is limited to personnel with a need to know, bound by confidentiality obligations at least as restrictive as those in the Services Agreement (Section 7.3).
As noted above, automated content classifiers may flag legitimate legal work. Flagged content is subject to review by OpenAI personnel or contractors under these access provisions.
| Protection | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all API communications |
| Encryption at rest | AES-256 during the retention period |
| Access controls | Limited to authorized personnel with confidentiality obligations |
| Compliance | SOC 2 Type 2, ISO 27001/27017/27018/27701 certified |
Bells Up AI's use of the OpenAI API is governed by:
Under the Data Processing Addendum, OpenAI commits to:
OpenAI maintains the following certifications:
What Amazon Does: Amazon provides the cloud infrastructure where the Bells Up AI application runs. This includes:
When you use OpenAI models through Bells Up AI, your prompts travel directly from our application to OpenAI's servers. Amazon does not process your AI requests.
Amazon provides the computing resources and storage that our application uses. Under the AWS Shared Responsibility Model:
Amazon operates the physical servers and storage infrastructure we use. Amazon's access to data stored on its infrastructure is governed by contract and verified by independent audits:
"[Amazon] will not access or use Customer Data except as necessary to maintain or provide the Services, or as necessary to comply with the law or a binding order of a governmental body."
This prohibits Amazon from using your data to develop Amazon's own AI or other products, or from providing your data to others for such purposes.
Amazon's SOC 2 Type II certification provides independent verification that Amazon maintains and follows these access controls.
| Protection | Implementation |
|---|---|
| Encryption in transit | TLS 1.2+ for all communications |
| Encryption at rest | AES-256 for all stored data |
| Server storage | Encrypted at the hardware level |
| Access controls | Credentials managed through Amazon's identity system; no hardcoded passwords |
Bells Up AI's use of Amazon services is governed by:
Under the Data Processing Addendum, Amazon acts as a "data processor" — meaning Amazon processes data on our behalf according to our instructions, rather than controlling or owning the data.
We encourage you to review the source documents:
| Document | What It Covers | Link |
|---|---|---|
| OpenAI Services Agreement | Master contract: no-training commitment, content ownership, data handling | View |
| OpenAI Enterprise Privacy | Data retention, access controls, privacy commitments | View |
| OpenAI Service Terms | Feature-specific terms for particular OpenAI products, separate from the Services Agreement | View |
| OpenAI Data Processing Addendum | GDPR/CCPA compliance, data handling obligations | View |
| OpenAI Business Data Privacy | Training commitments, encryption, certifications | View |
| OpenAI Trust Portal | Security certifications and compliance | View |
| AWS Data Processing Addendum | Amazon's data handling, confidentiality commitments | View |
If you have questions about how your data is protected when using OpenAI models through Bells Up AI, contact us at info@bellsup.ai.
This document describes data handling for OpenAI models accessed via the OpenAI API. Other models available through Bells Up AI have different data flows — see the privacy information page for each model family.
This disclosure is provided for informational purposes. Bells Up AI does not provide legal advice to our customers, and attorneys selecting AI models should exercise their independent professional judgment regarding model selection. We believe prudent AI risk management practices include considering the risks of using particular models and assessing the applicability of specific regulatory and contracting requirements.