Last Reviewed: September 10, 2026

At a Glance

“Qwen” refers to the AI models; “Alibaba” is the company that developed them. The Qwen AI models are software (large language models) that generate responses to your prompts. Alibaba — formally Alibaba Cloud Computing Limited, a subsidiary of Alibaba Group — is based in China.

Bells Up AI runs the Qwen AI models on Amazon’s servers in the United States. Alibaba itself never receives your prompts, your documents, or the models’ responses.

Your data never leaves Amazon’s infrastructure. Alibaba has zero access to your prompts or responses. However, model output censorship concerns and regulatory uncertainty persist regardless of hosting.

At a glance: Qwen (via Amazon Bedrock) privacy practices
QuestionAnswer
Can Alibaba access your prompts or documents?No — Alibaba never receives them
Can Alibaba train AI on your prompts or documents?No — Alibaba has zero access
Can Alibaba employees or contractors review your data?No — Alibaba has zero access
How long does Alibaba retain your data?N/A — Alibaba never receives your data
Does Amazon Bedrock store your prompts or documents?No — Amazon Bedrock applies zero data retention by default (not stored)
Does Amazon train AI on your data?No — prohibited by contract
Does Amazon scan your data for abuse?Yes — but Amazon Bedrock uses a zero operator access (ZOA) model, so no service operators can access your inputs or outputs (details)
Can Amazon employees or contractors review your prompts or responses?No — Amazon Bedrock uses a zero operator access (ZOA) model, so AWS operators cannot access your inputs or outputs; content flagged as apparent CSAM may be reviewed for confirmation and reporting. Access to data stored on Amazon’s infrastructure is separately limited (details)
Is this disclosure legal advice?No. Bells Up AI does not provide legal advice. Attorneys should exercise independent professional judgment regarding model selection.

Your data is encrypted in transit (TLS 1.2+) and at rest (AES-256). Amazon Web Services — the cloud provider that runs the model and where your prompts are processed — holds SOC 2 and ISO 27001 certifications.


Summary of What You Need to Know About Using Qwen Through Bells Up AI

Bells Up AI believes that our customers should have access to the full range of AI tools and the information they need to make informed professional decisions about which models to use, and when and how to use them. Model selection is always the attorney’s professional judgment call.

Alibaba carries a federal designation. On June 8, 2026, the Department of Defense added Alibaba to its Section 1260H list of “Chinese military companies,” effective June 30, 2026. That designation bars direct Department of Defense contracting; it does not restrict commercial or civilian use of Qwen and does not affect availability through Amazon Bedrock. Alibaba has sued to challenge the designation, and no ruling had issued as of this review. Texas added Alibaba to its state prohibited-technology list in January 2026, which reaches state-government devices and networks only. As of the Last Reviewed date, Bells Up AI has not identified a U.S. restriction on private or commercial use of Qwen. Attorneys performing work for the Department of Defense or its contractors may wish to consider whether the designation bears on their engagements. See the full regulatory discussion.

Alibaba’s own services handle data differently from the route Bells Up AI uses. Alibaba’s hosted Qwen offerings, including chat.qwen.ai and Alibaba Cloud Model Studio, operate under terms that permit Alibaba to use portions of prompts for model training. Those terms govern users who go to Alibaba directly. They do not govern your use of Qwen through Bells Up AI.

Qwen through Bells Up AI uses Amazon Bedrock, not Alibaba’s services. Qwen models are open-weight under the Apache 2.0 license, and Alibaba supplies the trained model weights to Amazon for deployment on Amazon’s infrastructure. Alibaba has no access channel to the Bedrock-hosted copies of those models. Your prompts, documents, and the models’ responses remain on Amazon’s servers within the United States, and training on them is prohibited by contract. Bedrock applies zero data retention by default. The limited exceptions, including a 30-day retention window for certain other providers’ models and review of content flagged as apparent CSAM, are described below. See Alibaba: The Model Developer for the basis of each statement.

Nevertheless, model behavior and quality risks persist regardless of where the model is hosted. Censorship and bias are properties of the trained model weights and are unchanged by U.S. hosting. In November 2025, Taiwan’s National Security Bureau reported that five Chinese-developed AI models exhibited security violations and generated content reflecting Chinese Communist Party propaganda and bias; Qwen, marketed there under the name “Tongyi,” recorded the most violations of the five models tested. Separately, in March 2025 the AI security firm PointGuard AI assigned Qwen 2.5 an overall risk score of 9.0 out of 10, including a 57.6% failure rate on hallucination testing. That evaluation examined Qwen 2.5 rather than the Qwen 3 models offered here, and we have not located an equivalent independent evaluation of the specific models in this catalog. We identify that gap rather than infer findings from the earlier model. See What Bedrock Does and Does Not Address for the full analysis.

Practice considerations. Alibaba does not receive content submitted through Bells Up AI, and Amazon does not train on it. Model output and Alibaba’s regulatory posture require separate consideration. Qwen may be appropriate for legal research on public information, general knowledge questions, internal administrative work, coding and drafting tasks you will review, and comparing model outputs for evaluation purposes. As with any model, weigh the sensitivity of what you enter, and do not treat a drafting or coding task as low-sensitivity merely because of its form. Use heightened caution on matters touching China, Taiwan, Hong Kong, or the conduct of the Chinese government, given the documented content-shaping findings. Use heightened caution on work for the Department of Defense or its contractors. Alibaba’s Section 1260H designation may require you to determine contract scope, flow-downs, and client instructions before use. Use heightened caution in matters where opposing counsel or a court might examine the AI tools used. Verify every citation and factual assertion against a primary source, as you would with any model.


The Three Parties Involved

When you use the Qwen family of AI models through Bells Up AI, three parties are involved in processing your request:

  1. Alibaba is the Model Developer — the company that created and trained the Qwen family of AI models (the Qwen 3 family and related variants). Alibaba Cloud Computing Limited, a subsidiary of Alibaba Group, develops and maintains these models.
  2. Amazon is the Infrastructure Provider — Amazon provides cloud computing services (servers, storage, networking) under the brand “Amazon Web Services” or “AWS.” Amazon hosts both (a) the Qwen AI models through a service called “Amazon Bedrock,” and (b) the Bells Up AI application on Amazon’s servers.
  3. Bells Up AI (“we” or “us”) — We built and operate the application you are using.

Each party operates under contractual obligations that protect your data. Below, we explain what each party can and cannot do with your data, with citations to the governing contracts.


Alibaba: The Model Developer

What Alibaba Does: Alibaba Cloud develops and trains the Qwen family of AI models. Alibaba provides the trained model weights to Amazon for deployment on Amazon’s infrastructure. Qwen models are open-weight under the Apache 2.0 license, meaning the model weights are publicly available. Alibaba has no proprietary access channel to the Bedrock-hosted copies of these models.

What Alibaba Cannot Do

Alibaba cannot access your prompts, documents, or Qwen’s responses when you use Qwen through Bells Up AI. This is a technical restriction. Alibaba has no access to the Amazon infrastructure where Qwen is deployed.

Amazon does not provide Alibaba with access to your prompts, documents, or responses. In order to run AI models like the Qwen models you access through Bells Up AI, Amazon maintains “Model Deployment Accounts”, which model developers like Alibaba do not have access to:

“Model providers don’t have any access to those accounts. After delivery of a model from a model provider to [Amazon], Amazon Bedrock will perform a deep copy of a model provider’s inference and training software into those accounts for deployment. Because the model providers don’t have access to those accounts, they don’t have access to Amazon Bedrock logs or to customer prompts and completions.”

— Amazon Bedrock Data Protection Documentation

No Training on Your Data

Amazon Bedrock prohibits both Amazon and third-party model providers from using your prompts, documents, or model responses for training:

Amazon does not use your prompts and responses to train its own models, and does not share them with the model provider. AWS states that retained inputs and outputs (for the limited set of models that require retention) are “stored and processed by AWS and are not shared with third-party model providers.”

— Amazon Bedrock Abuse Detection Documentation

Qwen models on Bedrock are sold by AWS and governed by AWS service terms:

“Qwen serverless models on Amazon Bedrock are sold by AWS.”

— AWS Bedrock Third-Party Model Terms


Chinese-Origin Model Considerations

Alibaba Group is headquartered in Hangzhou, China. As a Chinese company, Alibaba is subject to Chinese national security and data laws. Attorneys should understand what these laws require, and why Bedrock’s architecture matters in this context.

Chinese Laws That Apply to Alibaba

National Intelligence Law (2017, amended 2018):

“All organizations and citizens shall support, assist, and cooperate with national intelligence efforts in accordance with law.”

— National Intelligence Law of the PRC, Article 7 (China Law Translate)

Data Security Law (2021): Classifies data and imposes handling requirements on Chinese companies. Compels data disclosure to authorities under national security provisions.

Personal Information Protection Law (PIPL, 2021): China’s data protection framework, with explicit carve-outs for national security and public interest that allow government access to personal data held by Chinese companies.

Why Bedrock Changes the Analysis

These laws allow Chinese authorities to compel Alibaba to disclose data. Through Bedrock, Alibaba does not possess your inference data — your prompts, documents, and Qwen’s responses never reach Alibaba’s systems. Chinese authorities cannot compel disclosure of data Alibaba does not have.

Alibaba’s own services and Qwen through Bedrock use different data flows:

Comparison of data privacy risks: Bedrock versus direct Alibaba API
Concern Direct Alibaba API Bedrock (Bells Up AI)
Alibaba receives prompt dataYesNo — AWS architecture prevents it
Data stored in Chinese jurisdictionPossible (China or Singapore)No — stays in selected U.S. AWS region(s) (us-east-1, plus us-east-2 for the Qwen3 235B and Qwen3 Coder 480B A35B models)
Chinese gov’t can compel data disclosureYes, via AlibabaNo data for Alibaba to disclose
Data used for model trainingYes (per Alibaba ToS)No (per AWS policy and contract)

What Bedrock Does and Does Not Address

Bedrock prevents:

Bedrock does not address:

September 2026 federal advisory. On September 8, 2026, the National Security Agency, the Cybersecurity and Infrastructure Security Agency, and the Federal Bureau of Investigation issued a joint cybersecurity advisory, AA26-251A, titled “China-Based Artificial Intelligence Companies Conducting Industrial-Scale Distillation Campaigns Against U.S. AI Companies.” The advisory names six China-based AI companies — DeepSeek, Moonshot AI, Alibaba, Z.AI, MiniMax, and StepFun — that it states extracted training data from U.S. frontier models. It states that in late 2025, Alibaba “distilled Claude-4, Claude Opus, Claude Sonnet, and GPT-5 to improve their AI models’ software engineering skills, customer service dialogue functionality, image/character creation, and integration of RL, SFT, and distillation capabilities.” The advisory directs its recommendations to U.S. AI developers, on detecting and responding to distillation. It imposes no restriction, obligation, or requirement on companies or individuals that use these models. It concerns how these models were trained, not how your prompts and responses are handled when you use them; the data-handling protections described in this disclosure are unaffected.

Amazon: The Infrastructure Provider

Amazon provides two distinct services relevant to how your data is handled:

Amazon Bedrock (The AI Service)

What Amazon Bedrock Does: Amazon Bedrock is the service that hosts and runs the Qwen AI models. When you submit a prompt, Bells Up AI sends it to Amazon Bedrock, which processes it through Qwen and returns the response.

Prompt Improvement Tool

The optional “Improve my prompt” tool sends the draft prompt to Amazon Bedrock’s prompt-optimization service. The tool sends your draft prompt to Amazon Bedrock regardless of the model you select. Conversations, documents, and workflow runs are processed by the model you selected.

Amazon Bedrock’s Core Commitments:

No Storage of Your Prompts or Responses:

“Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output. Also, Amazon Bedrock uses a zero data retention (ZDR) data security model. This means that by default, Amazon Bedrock does not store model inputs or outputs.”

— Amazon Bedrock Abuse Detection Documentation

No Training on Your Data:

Amazon does not use your prompts and responses to train its own models, and does not share them with the model provider. AWS states that retained inputs and outputs (for the limited set of models that require retention) are “stored and processed by AWS and are not shared with third-party model providers.”

— Amazon Bedrock Abuse Detection Documentation

Data Stays in Region: Your data remains in the Amazon data center region where the request is processed. Bells Up AI uses the us-east-1 (Northern Virginia) region, except for the Qwen3 235B and Qwen3 Coder 480B A35B models, which run in us-east-2 (Ohio). Both are U.S. regions; your requests are not routed outside the United States.

Automated Abuse Detection

Amazon Bedrock runs automated content scanning on data processed through the service. If that scanning flags apparent child sexual abuse material, the AWS Service Terms provide:

“If we detect apparent child sexual abuse material (“CSAM”), you agree and instruct that we may: (a) review the flagged input or output to determine if it is CSAM, and (b) report the incident to the National Center for Missing and Exploited Children or other authority.”

— Amazon Web Services Service Terms, Section 50.12.2.1 (September 1, 2026)

The Service Terms also provide that, for certain models identified on Amazon’s Bedrock abuse-detection documentation, Amazon Bedrock stores inputs and outputs for up to 30 days to detect terms-of-service violations and may review them if a potential violation is detected. None of the models available through Bells Up AI are identified on that list as of this review.

Apart from these provisions, Amazon’s abuse-detection documentation describes Amazon Bedrock’s default access model:

“Amazon Bedrock uses a zero operator access (ZOA) data security model. This means no operators of the service can access model input or output.”

— Amazon Bedrock Abuse Detection Documentation

What this means:

This automated scanning is narrower in scope than the abuse monitoring systems used by direct API providers like OpenAI or Google, which retain data for up to 30 or 55 days and may involve human review of flagged content. Amazon Bedrock’s abuse detection operates at the infrastructure level and does not involve the model provider (Alibaba).

What Metadata Alibaba May Receive

While Alibaba never receives the content of your prompts or responses, Amazon may share non-content usage information with third-party model providers:

“We may share information, that does not include Your Content, about your use of a third-party model with the provider of that third-party model.”

— Amazon Web Services Service Terms, Section 50.12.5 (September 1, 2026)

This metadata may include identifiers such as Bells Up AI’s AWS Account ID, the AWS region, the model used, request counts, token usage, and timestamps. It contains no content from your prompts, documents, or responses.

Amazon Web Services Infrastructure (Servers and Storage)

What This Means: Separately from Amazon Bedrock, the Bells Up AI application itself runs on Amazon’s cloud infrastructure. This includes:

Can Amazon Access This Data?

Amazon operates the physical servers and storage infrastructure we use. Amazon’s access to data stored on its infrastructure is governed by contract and verified by independent audits, which test whether Amazon’s actual practices match its contractual commitments:

Amazon “will not access or use, or disclose to any third party, any Customer Data, except, in each case, as necessary to maintain or provide the Services, or as necessary to comply with the law or a valid and binding order of a governmental body (such as a subpoena or court order).”

— Amazon Web Services Data Processing Addendum

This prohibits Amazon from using your data to develop Amazon’s own AI or other products, or from providing your data to others for such purposes.

Amazon’s SOC 2 Type II certification provides independent verification that Amazon maintains and follows these access controls.

Technical Protections:

Technical protections: encryption and access controls
Protection Implementation
Encryption in transitTLS 1.2+ for all communications
Encryption at restAES-256 for all stored data
Server storageEncrypted at the hardware level
Access controlsCredentials managed through Amazon’s identity system; no hardcoded passwords

Governing Agreements

Bells Up AI’s use of Amazon services is governed by:

Under the Data Processing Addendum, Amazon acts as a “data processor” — meaning Amazon processes data on our behalf according to our instructions, rather than controlling or owning the data.

Compliance Certifications

Amazon Bedrock and the underlying infrastructure maintain the following certifications:

See: Amazon Bedrock Security & Compliance


Verify These Claims

We encourage you to review the source documents:

Source documents for verifying privacy claims
Document What It Covers Link
AWS Bedrock Third-Party Model Terms (Qwen) Qwen-specific terms, sold-by-AWS designation View
Amazon Bedrock Data Protection No-storage, no-training, no-access commitments View
Amazon Web Services Service Terms Bedrock-specific terms (Section 50.12), abuse detection, metadata sharing View
Amazon Web Services Data Processing Addendum Amazon’s role as processor, access limitations View
Amazon Bedrock Security & Compliance Certifications (SOC, ISO, HIPAA) View
China’s National Intelligence Law (English translation) Legal obligations on Chinese organizations View
NCSC/DNI Bulletin on PRC Laws US intelligence community analysis of Chinese data laws View

Questions?

If you have questions about how your data is protected when using Qwen through Bells Up AI, contact us at info@bellsup.ai.


This disclosure covers Qwen models accessed through Amazon Bedrock. It does not cover Alibaba’s direct services. See each model family’s disclosure for information about other models available through Bells Up AI.

This disclosure is provided for informational purposes. Bells Up AI does not provide legal advice to our customers, and attorneys selecting AI models should exercise their independent professional judgment regarding model selection. We believe prudent AI risk management practices include considering the risks of using particular models and assessing the applicability of specific regulatory and contracting requirements.

The regulatory and policy landscape for Chinese-origin AI models is evolving. Bells Up AI reviews this disclosure periodically, but attorneys should independently verify current regulatory requirements. The “Last Reviewed” date above reflects when this document was last updated.