Wrivio
Get Wrivio
6 min readBy Wrivio Team

Five Questions To Ask An AI Vendor About Your Data

Evaluating an AI tool for work usually means reading a privacy page written by someone whose job was to make you comfortable. The pages are rarely dishonest. They are selective, and the selection is the problem.

These five questions cut through it. They are deliberately specific, because specific questions are hard to answer vaguely without the vagueness becoming obvious.

1. Which Machine Processes The Text, And Where Is It?

Start here, because everything else is downstream.

You want a named answer, and under the GDPR a controller is expected to know it: our servers in a stated region, a named cloud provider’s infrastructure, a named model provider’s API, or the customer’s own device. “Securely processed” is not an answer to this question.

The follow-up that matters: is there a subprocessor? Many AI products are a interface over another company’s model, which means your text reaches at least two organisations. That is not disqualifying, but it doubles the number of data handling policies you are relying on and it should appear in the answer without being extracted.

If a vendor cannot name where processing happens in one sentence, that is your result for this question.

2. How Long Is Content Retained, And By Whom?

Ask for a duration, not a policy statement.

Good answers look like: not retained after the response is returned; retained 30 days for abuse monitoring then deleted; retained until you delete it, with deletion propagating within a stated window.

Note that retention by the vendor and retention by their model provider can differ. The vendor may hold nothing while the underlying API provider holds content for a month. Both numbers matter.

And ask specifically about support channels, because that is where the exception usually lives. Content you paste into a support ticket often falls outside the retention commitments that cover the product itself.

3. Is My Content Used For Training, And Is That The Default?

This is the question everyone asks and the least informative of the five, because nearly every business-tier product now answers no.

The useful refinement is whether it is the default or an opt-out, and whether it is contractual or a policy statement. A policy can change with a notice email; a contractual commitment cannot.

Also worth asking: does the answer cover both the vendor and any model provider behind them. A vendor who does not train on your data but sends it to a provider who might has answered the letter of the question.

4. What Happens To My Data If The Company Is Acquired Or Shuts Down?

Rarely asked, frequently the one that actually bites.

AI tooling is a consolidating market. The commitments you evaluated were made by a company that may not exist in its current form in two years, and customer data is an asset that transfers.

You are looking for a stated position on transfer, a deletion or export path you control, and ideally a commitment that material changes trigger notice rather than a silently updated policy page.

The related practical question: can you get your own data out? A tool that holds your accumulated instructions, templates, and history with no export is a tool you cannot leave. Export is a portability feature and a risk control at the same time.

5. What Can You Show Me Rather Than Tell Me?

The closing question, and the one that separates careful vendors from confident ones.

Concretely: a subprocessor list, a data processing agreement you can actually sign, a security page with dates on it, documentation of what the product does when offline, and a support contact that reaches someone technical.

None of these prove a tool is safe. Their absence is informative, because each is cheap for an organisation that has thought about the problem and awkward for one that has not.

For local-first tools there is a stronger version available: can I verify the claim myself? A tool that says it processes text on your machine can be tested by disconnecting the network and using it. How to tell if an AI tool really runs offline is that test, and being able to run it is worth more than any document.

Writing The Ask So It Gets Answered

Vendors answer specific emails and deflect vague ones.

Before:

Hi, we are evaluating your product and had some questions about security and privacy. Could you send over any documentation you have?

After:

We are evaluating your product for client correspondence and need four things before we can proceed: where text is processed and by which subprocessors, the retention period for content in both your systems and any model provider you use, whether the no-training commitment is contractual or policy, and your data export path. A DPA and subprocessor list would cover most of this if you have them.

The second gets a useful reply or a revealing silence. The first gets a marketing PDF.

A Wrivio Context for vendor due diligence could say:

Rewrite this as a direct, professional request to a vendor. Keep every question, technical term, and requirement exactly as written. Do not soften the questions, combine them, or add pleasantries that obscure what is being asked.

Press Ctrl+Shift+Space, paste the draft, and check the diff. The failure mode here is a model politely blunting the specific questions into general ones, which defeats the point.

This describes what to ask rather than what your obligations are. Where a contract or regulation governs the answer, have it reviewed by someone qualified.

Common Questions

What is the most important question to ask an AI vendor?

Where the text is actually processed and by which organisations. Everything else, retention, training, deletion, depends on knowing which systems hold your content in the first place.

Is a no-training commitment enough for confidential work?

No. Not training on your data says nothing about whether it is stored, for how long, or who can access it. Ask about retention separately and get a duration.

Why ask what happens if the vendor is acquired?

Because customer data transfers with the company, and the commitments you evaluated were made by an entity that may not exist unchanged in two years. You want a stated transfer position and an export path you control.

What if a vendor will not answer these questions?

That is an answer. Each of these is straightforward for an organisation that has thought about data handling, so evasion usually indicates the thinking has not happened.

Download Wrivio for Windows if you would rather verify a privacy claim by disconnecting the network than by reading a vendor questionnaire.