Industry
Vendor Questions to Ask About Where Your Prompts Are Stored
Twelve questions to put to an AI vendor about prompt storage: retention, training use, subprocessors, deletion on exit, and the answers that should worry you.
Written by Sicherhaven
Your team types client names, salary figures and half formed strategy into an AI tool all day. Those prompts are stored somewhere, for some length of time, readable by someone.
Ask twelve questions before you sign. They cover four areas: how long prompts are kept, whether they are used to train anything, who else touches them, and what happens when you leave. Get the answers in writing rather than in a demo call, because what a salesperson says and what the contract says are often different documents. Ask them after you have settled whether the job needs an agent at all rather than an assistant or a workflow rule.
The twelve questions
Retention
1. How long are prompts and outputs stored by default?
You want a stated period, not "as long as necessary".
2. Can we set a shorter retention period, and is it enforced automatically?
A setting that exists but has to be requested each time is not a control.
3. Is retention different for prompts, outputs, attachments and logs?
Often yes. A tool that deletes prompts after thirty days may keep the file you uploaded much longer.
4. Are deleted prompts removed from backups, and on what schedule?
The honest answer usually involves a delay. A vendor that claims instant removal everywhere has probably not thought about their own backups.
Training use
5. Are our prompts used to train or improve your models?
Ask about improvement as well as training, because "we do not train on your data" sometimes coexists with evaluation and tuning that use the same content.
6. If not by default, is there a setting that changes it, and who can change it?
An administrator toggle that a team lead can flip is a real risk.
7. Are prompts reviewed by humans for quality or safety purposes?
Human review is common and not automatically wrong. You need to know it happens, who those people are and what they can see.
Subprocessors and location
8. Which subprocessors see prompt content, and where are they?
You want a list, not a category. Model providers, hosting, logging, analytics, support tooling.
9. In which countries is prompt data stored and processed?
Data residency rules differ a lot by country and sector, and requirements for a regulated business are not the same as for a marketing team. Check what applies to you rather than assuming.
10. How are we notified when a subprocessor changes?
Notice with a right to object is stronger than notice alone.
Deletion and exit
11. On termination, what is deleted, when, and do we get confirmation?
Ask specifically about prompts, outputs, logs and any derived data such as embeddings or usage records.
12. Can we export our prompt library and history in a usable format?
If a prompt library is where your process knowledge ended up living, being unable to take it with you is a serious lock in.
Answers that should worry you
Some responses are worth treating as findings rather than answers.
- "That is covered in our security documentation" with no direct answer. Push once. If the second answer is also a document reference, assume the answer is bad.
- "We do not store prompts" with no qualification. Almost every system logs something for debugging. A vendor who says this without nuance has either not asked their own engineers or is describing an aspiration.
- "Enterprise customers get different terms." Fine, but then get the enterprise terms before signing, not after.
- Any answer about training that uses the word "anonymised" without explaining what was removed. Prompts contain names, figures and context that are hard to strip.
- Reluctance to name subprocessors. This list is usually public for mature vendors.
Where self hosting changes the answer
If your data is sensitive enough that these answers keep coming back unsatisfying, running private models on your own infrastructure removes most of the questions rather than answering them. SicherOne supports private models being self hosted for that reason, which puts prompt storage inside your own boundary and turns questions 8 to 12 into internal policy rather than vendor terms.
That is not free. You take on the hosting, the updates and the access control yourself, and that cost still has to be argued for, which is its own exercise in getting a sceptical finance director to approve AI spend. It is worth considering when the alternative is accepting terms you cannot verify.
How to use the list
Send the twelve questions as a document and ask for written answers. Two things happen. You get answers you can attach to the contract, and you learn how the vendor behaves when asked something inconvenient, which tells you as much as the answers do.
Terms in this area change often, so re-ask at renewal rather than assuming last year's document still describes the product. Renewal is also the moment for reviewing what the spend actually bought.
← All postsWe're building the future of community events and financial wellness
See how Eventify and WealthWise change the way people find events and manage money.
Get Started
