Skip to content
    Trust Center

    Privacy & Security

    How we protect your data when you (and our AI tools) work inside Market Rebellion.

    No Model Training on Your Data

    Prompts, code, and business data sent through our AI providers (Anthropic, OpenAI, Google) via their APIs are NOT used to train their foundation models. This is contractually guaranteed in their API terms — distinct from consumer chat products.

    Short Retention Windows

    API providers retain inputs/outputs for limited windows (typically up to 30 days) for abuse monitoring only, then permanently delete. Your data is never reviewed by humans unless we flag a Trust & Safety incident.

    Zero Data Retention (ZDR) Available

    For sensitive workloads, we can route through Zero Data Retention endpoints — provider stores nothing after the response is returned. Available on enterprise tiers and applied selectively to regulated data flows.

    Encryption Everywhere

    TLS 1.2+ in transit, AES-256 at rest. API keys are stored in encrypted secret vaults (never in code, never in logs). Database access enforced via row-level security.

    Live Data-Handling Posture

    Single source of truth for our AI training opt-out and retention configuration. Version 2026.05.01 — effective 2026-05-01.

    Anthropic

    Claude Sonnet, Claude Opus (API tier)

    No training
    ZDR available
    Default retention
    30 days
    Data residency
    United States
    DPA
    Signed
    SOC report
    SOC 2 Type II

    ZDR active for

    War Room intake • Member PII flows • KYC review assistance

    API customer data is not used to train Anthropic models per Commercial Terms §B.

    OpenAI

    GPT-5, GPT-5 mini, GPT-5 nano (API tier)

    No training
    ZDR available
    Default retention
    30 days
    Data residency
    United States
    DPA
    Signed
    SOC report
    SOC 2 Type II

    ZDR active for

    Support ticket triage with PII • Sales call transcript review

    Business/API data is not used to train OpenAI models per Business Terms §3.

    Google

    Gemini 2.5 Pro/Flash, Gemini 3 Pro/Flash preview

    No training
    ZDR available
    Default retention
    30 days
    Data residency
    United States
    DPA
    Signed
    SOC report
    SOC 2 Type II

    ZDR active for

    Regulated content review on request

    Vertex AI / Gemini API customer data is not used to train Google models.

    Rebel AI Gateway

    Routed transparently to providers above

    No training
    ZDR available
    Default retention
    No payload retention
    Data residency
    United States
    DPA
    Signed
    SOC report
    In-progress

    ZDR active for

    Gateway itself stores no prompt/response payloads

    Gateway forwards requests; logs only metadata (model, tokens, status), never payloads.

    Statements of Posture

    1. 1.No customer prompts, code, or business data is used to train any third-party AI foundation model.
    2. 2.All AI invocations occur via provider APIs operating under signed Data Processing Agreements (DPAs).
    3. 3.Default provider retention is 30 days for Trust & Safety review only; no human review in the absence of a flagged abuse incident.
    4. 4.Zero Data Retention (ZDR) endpoints are enabled for War Room intake, KYC review assistance, and any flow handling PII or material non-public information.
    5. 5.Every AI invocation is logged to an internal audit table (admin-only access) capturing provider, model, retention policy, and data classification.
    6. 6.API credentials are stored in an encrypted secret vault and rotated on demand. No keys reside in source code, browser storage, or logs.
    7. 7.All processing occurs in United States data centers. No customer data is transferred outside the US.
    8. 8.This posture is published at https://marketrebellion.ai/privacy-security and reaffirmed in our Privacy Policy.

    Provider-Specific Breakdown

    Each AI vendor has different defaults for training and retention. Below is the exact posture per provider — the tier we use, the contract clause we rely on, how it differs from the consumer product, and how long inputs and outputs live before deletion.

    Accuracy & sourcing. Posture version 2026.05.01 · effective 2026-05-01. Each contract clause below is labeled either

    Verbatim quote
    (a direct quote from the linked source) or
    Summary / paraphrase
    (our condensed paraphrase — verify against the linked source).

    Vendor terms can change without notice. Each provider tab shows the date we last verified that page end-to-end. The authoritative documents are the linked vendor terms and our signed DPAs — this page is a navigational aid, not a substitute for them. Discrepancies should be reported to security@marketrebellion.ai.

    Anthropic

    Claude Sonnet, Claude Opus (API tier)

    Tier in use: Anthropic API (Commercial)

    Vendor page last verified: 2026-05-01

    No training on our data
    ZDR available
    Retention: 30 days max
    Contract clause
    "Commercial Terms §B: "Anthropic will not train its models on Customer Content from Services.""
    Consumer vs. API
    Claude.ai (consumer) may use opted-in conversations for safety research; the API tier we use is contractually excluded from any training use.
    Retention purpose
    Trust & Safety abuse monitoring (CSAM, weapons, election integrity). No product analytics, no model training.
    What extends retention
    Retention may be extended only where Anthropic flags a Trust & Safety violation requiring investigation.
    Opt-out mechanism
    Default for all API workspaces — no toggle required. Confirmed in workspace settings and Commercial Terms.
    Human review policy
    No human review absent an automated abuse classifier flag. Reviewers are bound by confidentiality.
    Data residency
    United States
    Subprocessors
    AWS (US-East) · Google Cloud (US)
    DPA / Audit
    DPA signed · SOC 2 Type II
    ZDR active for
    War Room intake · Member PII flows · KYC review assistance

    Citations & sources

    1. [2]Vendor terms:Anthropic Terms· retrieved 2026-05-01
      Summary / paraphrase

    Sources are checked on each posture revision. Last full review: 2026-05-01. Vendors may amend their terms between reviews — always defer to the linked authoritative document.

    Security Controls

    TLS 1.2+ enforced on all endpoints
    AES-256 encryption at rest
    Row-level security (RLS) on every table
    Encrypted secret vault for API keys
    No AI training on customer data (API tier)
    Configurable Zero Data Retention routing
    US-only data residency
    Audit log on privileged actions
    SOC 2-aligned access controls
    Annual penetration testing

    Frequently Asked Questions

    Does Anthropic / OpenAI / Google train on data we send through the gateway?

    No. All three providers explicitly state in their API terms that customer API inputs and outputs are not used to train their models by default. This is fundamentally different from their consumer products (Claude.ai, ChatGPT, Gemini app), which may train on conversations unless opted out.

    What is Zero Data Retention (ZDR)?

    ZDR is a contractual configuration where the AI provider does not store any inputs or outputs after returning a response — not even for abuse monitoring. Standard API tiers retain data for up to 30 days; ZDR drops that to zero. Available as an enterprise add-on with each provider and applied to sensitive workflows on request.

    Who can see the data we send to AI?

    In the standard path: no human. Data is processed by the model and discarded after the retention window. The only exception is Trust & Safety review if automated systems flag content for abuse (CSAM, extremism, etc.) — which does not apply to normal business use.

    Where is data stored?

    Application data lives in our managed Postgres database in US-East regions with encryption at rest and row-level security. AI provider processing happens in the provider's US data centers. We do not transfer data to non-US jurisdictions.

    How do you handle API keys and secrets?

    All third-party API keys are stored in an encrypted secrets vault, scoped per environment, and never written to source code, logs, or browser storage. Rotation is supported on demand.

    What about PII and regulated data?

    We recommend not sending PII, PHI, or material non-public information to AI endpoints unless that flow has been explicitly reviewed and routed through a ZDR endpoint with a signed BAA/DPA. Contact compliance@marketrebellion.ai before introducing new regulated data flows.

    Can you provide documentation for our security team?

    Yes. We can share provider DPAs, SOC 2 reports, and a written attestation of our retention and training posture. Email security@marketrebellion.ai.

    Need documentation for your security team?

    We can share provider DPAs, SOC 2 reports, and a written attestation of our AI retention and training posture.