Privacy & Security
How we protect your data when you (and our AI tools) work inside Market Rebellion.
No Model Training on Your Data
Prompts, code, and business data sent through our AI providers (Anthropic, OpenAI, Google) via their APIs are NOT used to train their foundation models. This is contractually guaranteed in their API terms — distinct from consumer chat products.
Short Retention Windows
API providers retain inputs/outputs for limited windows (typically up to 30 days) for abuse monitoring only, then permanently delete. Your data is never reviewed by humans unless we flag a Trust & Safety incident.
Zero Data Retention (ZDR) Available
For sensitive workloads, we can route through Zero Data Retention endpoints — provider stores nothing after the response is returned. Available on enterprise tiers and applied selectively to regulated data flows.
Encryption Everywhere
TLS 1.2+ in transit, AES-256 at rest. API keys are stored in encrypted secret vaults (never in code, never in logs). Database access enforced via row-level security.
Live Data-Handling Posture
Single source of truth for our AI training opt-out and retention configuration. Version 2026.05.01 — effective 2026-05-01.
Anthropic
Claude Sonnet, Claude Opus (API tier)
- Default retention
- 30 days
- Data residency
- United States
- DPA
- Signed
- SOC report
- SOC 2 Type II
ZDR active for
War Room intake • Member PII flows • KYC review assistance
API customer data is not used to train Anthropic models per Commercial Terms §B.
OpenAI
GPT-5, GPT-5 mini, GPT-5 nano (API tier)
- Default retention
- 30 days
- Data residency
- United States
- DPA
- Signed
- SOC report
- SOC 2 Type II
ZDR active for
Support ticket triage with PII • Sales call transcript review
Business/API data is not used to train OpenAI models per Business Terms §3.
Gemini 2.5 Pro/Flash, Gemini 3 Pro/Flash preview
- Default retention
- 30 days
- Data residency
- United States
- DPA
- Signed
- SOC report
- SOC 2 Type II
ZDR active for
Regulated content review on request
Vertex AI / Gemini API customer data is not used to train Google models.
Rebel AI Gateway
Routed transparently to providers above
- Default retention
- No payload retention
- Data residency
- United States
- DPA
- Signed
- SOC report
- In-progress
ZDR active for
Gateway itself stores no prompt/response payloads
Gateway forwards requests; logs only metadata (model, tokens, status), never payloads.
Statements of Posture
- 1.No customer prompts, code, or business data is used to train any third-party AI foundation model.
- 2.All AI invocations occur via provider APIs operating under signed Data Processing Agreements (DPAs).
- 3.Default provider retention is 30 days for Trust & Safety review only; no human review in the absence of a flagged abuse incident.
- 4.Zero Data Retention (ZDR) endpoints are enabled for War Room intake, KYC review assistance, and any flow handling PII or material non-public information.
- 5.Every AI invocation is logged to an internal audit table (admin-only access) capturing provider, model, retention policy, and data classification.
- 6.API credentials are stored in an encrypted secret vault and rotated on demand. No keys reside in source code, browser storage, or logs.
- 7.All processing occurs in United States data centers. No customer data is transferred outside the US.
- 8.This posture is published at https://marketrebellion.ai/privacy-security and reaffirmed in our Privacy Policy.
Provider-Specific Breakdown
Each AI vendor has different defaults for training and retention. Below is the exact posture per provider — the tier we use, the contract clause we rely on, how it differs from the consumer product, and how long inputs and outputs live before deletion.
Accuracy & sourcing. Posture version 2026.05.01 · effective 2026-05-01. Each contract clause below is labeled either
Vendor terms can change without notice. Each provider tab shows the date we last verified that page end-to-end. The authoritative documents are the linked vendor terms and our signed DPAs — this page is a navigational aid, not a substitute for them. Discrepancies should be reported to security@marketrebellion.ai.
Anthropic
Claude Sonnet, Claude Opus (API tier)
Tier in use: Anthropic API (Commercial)
Vendor page last verified: 2026-05-01
Citations & sources
- [2]Vendor terms:Anthropic Terms· retrieved 2026-05-01Summary / paraphrase
Sources are checked on each posture revision. Last full review: 2026-05-01. Vendors may amend their terms between reviews — always defer to the linked authoritative document.
Security Controls
Frequently Asked Questions
Does Anthropic / OpenAI / Google train on data we send through the gateway?
No. All three providers explicitly state in their API terms that customer API inputs and outputs are not used to train their models by default. This is fundamentally different from their consumer products (Claude.ai, ChatGPT, Gemini app), which may train on conversations unless opted out.
What is Zero Data Retention (ZDR)?
ZDR is a contractual configuration where the AI provider does not store any inputs or outputs after returning a response — not even for abuse monitoring. Standard API tiers retain data for up to 30 days; ZDR drops that to zero. Available as an enterprise add-on with each provider and applied to sensitive workflows on request.
Who can see the data we send to AI?
In the standard path: no human. Data is processed by the model and discarded after the retention window. The only exception is Trust & Safety review if automated systems flag content for abuse (CSAM, extremism, etc.) — which does not apply to normal business use.
Where is data stored?
Application data lives in our managed Postgres database in US-East regions with encryption at rest and row-level security. AI provider processing happens in the provider's US data centers. We do not transfer data to non-US jurisdictions.
How do you handle API keys and secrets?
All third-party API keys are stored in an encrypted secrets vault, scoped per environment, and never written to source code, logs, or browser storage. Rotation is supported on demand.
What about PII and regulated data?
We recommend not sending PII, PHI, or material non-public information to AI endpoints unless that flow has been explicitly reviewed and routed through a ZDR endpoint with a signed BAA/DPA. Contact compliance@marketrebellion.ai before introducing new regulated data flows.
Can you provide documentation for our security team?
Yes. We can share provider DPAs, SOC 2 reports, and a written attestation of our retention and training posture. Email security@marketrebellion.ai.
Need documentation for your security team?
We can share provider DPAs, SOC 2 reports, and a written attestation of our AI retention and training posture.