Data, privacy, and models
What is stored and where, training and retention commitments, which models you can use, and how quality is measured.
- Is our data used to train models?No. One customer's traces, corrections, and context are never used to train models for other customers. Provider settings depend on the endpoints you choose and are verified at deployment.
- Which model providers are involved, and what do they see?Context is model-agnostic: Claude, GPT, Gemini, Kimi, or open weights. Which endpoints are reachable depends on your deployment, and each provider's retention settings are documented with you.
- Which models does Context use?Commercial or open-weight models available in your deployment. A runbook can pin one model or route between models, and providers can be swapped without rebuilding the workflow.
- Can I switch models mid-task?Yes. Your files, connected tools, and prior work stay in place, so you can change models without starting over.
- Can we bring our own model keys or private endpoints?Yes. Each deployment has an explicit provider allow-list, and a private inference gateway keeps model traffic inside your network. Your own provider account is not a subprocessor.
- How does Context learn how our company works?Unify keeps your procedures, accepted examples, and corrections in a filesystem agents navigate. Proposed updates from completed work go through the review policy your team sets.
- How do we know the work is good?Your team writes task-specific rubrics and accepted examples; Evals scores runs against them, surfaces failures, and compares changes. Humans stay in the loop for high-consequence decisions.
- How do evals work?Scorecards, judges, datasets, benchmarks, traces, and dashboards in one suite. Every run can be scored, and a read-only API exposes the results.
- What data does Context store?Five classes: institutional context, run traces, customer content, session recordings, and telemetry. Sensitive Data is out of scope under the DPA.
- Where does our data live?Inside your deployment in every mode. In a VPC, on-premises, or air-gapped deployment that means inside your own perimeter; model inference is the only cross-boundary flow.
- How long is our data retained?Operational retention is configured per deployment. Under the DPA, data is deleted or returned within 30 days of your election when the agreement ends, backups excepted.
- Can we export our data?Yes. Drive folders download as ZIP archives and single files directly; skills export through the CLI; evals data is available through the read-only API. Return or deletion at exit is a DPA commitment.
- Who are your subprocessors?The current list, with purpose and region for each, is published on the subprocessors page and in the Trust Center. A provider account you supply yourself is not a subprocessor.
- How are subprocessor changes notified?With at least ten days' notice and a written objection right; if an objection cannot be accommodated you may terminate the affected service with a pro-rata refund.
- How are international data transfers handled?Processing takes place in the United States; the Standard Contractual Clauses and the UK addendum are incorporated where GDPR, UK, or Swiss law applies.
The evidence behind these answers is in the Trust Center: read the deep dive →
Still need an answer?
Tell us what you were looking for and we reply within one business day.
Contact the team →Running a security review?
Documents, controls, and the request form live in the Trust Center.
Open the Trust Center →