Draft policy
AI data governance
Rules for optional StudioFlow AI features, human review, provider transparency and sensitive data.
Last updated 21 August 2026
Our AI rules
- Send only workspace context needed for the requested function and keep requests within the authenticated workspace boundary.
- Treat email, documents and web content as untrusted data, not instructions for tools or account actions.
- Require human review for consequential financial, legal, HR, client communication or record-changing outputs.
- Do not intentionally send credentials or unnecessary sensitive personal data to an AI provider.
- Record proportionate usage and provenance without logging full sensitive prompts by default.
- Test high-impact functions for accuracy, leakage, unsafe action and regional bias.
Current implementation and limits
StudioFlow supports workspace AI keys, feature switches, spend controls, model selection, usage records and workspace context. Calls currently reference Anthropic APIs. These controls do not prove zero-retention or no-training provider terms; those must be verified contractually.
AI output is assistance, not a tax filing, legal opinion, guaranteed forecast or binding employment decision. Customers remain responsible for review and use.
Questions about this document may be sent to hello@studioflow.business. Draft contractual and privacy materials require formal approval before reliance.