Back to the blog
AI agents

Does the AI train on my customers'' data? What to ask your provider

Published August 19, 2026By Brian Sasbon3 min read

The question nobody answers head on

Does the AI train on my customers' data? It is the question behind almost every security objection, and searching for it turns up very little.

When we traced it, the only piece asking it without hedging was from a legal publication. No provider answered it in the first person on their own blog.

That absence says something. So let us start with ours: Alumbra does not use customer data to train models. And move on to what matters more, which is how to verify that with any provider, us included.

Why the question matters more than it looks

Your support conversations are not ordinary data. Inside them are names, addresses, phone numbers, sometimes amounts and sometimes things the customer said without thinking they were being written down.

If that enters a training set, you stopped controlling it. There is no way to take a piece of data out of a model that has already been trained on it.

And there is a second layer, a legal one. In most countries you remain responsible for your customers' data even when the party processing it is a third party you hired.

The six questions

This is the short list. It works for any provider.

QuestionThe answer you want
Do you use my data to train or improve your models?An unconditional no
Does my organization's data mix with anybody else's?Never, with an explanation of how it is kept apart
What happens to what I send the model, the logs and the metadata?Something concrete, not "processed securely"
Will you sign a confidentiality agreement?Yes, without you having to fight for it
Where are the written policies?A link, not an email promising to send them
What certifications does the underlying platform hold?The name of the certification and who holds it

The third one separates providers who thought about this from those who did not. Almost everybody answers the first one well, because it is the expected one.

The answer that disqualifies

There is one answer that should end the conversation: "we use anonymized data to improve the service", said without further detail.

Anonymizing properly is hard and expensive. A support conversation carries so many cross-referenced details that re-identifying somebody is often possible. When that phrase arrives without a method attached, it usually means "we use it".

Ask for the method. If there is no method, there is a phrase.

Our answers, so you can compare

We put ours here because it is what we ask of others.

  • We do not use customer data to train models. No exceptions, no anonymized versions.
  • Each organization stays isolated. The AI in your account answers with your account's context and knows nothing about any other.
  • We sign a confidentiality agreement for anybody who asks.
  • The policies are published, not emailed on request.
  • The messaging platform underneath is SOC 2 compliant.
  • We never touch your WhatsApp credentials. The connection runs through Meta's official channels.

What you will not be able to audit

Here is what we do not promise, because a list of guarantees with no limits is useless for comparing.

We do not have a searchable audit log. The actions the AI takes are recorded as notes in the conversation itself, and an order's history lives on that order. Auditing means opening the conversation and reading it.

That is a real limitation. If your operation needs to export a full access log, ask specifically about that with any provider you evaluate.

Conclusions

  • No provider answers this on their blog, and that absence is already information.
  • Ask about logs and metadata too, not only about training.
  • "Anonymized data to improve the service", with no method, amounts to a yes.
  • Ask for the written policies and the certification name, not a verbal promise.
  • Even when you hire a third party, you remain responsible for your customers' data.

Frequently asked questions

Does Alumbra use my conversations to train its models?
No. Not the conversations, not the documents you upload, not your contact data. Not in anonymized versions either.
Can another organization see anything of mine?
No. Each organization works with its own context and the AI in one account has no way to read anything from another.
Do you sign NDAs?
Yes, on request and signed by Alumbra's officers. It does not have to be part of a large negotiation.
What happens to my WhatsApp credentials?
We do not hold them. The connection runs through Meta's official providers, so your number carries no risk from anything we do with those credentials.

Related posts

Get started

Get twice the output from your team without asking more of them

It answers WhatsApp, Instagram and web. It learns your business, takes the orders, and hands off to a person when it matters. You see every action noted in the chat.

Free Pro trial. No credit card required.