Skip to main content

ClearPoint AI Assistants and Privacy

Learn how ClearPoint handles your data when you use AI features, including data processing, OpenAI retention policies, encryption, and privacy compliance.

Written by Ted Jackson

ClearPoint AI uses OpenAI's API to power its analysis, recommendations, OKR generation, and strategic planning features. This article explains how ClearPoint handles your data when you use AI features, and what protections are in place to keep your information secure.


Which AI Model Does ClearPoint Use?

ClearPoint AI is powered by OpenAI GPT-4o, OpenAI's flagship large language model. When you use any AI feature in ClearPoint — including Analysis & Recommendations, OKR generation, Strategic Plan AI, Summarize, and Ask Me Anything — your request is processed via the OpenAI API.


User Consent

When you first use an AI feature in ClearPoint, you will be prompted to review and accept the OpenAI Subprocessor Agreement. AI features are only activated after you accept this agreement. You are always in control — the AI assistant will only process data that you choose to share within the AI interaction.


How Your Data Is Processed

When you use a ClearPoint AI feature, the content of your request — including any element data you are viewing — is sent to the OpenAI API for processing. ClearPoint takes the following steps to protect your data before and during transmission:

  • Anonymization — personally identifiable information (PII) is removed from data before it is sent to the OpenAI API, so that requests cannot be traced back to individual users.

  • End-to-end encryption — all data transmitted to and from the OpenAI API is encrypted in transit and at rest using strong encryption protocols.

  • No persistent storage of AI interactions — ClearPoint does not store the content of your AI interactions unless you explicitly save or apply the AI's output to an element in ClearPoint.


OpenAI Data Retention

OpenAI maintains a short-term retention policy for data sent via the API for debugging and abuse monitoring purposes. Key points:

  • OpenAI retains API data for up to 30 days, after which it is deleted.

  • OpenAI does not use data sent via the API to train or improve its models. API data is separate from data used for model training.

For full details, see OpenAI's API data usage policies.


Regulatory Compliance

ClearPoint's AI features comply with applicable data privacy regulations, including:

  • GDPR — General Data Protection Regulation (EU)

  • CCPA — California Consumer Privacy Act

  • Other applicable regional data privacy laws

Users retain all rights regarding their personal data, including the right to access, correct, and request deletion of their data. For data-related requests, contact [email protected].


AI Respects ClearPoint Permissions

ClearPoint AI only operates on data that you have access to within ClearPoint. The AI cannot access data outside your account, scorecards you don't have permission to view, or other users' private information. All AI interactions respect the same role-based access controls that govern the rest of ClearPoint.


Privacy by Design

Privacy is built into ClearPoint AI from the ground up — it is not an afterthought. ClearPoint regularly audits its AI data practices, monitors use of the OpenAI API, and updates its privacy policies to align with industry best practices and regulatory requirements.


Questions?

If you have questions or concerns about how ClearPoint handles your data when using AI features, contact ClearPoint Support at [email protected].


Related Articles

Did this answer your question?