Where Does an AI Agent's Data Live, and Who Owns It When the Build Ends?
An agent can run in your account while sending customer information elsewhere. Check who controls every destination before you sign.
A starting map for tracing an agent's data, including what reaches a model provider. Use six questions to check account control and put the handover terms in writing.
An AI agent's data locations are the places it reads, writes or sends information while it works. Map the business systems, runtime, logs, model services and any other processors involved.
An AI agent's data map should name every destination and who controls it. A description such as "in the cloud" leaves you unable to check retention, access or what happens when the vendor relationship ends.
Quick Answer
Start by checking your business systems, the agent's runtime, its logs and any model providers. These are categories to investigate; a workflow can include additional storage, backups, monitoring services and processors. Ask the vendor to trace each transfer, state the retention terms and document which accounts you control before you pay.
Four Categories to Investigate
Trace a booking request through each component that handles it, adding destinations as you go.
1. Your systems of record
The CRM, accounting package, inbox, calendar and job-management software stay where they are. The agent connects to them through accounts you authorise, and you can end that access by revoking the connection. If the workflow moves records into a vendor's platform, add that destination to the map and ask how you can export and delete those copies.
2. The place the agent runs
Check whose name is on the agent's hosting account and who pays its bill. DeployLabs builds agents on your own infrastructure from day one, in a cloud account or server you control.
3. The agent's log
Ask where the agent records its requests, actions and results. Those logs can sit with the agent or in separate monitoring tools. You need access to explain what happened when a customer questions an action.
4. The model provider
Hosted inference sends a request to the model provider. That request can carry instructions, selected records and tool results. The provider's terms govern retention. Running inference locally removes that particular transfer; check the rest of the workflow for external connections.
What Anthropic and OpenAI Publish About Your Data
The following statements cover the cited API and commercial-product policies. Consumer chat apps have separate terms.
Both providers state that API inputs and outputs are not used for training by default. Anthropic states that "by default, we will not use your inputs or outputs from our commercial products (e.g. Claude for Work, Anthropic API, Claude Gov, etc.) to train our models" (Anthropic privacy centre). OpenAI states that "as of March 1, 2023, data sent to the OpenAI API is not used to train or improve OpenAI models (unless you explicitly opt in to share data with us)" (OpenAI platform documentation).
Retention follows different rules at each. For API users, Anthropic states that it automatically deletes inputs and outputs on its backend within 30 days of receipt or generation (Anthropic privacy centre). Its stated exceptions are services with longer retention under your control, such as its Files API; cases where you and Anthropic have agreed otherwise, such as a zero data retention agreement; retention needed to enforce its Usage Policy; and retention required by law. OpenAI states that abuse monitoring logs are generated for all API feature usage by default and retained for up to 30 days, unless longer retention is required by law, or is reasonably necessary to protect its services or any third party from harm (OpenAI platform documentation). Eligible customers approved for its Zero Data Retention or Modified Abuse Monitoring controls can have customer content excluded from those logs. Its documentation also lists stored API objects that stay until you delete them.
Terms change, and they differ by plan. Run the check against the current page for the account your agent will use.
Not sure where AI fits in your operations?
Take the Free AI Readiness Scorecard →Canadian Privacy Guidance: Responsibility Stays With You
In its guidance on cross-border processing under PIPEDA, the Office of the Privacy Commissioner of Canada says an organization "is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing" (OPC, Guidelines for processing personal data across borders, 2009). The same guidance says organizations must tell individuals that their information may be processed in a foreign country and may be accessible to law enforcement and national security authorities of that jurisdiction. It adds that no contract can override the laws of the country to which the information has been transferred.
This January 2009 guidance predates generative AI. Applying its accountability principle to a hosted model is an inference. Which law governs depends on your province, sector and activity; counsel should confirm the applicable obligations before deployment.
What Goes Wrong When Ownership Is Unclear
Modelled example: a business ends its vendor contract. Its CRM and inbox remain accessible, but the agent's workflows, logs and model account sit with the vendor. Without a runnable handover, it has to rebuild the workflow.
Modelled outcome: with accounts it controls and a handover it has tested, the business revokes the vendor's access and keeps running. This is a hypothetical comparison, with no measured customer outcome.
What Should Transfer When the Build Ends
Get the answers to these six questions in writing before signing.
- Who owns the account the agent runs in on day one, and who pays for it?
- In whose name is the model provider account and its access key?
- Can you export the agent's log in a readable format?
- Do the workflows and rules exist in a form you can run without the vendor?
- Which providers bill you each month, and at whose rates?
- Does the vendor keep any copy of your data after handover?
At DeployLabs, the handover at final payment covers the data, the accounts the agent runs in, the configured workflows as installed, your rules as encoded, the credentials and the documentation, all runnable on infrastructure you control. The agent is yours, outright. Hosting, model usage and any software subscriptions remain separate bills from those providers, charged to your accounts at their own rates, so running the agent still carries hosting and usage costs.
Two Objections
The first: "A vendor-hosted platform is simpler, so why own the accounts?" A hosted platform can suit your business. Use the six questions to establish its exit terms and test the export process before committing.
The second: "Then I will run the model myself." Local inference brings hardware, maintenance and capability decisions. It also leaves every other external connection to check. A two-week assessment can compare these choices for one workflow.
For the build-or-buy decision, start with three diagnostic questions. Review access controls alongside the data map using seven governance gaps.
Before signing, have the vendor walk through the data map and demonstrate the proposed handover. Check that your team can run the workflow, find its logs and revoke the vendor's access using accounts it controls.
If you want the data locations mapped for one real workflow in your business, the AI Workflow Assessment does that in two weeks, and the fee is credited toward a build. You can also check where you stand today with the AI readiness scorecard.
If the vendor relationship ended tomorrow, could your team run the workflow and account for every copy of its data?
- Map your business systems, the agent's runtime, its logs and any model providers, then add other storage and processors the workflow uses.
- Check who controls each account, who processes the information and how long each copy stays.
- Default training and retention are separate questions. Check both against the current policy for the exact product and account you use.
- The Privacy Commissioner's 2009 PIPEDA guidance keeps responsibility with the organization transferring personal information for processing. Ask counsel which law and obligations apply to your activity.
- Get six answers in writing before you sign: who owns the account, the provider key, the log, the workflows, the monthly bills, and any copy the vendor keeps.
Related Reading
- Custom AI or Off-the-Shelf? Three Diagnostic Questions for Small Business - a way to decide which approach fits before you compare vendors.
- The 7 AI Agent Governance Gaps Most SMBs Don't Know They Have - who can see and change what an agent does.
- Shadow AI and Legal Liability: What Canadian Business Owners Need to Know in 2026 - the legal exposure when staff use AI tools nobody approved.