AI models and providers
Windmill uses state-of-the-art AI models from trusted providers: These models power Windy, our AI agent, to help with feedback collection, recap generation, performance review drafting, and more. Zero data retention Windmill has zero data retention enabled across all AI model providers. This means:- Your data is not stored by our AI providers after processing
- API calls are processed and immediately discarded
- No logs or caches of your data are retained by OpenAI, Anthropic, or Google
Zero data retention ensures that your company’s data never becomes part of AI provider training datasets or storage systems. In the future, if we choose to use other model providers, we only use providers that support zero data retention policies.
AI security controls
AI features follow the same access controls as the rest of Windmill. Windy cannot retrieve or use content that the requesting member cannot access. Windmill application services enforce these permissions; permission decisions are never delegated to AI models. Company isolation Search indexes and embeddings are isolated by company. Windmill checks resource-level permissions when it retrieves content. Embeddings are encrypted at rest and deleted with their linked source data. Controlled actions Windy uses defined tools with validated inputs. Model-generated requests remain subject to the same permissions as the member making the request. Windy does not execute model-generated code, browse the internet, or modify external systems. Output handling Windmill validates tool inputs and sanitizes AI-generated web content before it is displayed or used in an action.Data retention
Windmill retains data from customers as long as they have an active engagement with Windmill. Customers have the right to request complete data deletion after ending an engagement.Telemetry
Zero data retention applies to our AI model providers. Windmill records AI inputs, outputs, and tool activity as product telemetry. Access is limited to authorized personnel and is protected by audit logs. Customers can request AI interaction and tool activity logs for their Windmill environment for audit or export.Model training
We do not train public models on your data. Here’s what that means:- Windmill does not build or train generalized AI models from customer data
- Any custom AI models we train are for internal use only, strictly to operate and enhance our product
- We will never offer these models as an inference service to external parties
- When we train custom models, they’re exclusively derived from generated synthetic datasets
Your data stays your data. We never use your company’s information to improve models that serve other customers.