Build Your AI Transparency Notice

Answer what you can -- skip anything that doesn't apply. We'll draft a notice from your answers and email it to you.

AI Transparency Notice Questionnaire

The more detail you give us, the more useful your draft will be. Leave a question blank if it doesn't apply -- we'll simply omit that section rather than guess.

We'll email your draft AI Transparency Notice here as soon as it's ready. We never publish or share this address.

The Basics

Use your company's legal or commonly known brand name -- whichever your customers would recognize.

The name customers actually see in your app or marketing materials -- not an internal codename.

Describe it the way you'd explain it to a customer on a sales call, not the way you'd explain it to an engineer. Avoid technical jargon.

Not sure? Most companies select at least 'End customers.' Add 'Regulators' if you operate in the EU or another region with AI-specific disclosure laws.

Not sure whether one exists? Check your website's trust center or privacy policy, or ask your legal/compliance team.

Purpose and Features

Focus on the goal, not the technology. What problem does it solve, and what does a customer get out of using it? One or two sentences is plenty.

Put each distinct AI-powered capability on its own line. If there's really just one feature (already covered above), you can leave this blank.

Data Sources and Storage

Select every type of data the AI feature actually processes, even if a human never looks at it directly.

Think about where the data physically originates before it reaches the AI: typed in by users, uploaded documents, pulled from another system, purchased/licensed lists, etc. If you're not sure, ask engineering or product where the model gets its input.

Check your hosting agreement or ask engineering/IT if you're not sure.

Most cloud providers encrypt data by default -- ask engineering or security to confirm. It's fine to say you rely on your cloud provider's default encryption if that's accurate.

Does each customer's data live in its own separate space, or is it mixed together behind access controls? If unsure, ask engineering whether the system is "multi-tenant" with logical separation.

How long is data kept, and what happens to it if a customer cancels or deletes their account? Check your data retention policy, or ask legal/compliance if one exists.

AI Model

"Generative" means the AI creates new content, like writing a reply or an image. "Closed/non-generative" means it only picks from a fixed set of outcomes, like a category, a score, or a yes/no. Ask engineering if you're not sure.

"Built in-house" means your own engineers created the model. "Fine-tuned" means you started with someone else's model and customized it. "Used as-is" means you call a service like OpenAI or Google directly without modifying it. Ask engineering if unsure.

Third-Party AI Providers

This means a company outside your own that runs the AI model, like OpenAI, Anthropic, Google, or Microsoft. If your engineers call an external AI API, the answer is yes.

Check your contract or Data Processing Agreement (DPA) with the provider, or ask legal/procurement. Most enterprise AI agreements state customer data isn't used for training -- look for language like "will not train on your data."

How is data protected on its way to the provider? Common answers include an encrypted connection (HTTPS/TLS) and authenticated API keys. Ask engineering if unsure.

Some companies let customers connect their own OpenAI/Azure account so the customer controls that relationship directly. Most don't -- "No" is a perfectly normal answer.

Model Training

This means your company creates or customizes a model using data, as opposed to just using someone else's model unchanged. If you only call a third-party AI API without custom training, the answer is likely "No."

Describe, in general terms, what data was used to build or fine-tune the model. Ask your data science/engineering team if you're unsure.

It's common (and often preferred) to answer 'Never' or 'Only with explicit authorization.' Answer honestly based on current practice -- don't describe a policy that isn't actually in place yet.

Who can access the environment where training happens, and is it kept separate from production systems? Ask engineering/security.

Is there a review or approval step before a newly trained model replaces the current one? Ask engineering about their release/deployment process.

Principles, Bias, and Limitations

Optional. If your company has an AI use policy, data ethics statement, or similar internal commitments, summarize them here. Leave this blank if nothing formal exists yet.

Examples: approving/denying an application, scoring a person's risk, ranking candidates, verifying identity. If the AI only summarizes documents or answers general questions, the answer is likely 'No.'

It's completely fine to say this work is planned or not yet formalized -- honesty matters more than sounding polished. Ask your product or data science team what testing (if any) has been done.

What does your team already know the system gets wrong, struggles with, or wasn't built to handle? This is one of the most important sections -- a notice with no limitations listed reads as marketing, not a real disclosure.

Human Oversight and Risk

Does a person ever check, approve, or override the AI's output before it reaches the end user? If there's no such step anywhere, that's a valid (and important) thing to disclose.

Where in the process does a human look at the output, and what makes that happen -- every time, only for flagged/low-confidence results, or only if a customer asks?

What does your company actively guarantee or control on its end? Think about things like data storage security, keeping customer data separate, and system uptime.

What's explicitly on the customer's plate? A common example: keeping their own login credentials confidential, or making sure the data they upload is accurate.

Customer Controls and Continuous Improvement

Can a customer or user turn this specific AI feature off, or is it a core, always-on part of the product?

What else can a customer or user actually do? Examples: flag or correct a wrong answer, ask for a human to review it, or request their data be deleted.

Optional. Do you periodically review how well the model is performing, or plan to revisit this notice on a schedule (e.g., annually)?

Contact and Links

A real, monitored inbox or team name, e.g. your support or security team. This is the address customers will use if something goes wrong, so make sure it's actually staffed.

Paste the full web address of your published Privacy Policy, if you have one.

If you have a SOC 2 report, trust center, or security page, link to it here.

Optional -- link to any public AI use or vendor management policy summary you may have.

This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.