When Kai answers a question, part of the conversation is sent to an AI provider to generate the reply. This article describes exactly what is sent, who receives it, and what you can turn off. It's written for the people who have to answer these questions in a security review.
Four things.
The customer's question and the conversation it belongs to.
The content Kai retrieved from your knowledge sources for that question — article text, crawled pages, documents.
A fixed set of fields about the contact, where you have them: name, email, phone, company ID, company name, plan, device type, platform, location, last page viewed, and your own custom attributes.
Your configuration — Kai's name, tone, language, and any custom instructions you wrote.
If contact memory is enabled, the notes saved in that contact's memory are also included.
Gleap is not tied to one AI company. Depending on the model in use, requests go to OpenAI, Anthropic, Google, xAI, Mistral, or through OpenRouter, which routes to further model providers such as DeepSeek, Qwen, Kimi, MiniMax, and GLM.
Processing locations differ per provider. Several process in the EU — Mistral and xAI in the EU, Anthropic in the US and EU, Google in the US or EU. OpenAI processes in the US. DeepSeek's direct API, used only as a fallback when those models aren't reachable through OpenRouter, processes in China.
Because this list changes as models come and go, the current version is published and maintained on Gleap's sub-processor page. Treat that page as the source of truth for an audit; the contractually binding version is Annex 8.10 of the Data Processing Addendum.
Under Gleap's agreements with these providers, they are contractually prohibited from using submitted data to train or improve their models. That applies to models reached through OpenRouter as well, which forwards requests under the same terms.
Answering isn't the only step. Finding the right content and preparing it involves a few more processors, each only when the relevant feature is used:
Embedding and reranking of your knowledge base, tickets, and messages, so search can find the right passage.
Crawling your website when you connect it as a knowledge source.
Converting uploaded PDFs and spreadsheets into text.
Web search and page retrieval, for agents that are allowed to search the web.
Isolated cloud sandboxes, where Kai Code works on the repositories you connected to.
Your conversations, contacts and databases sit on Gleap's core infrastructure in the EU (Frankfurt). Files uploaded through the widget or the dashboard — screenshots and attachments — are held in Cloudflare object storage, which is distributed rather than tied to one region. AI providers receive only what a given request needs; none of them is where your workspace is kept.
AI features are optional. If your organisation can't use them at all, they can be disabled entirely, and no data goes to any AI provider. Contact Gleap to have this set up for your workspace.
For questions about data locations, or to be notified when the sub-processor list changes, write to [email protected].