Legal · AI Addendum

AI Addendum

The AI-specific commitments: which models see your content, what they may not do with it, and where the limits of an autonomous agent are.

Last updated 24 July 2026 · Effective 24 July 2026

This Addendum forms part of the Terms of Service and the Data Processing Addendum. It exists because generic AI language in a standard SaaS contract does not answer the questions a security or legal reviewer actually asks.

1. The no-training commitment

Your content is never used to train, fine-tune, or improve any machine learning model. Not ours. Not our model providers’. Not any third party’s.

This applies to everything you put into or generate within the Service:

  • Documents and knowledge base content
  • Table data
  • Prompts, instructions and agent configuration
  • Chat and conversation history
  • Model output generated for you
  • Audit and run records

This is a contractual restriction on every model provider we engage, using zero-retention or no-training terms where the provider offers them, not merely an internal policy. If we ever wanted to change it, it would require your affirmative opt-in — not a change to this page.

2. Which models see your content

Content is sent to a model provider only when an agent runs, only for inference, and only to the provider that agent is configured to use. There is no silent routing, no aggregation layer that shops your prompt around, and no default provider that sees everything.

Every provider we support is named individually, with its processing location, on the subprocessors page. Read that list before you assume where your data goes — one supported provider is located in the People’s Republic of China, and it is named there rather than hidden inside a regional aggregate. It is engaged only if you configure an agent to use it.

2.1 Bring your own keys

Where you supply your own provider API key, requests run under your agreement with that provider, and you are billed by them directly. In that arrangement the provider is your subprocessor, not ours, and their terms — including their training and retention terms — govern that processing. We do not intercept, log the content of, or mark up those requests.

3. Autonomous action

The Service does not only generate text. It acts: it sends email, creates and modifies records, posts messages, and calls APIs on systems you connect. Those actions are real and frequently irreversible.

Three things follow, and you should be clear on all three:

  • You decide the autonomy. You configure which tools an agent may use, what it may do without asking, and what requires a human to approve.
  • We enforce your decision in the execution path. A policy engine evaluates every tool call before it runs. An unapproved write is a no-op regardless of what the model decided or what a prompt told it to do. The gate is not advisory.
  • You are responsible for the configuration. Choosing to let an agent act without review is a decision you make, and you are responsible for the consequences.

4. Human oversight controls

Available to you, and we recommend using them for anything consequential:

  • Approval gates — an agent pauses and requests human approval before a sensitive action. Approval grants are single-use: approving once does not approve the next call.
  • Policy rules — allow or block by tool, integration, or operation type, evaluated before execution.
  • Read-only mode — grant retrieval without write access.
  • Budget caps — hard spend limits that stop execution at the ceiling.
  • Circuit breakers — automatic halt on repeated failure or anomalous behaviour.
  • Audit trail — every run and tool call recorded with sanitised inputs and outputs, pinned to the immutable config version it ran under, so you can reconstruct exactly what happened and under what rules.

5. Known limitations

Stated plainly, because a reviewer will ask and a vague answer wastes everyone's time:

  • Output can be wrong. Models fabricate confidently. Output can be inaccurate, outdated, internally inconsistent, or entirely invented while appearing authoritative.
  • Output is not deterministic. The same input can produce different output on different runs.
  • Models carry bias from their training data, which can surface in ranking, screening or summarising tasks.
  • Prompt injection is a real risk. An agent reading untrusted content — a web page, an inbound email, a shared document — may encounter text crafted to redirect it. We apply injection defences and a governance gate that limits what a redirected agent can actually do, but no defence is complete. This is why approval gates matter on anything that leaves your system.
  • We do not guarantee output accuracy, and no SLA covers it.

6. Prohibited and high-risk uses

The Acceptable Use Policy prohibits deploying agents to make final, unreviewed decisions materially affecting a person’s rights, safety, livelihood or access to services — employment, credit, insurance, healthcare, legal advice, housing, education and public benefits. Agents may assist with these; a competent human must decide.

7. Transparency and the EU AI Act

Where you use the Service to interact with people, you are generally the deployer of the AI system and we are the provider of the underlying platform. Article 50 of Regulation (EU) 2024/1689 places transparency duties on both, and the allocation matters:

  • We provide the mechanism. Chat surfaces identify themselves as AI, and the platform gives you the means to disclose AI involvement on the surfaces you build.
  • You are responsible for the disclosure where you deploy an agent to interact with your own customers, employees or the public — including telling them they are interacting with an AI system, and labelling AI-generated content where the law requires it.
  • Do not configure an agent to deny being an AI or to impersonate a named real person. This breaches the Acceptable Use Policy.

If your deployment falls into a high-risk category under the AI Act, you carry the corresponding obligations. We will provide the technical information reasonably available to us to support your assessment — write to legal@turtleaicoworker.com.

8. Intellectual property in output

As between you and us, you own the output generated for you, to the extent output is capable of ownership under applicable law. Note two limits that are features of the technology, not of our terms: AI-generated material may not attract copyright protection in some jurisdictions, including India and the United States; and identical or similar output may be generated for another user from a similar prompt, so we cannot grant exclusivity over it.

We make no warranty that output does not infringe a third party’s rights, and we do not offer an IP indemnity for model output. Review output before publishing or relying on it.

9. Changes

Adding a model provider is a change to the subprocessor list and carries 30 days’ notice with a right to object. We will not weaken the no-training commitment in clause 1 without your affirmative opt-in.

Questions about this document? Write to legal@turtleaicoworker.com.