Data access and data minimisation
The most common question about Revizo AI is “what does it get access to?”. The answer has two parts: what the assistant can look up through tools, and what is actually sent to the model provider in one request. They are not the same, and the difference is the point of the data minimisation.
Principle
Revizo does not send the accounts to the model “just in case”. Each request receives:
- a small, fixed set of context about the user and where they are,
- what the user themselves have written or pasted,
- the result of the tools the model asked for — and only those.
Everything is fetched with organisation ID from the logged-in session. Nothing in the context can come from another organisation.
What is included in one request
Always included
| Data | Source | Why |
|---|---|---|
| The user’s first name, organisation name, role | Clerk session | Address and adaptation |
| Number of clients in the organisation | Database (counted) | So the assistant knows the scope it is talking about |
| The page the user is on, and section | Browser | Contextual replies and navigation |
| Active company and client (name) | Database, filtered on tenant | Looks up the name only if it belongs to the organisation — otherwise it is omitted |
| Date and time (Europe/Oslo) | Server | So deadlines and “next week” are correct |
| The conversation so far | Browser → server | Continuity in the dialogue |
| The structure of the side menu | Code | So the assistant links to the right pages |
Included when relevant
| Data | Triggered by | Limitation |
|---|---|---|
| Hits in Revizo’s knowledge base (product help, deadlines, FAQ) | Product and how-to questions | Revizo’s own text, not customer data |
| The user’s own “memories” | All chats except the task panel | Max 10 per request, max 50 stored per user. Short preference and context sentences. |
| Contact list (name, role, company) | The organisation has contacts | Max 25 contacts, without email address. Email is fetched only when a tool looks up one specific contact. |
| Details about one task | The user chats from an open task panel | Only tasks the user themselves has access to see. HTML is stripped to plain text. |
| Screenshots the user pastes | The user pastes an image | Max 4 per message. Sent to Anthropic as an image. |
| Tool results | The model calls a tool | See the next section |
What the tools can return
Tool results are the only path to domain data. Each tool returns a bounded, structured extract — not raw tables.
| Tool group | Example of what is returned | What is not returned |
|---|---|---|
| Clients and status | Client name, number of unmatched items, deviations, responsible person | Individual transactions, bank account numbers |
| Tasks | Title, status, deadline, subtasks, notes — for tasks the user can see | Tasks that are private to others or other teams |
| Smart Match | Number of matches, percent reconciled, period | The transaction lines themselves (shown in the UI, not in the model) |
| Contacts | Name, role, email, company | Free-text notes about the contact |
| Calendar and reminders | Title, time | Content in external calendars beyond what the user has connected |
| Team | Workload per member, absence | Salary, personal details |
| Archive | Folder names, document titles, metadata | The document content |
| Lovdata | Section, statutory text, link | — (public source) |
| Export | Filename, size, number of rows | The file’s content (delivered directly to the user, not via the model) |
One tool is worth mentioning specifically: routine description on account keeps the account’s existing routine text deliberately outside the model’s context. The text accompanies the confirmation card to the browser so the user can undo, but it is not sent to Anthropic.
What is never sent
- Data from other organisations. All lookups are filtered on
tenant_idfrom the session. - National ID numbers and bank account numbers. The assistant is instructed not to reproduce them, and the reply is filtered server-side for such patterns. Instruction and filter are a safety net — the primary protection is that the tools do not return the fields.
- Entire transaction sets, general ledger, or chart of accounts.
- File bytes from attachments in ordinary chat. Document analysis is a separate function that can be turned off separately, and sends only extracted text (max 15,000 characters).
- Integration tokens, API keys, or other secrets.
- Login, passwords, or session data.
Where data is processed
| Processing | Provider | Location | What is sent | Training on data |
|---|---|---|---|---|
| Chat and tool choice | Anthropic | USA | System prompt, conversation, context, tool results, screenshots | No — commercial API agreement |
| Document analysis | Anthropic | USA | Extracted text from the attachment | No |
| Semantic search in help text | OpenAI | USA | The user’s question text | No |
| Voice mode | OpenAI | USA | Audio, transcription, tool results for the curated subset | No |
| Conversation archive, memories, usage | Supabase | Frankfurt | — | — |
About retention at the provider: Anthropic and OpenAI process the request to deliver the reply, under their commercial API terms. Revizo has not ordered storage with them, and does not use the provider’s history for anything. Current agreement status, including any zero-retention agreements, is documented in the provider pack we send on request — see Sub-processors.
About transfer to the USA: The transfer is limited to what is needed for the relevant function, and is secured with the European Commission’s standard contractual clauses (GDPR Art. 46(2)(c)). The organisation can choose to turn the AI functions off entirely or in part. See Data Processing Agreement.
What Revizo stores
| Table | Content | Purpose | Retention |
|---|---|---|---|
ai_conversations | Messages, replies, tools used, token usage, page context, rating | Conversation history for the user, cost control | Deleted automatically after 90 days. The user can delete individual conversations at any time. |
ai_user_memory | Short sentences about the user’s preferences and work pattern | Personal adaptation across conversations | Expires per type (60–180 days, preferences until they are replaced). Max 50 per user. Deleted with conversations older than 90 days. |
ai_usage_log | Model, tokens, category, estimated cost, timestamp | Quota and billing | As long as the organisation is active |
ai_export_files | Files created via chat (Excel, CSV, PDF) | Download from the card | Deleted after 24 hours |
| Audit log | Actions performed via the assistant | Audit trail | As long as the organisation is active |
All rows are tied to tenant_id and are deleted together with the organisation. See Data retention.
What is not stored: The model’s internal reasoning and tool arguments that were rejected. Screenshots the user pastes are stored as part of the conversation, in the same tenant and with the same 90-day deletion, so the user can see what was asked about.
The user’s own control
| Wish | How |
|---|---|
| See previous conversations | AI page → sidebar |
| Delete a conversation | Menu on the conversation → Delete |
| Delete all conversations | Deleted automatically after 90 days, or contact support for immediate deletion |
| Prevent anything being sent to a model | Administrator turns the function off under Settings → AI & Privacy |
| Export conversation data | Included in the organisation’s full data export (Settings → Danger zone) |
Data minimisation in practice — an example
User on the matching page for the client “1920 Bank” writes: “How many items remain, and run Smart Match.”
Sent to Anthropic in the first round:
- System prompt with rules and tool catalogue
- “User: Kari · Organisation: Byrå AS · Role: Member · Number of clients: 42”
- “Current page: /avstemming/matching/… · Section: matching · Active client: 1920 Bank”
- Date and time
- Name, role, and company for up to 25 contacts (without email)
- Up to 10 short memories about Kari
- The message
The model asks for run_smart_match with client ID from the page context.
Revizo verifies that the client belongs to Byrå AS, runs the matching, logs match.created in the audit log, and returns:
- “client: 1920 Bank · number of matches: 18 · percent reconciled: 92 · remaining: 4 · period: Jan–Mar 2026”
Not sent: the 34 transactions that were matched, balances, bank account numbers, status of the other 41 clients, the contacts’ email addresses, and the content of any task.
Last updated: September 2026