Skip to main content

Data access and data minimisation

The most common question about Revizo AI is “what does it get access to?”. The answer has two parts: what the assistant can look up through tools, and what is actually sent to the model provider in one request. They are not the same, and the difference is the point of the data minimisation.


Principle​

Revizo does not send the accounts to the model “just in case”. Each request receives:

  1. a small, fixed set of context about the user and where they are,
  2. what the user themselves have written or pasted,
  3. the result of the tools the model asked for — and only those.

Everything is fetched with organisation ID from the logged-in session. Nothing in the context can come from another organisation.


What is included in one request​

Always included​

DataSourceWhy
The user’s first name, organisation name, roleClerk sessionAddress and adaptation
Number of clients in the organisationDatabase (counted)So the assistant knows the scope it is talking about
The page the user is on, and sectionBrowserContextual replies and navigation
Active company and client (name)Database, filtered on tenantLooks up the name only if it belongs to the organisation — otherwise it is omitted
Date and time (Europe/Oslo)ServerSo deadlines and “next week” are correct
The conversation so farBrowser → serverContinuity in the dialogue
The structure of the side menuCodeSo the assistant links to the right pages

Included when relevant​

DataTriggered byLimitation
Hits in Revizo’s knowledge base (product help, deadlines, FAQ)Product and how-to questionsRevizo’s own text, not customer data
The user’s own “memories”All chats except the task panelMax 10 per request, max 50 stored per user. Short preference and context sentences.
Contact list (name, role, company)The organisation has contactsMax 25 contacts, without email address. Email is fetched only when a tool looks up one specific contact.
Details about one taskThe user chats from an open task panelOnly tasks the user themselves has access to see. HTML is stripped to plain text.
Screenshots the user pastesThe user pastes an imageMax 4 per message. Sent to Anthropic as an image.
Tool resultsThe model calls a toolSee the next section

What the tools can return​

Tool results are the only path to domain data. Each tool returns a bounded, structured extract — not raw tables.

Tool groupExample of what is returnedWhat is not returned
Clients and statusClient name, number of unmatched items, deviations, responsible personIndividual transactions, bank account numbers
TasksTitle, status, deadline, subtasks, notes — for tasks the user can seeTasks that are private to others or other teams
Smart MatchNumber of matches, percent reconciled, periodThe transaction lines themselves (shown in the UI, not in the model)
ContactsName, role, email, companyFree-text notes about the contact
Calendar and remindersTitle, timeContent in external calendars beyond what the user has connected
TeamWorkload per member, absenceSalary, personal details
ArchiveFolder names, document titles, metadataThe document content
LovdataSection, statutory text, link— (public source)
ExportFilename, size, number of rowsThe file’s content (delivered directly to the user, not via the model)

One tool is worth mentioning specifically: routine description on account keeps the account’s existing routine text deliberately outside the model’s context. The text accompanies the confirmation card to the browser so the user can undo, but it is not sent to Anthropic.


What is never sent​

  • Data from other organisations. All lookups are filtered on tenant_id from the session.
  • National ID numbers and bank account numbers. The assistant is instructed not to reproduce them, and the reply is filtered server-side for such patterns. Instruction and filter are a safety net — the primary protection is that the tools do not return the fields.
  • Entire transaction sets, general ledger, or chart of accounts.
  • File bytes from attachments in ordinary chat. Document analysis is a separate function that can be turned off separately, and sends only extracted text (max 15,000 characters).
  • Integration tokens, API keys, or other secrets.
  • Login, passwords, or session data.

Where data is processed​

ProcessingProviderLocationWhat is sentTraining on data
Chat and tool choiceAnthropicUSASystem prompt, conversation, context, tool results, screenshotsNo — commercial API agreement
Document analysisAnthropicUSAExtracted text from the attachmentNo
Semantic search in help textOpenAIUSAThe user’s question textNo
Voice modeOpenAIUSAAudio, transcription, tool results for the curated subsetNo
Conversation archive, memories, usageSupabaseFrankfurt——

About retention at the provider: Anthropic and OpenAI process the request to deliver the reply, under their commercial API terms. Revizo has not ordered storage with them, and does not use the provider’s history for anything. Current agreement status, including any zero-retention agreements, is documented in the provider pack we send on request — see Sub-processors.

About transfer to the USA: The transfer is limited to what is needed for the relevant function, and is secured with the European Commission’s standard contractual clauses (GDPR Art. 46(2)(c)). The organisation can choose to turn the AI functions off entirely or in part. See Data Processing Agreement.


What Revizo stores​

TableContentPurposeRetention
ai_conversationsMessages, replies, tools used, token usage, page context, ratingConversation history for the user, cost controlDeleted automatically after 90 days. The user can delete individual conversations at any time.
ai_user_memoryShort sentences about the user’s preferences and work patternPersonal adaptation across conversationsExpires per type (60–180 days, preferences until they are replaced). Max 50 per user. Deleted with conversations older than 90 days.
ai_usage_logModel, tokens, category, estimated cost, timestampQuota and billingAs long as the organisation is active
ai_export_filesFiles created via chat (Excel, CSV, PDF)Download from the cardDeleted after 24 hours
Audit logActions performed via the assistantAudit trailAs long as the organisation is active

All rows are tied to tenant_id and are deleted together with the organisation. See Data retention.

What is not stored: The model’s internal reasoning and tool arguments that were rejected. Screenshots the user pastes are stored as part of the conversation, in the same tenant and with the same 90-day deletion, so the user can see what was asked about.


The user’s own control​

WishHow
See previous conversationsAI page → sidebar
Delete a conversationMenu on the conversation → Delete
Delete all conversationsDeleted automatically after 90 days, or contact support for immediate deletion
Prevent anything being sent to a modelAdministrator turns the function off under Settings → AI & Privacy
Export conversation dataIncluded in the organisation’s full data export (Settings → Danger zone)

Data minimisation in practice — an example​

User on the matching page for the client “1920 Bank” writes: “How many items remain, and run Smart Match.”

Sent to Anthropic in the first round:

  • System prompt with rules and tool catalogue
  • “User: Kari · Organisation: Byrå AS · Role: Member · Number of clients: 42”
  • “Current page: /avstemming/matching/… · Section: matching · Active client: 1920 Bank”
  • Date and time
  • Name, role, and company for up to 25 contacts (without email)
  • Up to 10 short memories about Kari
  • The message

The model asks for run_smart_match with client ID from the page context.

Revizo verifies that the client belongs to Byrå AS, runs the matching, logs match.created in the audit log, and returns:

  • “client: 1920 Bank · number of matches: 18 · percent reconciled: 92 · remaining: 4 · period: Jan–Mar 2026”

Not sent: the 34 transactions that were matched, balances, bank account numbers, status of the other 41 clients, the contacts’ email addresses, and the content of any task.


Last updated: September 2026