Do AI companies sell your data? What to read in the policy

Some may; the privacy policy is where to check. How to read its sale and sharing sections, and what Sume's policy says it collects and shares.

4 min readSume
All posts

Whether an AI company sells your data depends on the company, and its privacy policy is where to check: look for a sentence about selling personal information, then read the list of cases in which it shares data. Selling and sharing are different questions. A company that sells nothing can still pass data to the providers that host, bill and run its service.

Sume's Privacy Policy (last updated September 13, 2026) says it does not sell personal information. This post quotes that policy, the Terms of Service and the Authentication docs, all read on 2026-09-29. It is not legal advice.

What should I look for in an AI tool's privacy policy?

Four sections answer most of the question:

  • A sale statement: whether the company sells personal information, and whether it shares it for advertising.
  • The sharing list: every kind of recipient, not just "partners".
  • The service providers: by category, ideally by name, including the AI model providers that process your prompts and media.
  • The collection list: what the company gathers, from sign-in details to your uploads and logs.

Does Sume sell your data?

No. The policy states: "Sume does not sell personal information and does not share it for cross-context behavioral advertising." It then lists six situations in which it does share information:

From the "When we share information" section of Sume's Privacy Policy, read 2026-09-29.
Shared withWhen or why
Service providersHelp Sume operate, secure, bill, support, analyze, or improve the Services
Your organization's members or administratorsWhen you use Sume as part of an organization or team account
MCP clients and applications you authorizeWithin the access you grant them, until you revoke that access
Payment processors and financial service providersBilling, invoices, tax, fraud prevention, and dispute handling
Legal requests and protectionWhen required by law or legal process, or to protect the rights, safety, security, and integrity of Sume, users, providers, or the public
Corporate transactionsA merger, financing, acquisition, reorganization, or similar transaction, subject to appropriate safeguards

What data does an AI tool collect?

More than your prompts. Sume's policy lists eleven categories. The ones a buyer usually asks about:

  • Content you submit: prompts, scripts, product images, uploaded media and chat attachments, voice and text-to-speech input, reference files, URLs, avatar inputs and brand assets.
  • Agent activity: chat threads and messages, tool calls and results, spend approval decisions, scheduled runs and automation history.
  • Generated outputs and their metadata, such as media artifacts, job status and usage events.
  • Technical and security data: IP address, user agent, device and browser information, logs, crash reports and product analytics.
  • Developer data: API key metadata and prefixes, MCP client grants, webhook endpoints and usage records. The Authentication docs add that API responses expose key metadata but never the full secret.
  • Billing data. Payments are processed by Stripe, and Sume does not receive or store full payment card numbers.

Who are the service providers?

Sume's policy names some and describes the rest by category: Clerk for authentication and organization management, Vercel for hosting and delivery, Stripe for payments and invoicing, PostHog and Vercel Analytics for product analytics, and Sentry for error and performance monitoring. It also lists AI model providers for image, video, avatar, speech and language generation without naming them, and the Terms say Sume keeps its internal model routing private.

On analytics, the policy says capture is explicit rather than broad page autocapture, and where session replay is enabled it is configured to mask text input.

Does sharing include my own team?

Yes, in a team account: the policy lists your organization's members and administrators as recipients, and says an administrator of an organization you did not create may retain or remove its content after you leave. Is my data safe with AI? covers who sees what by role.

What the policy says about retention and training is covered in Is my data used to train AI? and Zero data retention for AI video APIs.

Sources

Related posts

More in Developers

All Developers posts

Written by Sume