LeadMove Docs
Developers

Data sent to a connected assistant

What leaves your account when you connect an assistant, who receives it, what never leaves, and how to stop it.

When you connect an assistant, the answers to its questions leave your account and reach the company that provides that assistant — Anthropic for Claude, OpenAI for ChatGPT — under their terms, not ours.

That includes your leads' contact details, unless you turn on Mask personal fields on the connection.

Nothing leaves until you connect one, only what a question actually needs is read, and credentials never leave at all.

What is sent

Only in response to a question, and only from your organization:

  • Pipelines, sources, buyers, routing rules — their settings, as the app shows them.
  • Leads — fields, score and grade, routing status, and the trace of what happened to them.
  • Contact details — names, emails, phone numbers, when the question is about a specific lead, because that is the answer.
  • Deliveries and disputes — attempts, responses from your buyers' systems, dispute notes.
  • Reports — counts, trends, spend, usage against your quota.

Turning on Mask personal fields partly hides names, emails and phone numbers in everything a connection reads. It is forced on for members, and off by default for admins and owners — masking is a choice for the people who already see this data in the app all day.

What is never sent

No permission and no request reaches these:

  • API keys, of any kind, including your pipelines' ingestion keys.
  • Buyer portal passwords or sign-in tokens.
  • The authentication headers on a delivery endpoint — an assistant sees that an endpoint has headers and what they're called, never their values.
  • The values in a webhook URL's query string, such as a key passed as ?api_key=…. An assistant sees the parameter names (?api_key=•••), never the values, and the activity log shows them the same way.
  • The fixed values in a webhook's body template or URL parameters, such as apikey set to your buyer's key. An assistant sees each parameter's name and the lead fields it sends ({email}), and ••• for a fixed value. The activity log shows them the same way.
  • Payment details, card numbers, invoices.
  • Anything belonging to another organization.

Who receives it

The provider of the assistant you connected, and nobody else. We do not send your data to any assistant you have not connected.

That provider is your sub-processor for this purpose, not ours — you chose it, and their terms govern what they do with it, including whether they train on it. Our own sub-processors are listed in the privacy policy.

What we keep

Every call a connection makesThe tool name, whether it worked and how long it took — kept 30 days
Every change it appliesWhat changed, before and after, kept 2 years in the activity log
The questions you askedNot stored by us. They live in your assistant's own history
The key or tokenOnly a fingerprint. Nobody, including us, can read it back

The per-call log deliberately records the shape of a request, never its values — a search term is exactly the argument that carries an email address.

How to stop it

  • Settings → Developers → Assistant access, turn off Let assistants read this workspace. Everything stops on the next request, including the in-app assistant.
  • Mask personal fields on a connection, to keep the answers while hiding the contact details.
  • Suspend a connection to pause it, or Revoke it to end it.

Revoking does not reach back: what an assistant already read has already been sent. Revoke first, then ask the provider about their retention if it matters.

Questions

Is my data used to train a model? That is between you and the provider you connected, and it is governed by their terms and your account with them. We don't send anything to a model on your behalf here — your assistant pulls what it needs and does what its own terms say.

Can I connect an assistant and keep contact details out of it entirely? Turn on Mask personal fields. Reports, routing traces and configuration stay fully readable; names, emails and phone numbers come back partly hidden.

Does the in-app assistant send the same thing? Almost, with one difference: it never masks contact details, connected or not. You are already looking at the app, where a lead's name, email and phone are one click away, so hiding them in an answer would not keep them from you. It can also propose changes, the same way a connected assistant does — but only ever as a card you apply yourself; it has no way to apply one on its own. It is governed by the same read switch.

On this page