AI Assistant Data Flows Addendum (v1.0)

Effective date: v1.0 · Last updated: May 2026

Key facts

  • Raw image, video, and audio content is never sent to AI providers in v1.0 of Rosie.
  • Consent applies at the organization level. An organization owner on a paid plan signs this addendum once on behalf of all members.
  • You can revoke consent at any time from Organization Settings → AI Assistant. Rosie stops accepting new requests for your organization within 60 seconds.
  • Conversation content is retained for up to 37 days; usage metadata is retained as part of our audit log (see §5).

1. Introduction

This AI Assistant Data Flows Addendum ("Addendum") forms part of the ReelStorage Terms of Service between K5 Labs, LLC, operating as ReelStorage ("ReelStorage," "we," "us"), and your organization ("you," "Customer"). It describes how your data is processed when you use Rosie, the ReelStorage AI Assistant feature.

By enabling Rosie for your organization, you acknowledge and agree to the data-flow practices described in this Addendum. This Addendum is versioned; the URL of this page (/legal/ai-data-flows/v1.0) is the permanent canonical link to the version your organization consented to. Future versions ship under a new path (e.g., /legal/ai-data-flows/v1.1) and require fresh consent before Rosie continues to function for your organization.

2. AI Providers

Rosie routes inference requests through the following AI providers. Consenting to this Addendum covers both providers so that your organization is not asked to re-consent if ReelStorage exercises automatic failover between them.

ProviderModelPurposeProcessing region
Google LLC (Gemini API, paid tier)Gemini 3.1 Flash-LitePrimary AI inference — natural language understanding and tool executionUnited States
OpenAI, L.L.C.Reserved for automatic failoverBackup inference when the primary provider is unavailable.United States

Both providers are listed as sub-processors on our Sub-Processors page. The data-processing agreement between ReelStorage and each provider requires the provider to use your data only to fulfill the inference request and prohibits training on Customer data. A copy of the applicable provider DPA is available on request — see §8.

3. Data Categories Sent to AI Providers

3.1 What is included

When you or a member of your organization sends a message to Rosie, the following categories of data may be included in the request sent to the AI provider:

  • Your chat message. The literal text of the message you typed in the Rosie panel.
  • System prompt and tool schemas.A ReelStorage-authored system prompt describing Rosie's capabilities, plus structured schemas for the tools Rosie can call. These do not contain your personal data but define the assistant's behavior.
  • Asset filenames and labels. The names and assigned labels of assets in your project, retrieved when Rosie executes a search or inspection tool.
  • Asset metadata. Structured metadata attached to assets, including file type, size, duration, resolution, IPTC/XMP tags, custom fields, and collection membership. This metadata is what Rosie reads when you ask it to find, describe, or organize assets.
  • Project name and structure. The name of the project you are working in, folder structure, project-level settings, and status information (e.g., whether the project is active or archived).
  • Tool outputs. Structured results returned by the tools Rosie calls during a conversation — for example, the metadata records of the assets that matched a search query. These outputs are passed back to the model as context so it can formulate a useful response.

3.2 What is never included in v1.0

The following data categories are explicitly excluded from what Rosie sends to AI providers in v1.0. If a future version of Rosie introduces any of these categories, a new addendum version (e.g., v1.1) will be published and fresh consent will be required before any affected data is sent.

  • Raw image, video, or audio content. Rosie does not download or transmit the binary content of your media files to any AI provider. Only metadata associated with assets is sent.
  • Full file contents of non-media documents. Text extraction or full-content analysis of PDFs, spreadsheets, or other documents is not performed in v1.0.
  • Biometric data.Facial-recognition embeddings and face-detection outputs are processed within ReelStorage's self-hosted infrastructure and never cross the boundary to any third-party AI provider.
  • Credentials, tokens, or secrets. ReelStorage never includes API keys, access tokens, passwords, or cryptographic secrets in AI requests.
  • Billing or payment information. Payment method details and invoice data are never sent to AI providers.
  • Other organizations' data. Every Rosie session is strictly scoped to the project and organization you are authenticated against. Cross-organization data access is not permitted.

4. Region of Processing

AI inference for Rosie is performed by sub-processors headquartered in the United States, governed by the data-handling commitments in each provider's published API Terms and Data Processing Addendum.

If your organization is subject to data-residency requirements that restrict processing outside a specific region or jurisdiction, please contact [email protected] before enabling Rosie. EU-residency endpoints are on the ReelStorage roadmap but are not available in v1.0.

5. Logging and Retention

5.1 LLM observability traces

Rosie inference calls are traced through Braintrust, a third-party LLM-observability sub-processor. Each trace includes the prompt sent to the model, the model's response, token counts, latency, cost metadata, and ReelStorage-assigned identifiers (your user, organization, and project IDs, and the addendum version in effect at the time of the call). Trace data is used by ReelStorage to diagnose issues, evaluate model quality, and monitor usage patterns. Trace data is retained for 90 days, after which it is purged from the Braintrust platform.

5.2 Audit logs (ReelStorage platform)

ReelStorage maintains its own audit log of every Rosie action — including tool invocations, write operations, credit-consumption events, consent grants and revocations, and any administrator views of conversation content. These logs are stored in ReelStorage's own infrastructure (not at the AI provider) and are subject to the following retention schedule:

  • Minimum retention: 1 year. All Rosie-related audit log entries are retained for a minimum of 12 months from the date of the event.
  • Extended retention while assets remain active. Audit log entries associated with assets or projects that remain on the ReelStorage platform beyond the 1-year mark are retained for as long as those assets exist on the platform.
  • Deletion on organization offboarding. When your organization is deleted from ReelStorage, all associated audit log entries are deleted within 30 days, subject to any legal-hold obligations.

5.3 Provider retention and the no-training commitment

Neither Google LLC nor OpenAI, L.L.C. trains its foundation models on data submitted via ReelStorage's paid-tier API integration. This commitment is reinforced through ReelStorage's data-processing agreement with each provider and is also documented in each provider's published API Terms.

Under default API behavior, each provider retains submitted content for a limited abuse-monitoring window. As disclosed by each provider:

  • OpenAI: abuse-monitoring logs are retained for up to 30 days unless a longer period is required by law, after which they are deleted.
  • Google (Gemini API, paid tier): retention is for a limited period for the same abuse-monitoring purpose. The retained content is access-controlled and contractually scoped to abuse-detection use.

OpenAI reserves the right, as disclosed in its public terms, to retain content classified as severely violating its usage policies on certain frontier models. ReelStorage's v1.0 failover target is not currently subject to this retention; this disclosure is included so that future provider-model changes do not require re-consent.

ReelStorage does not enable provider features that would override these retention commitments — for example, Google's web- or maps-grounding features (which would attach a 30-day grounding-data retention) are not used in Rosie.

ReelStorage is separately pursuing Zero Data Retention amendments with each provider. When approved, this Addendum will be updated to a new version (v1.1) and consenting organizations will be prompted to re-consent to the upgraded terms.

5.4 Conversation storage and retention

Rosie conversations are stored within your organization's account on the ReelStorage platform. Conversations have two retention tracks:

  • Conversation content (messages, tool calls, and model responses) is retained for up to 37 days: 30 days of active retention plus a 7-day soft-delete buffer. After this window, the content is permanently deleted. You may delete a conversation earlier, in which case it is permanently removed within 7 days.
  • Conversation metadata (the conversation record, title, timestamps, message counts, token counters, model identifier, and the associated audit-log entries) is retained indefinitely, subject to the audit-log retention schedule in §5.2. After conversation content expires, an administrator viewing an old conversation sees the metadata but not the message body.

This two-track retention model reflects the data-minimization principle for message content together with the longer retention applicable to ReelStorage's audit logs.

5.5 Organization administrator visibility

Rosie conversations are work product produced on the ReelStorage platform on behalf of your organization. Organization administrators with the relevant organization-level permission can read the message content of any Rosie conversation in their organization while the content is retained (the 37-day window described in §5.4) and can read the associated conversation metadata for as long as it is retained.

Every administrator view of a user's conversation content is itself written to the audit log, so that history is recoverable on request. This visibility model mirrors how organization administrators access other work product on the platform (assets, comments, audit logs), and is disclosed inline in the Rosie chat panel on first use.

6. Your Rights

6.1 Revoking consent

An organization owner may revoke consent at any time from Organization Settings → AI Assistant. Upon revocation:

  • Rosie stops accepting new requests from your organization within 60 seconds.
  • Any in-flight Rosie request that has already begun processing will complete normally; subsequent requests are rejected.
  • Previously generated audit logs, observability traces, and credit-period records are retained according to the schedules described in §5 — revocation does not delete historical records.
  • Re-enabling Rosie is possible at any time by re-signing the then-current addendum from the same settings page.

6.2 Reviewing Rosie activity

Organization owners and members with the appropriate organization permission may review their organization's Rosie activity from Organization Settings → AI Assistant, including recent audit entries and read-only access to individual conversation threads. To request a full export of your organization's Rosie audit logs, contact [email protected].

6.3 Data subject rights (GDPR / CCPA)

If your organization is subject to GDPR, CCPA, or comparable data-protection law, individual data-subject rights (access, rectification, erasure, portability) related to data processed through Rosie are handled through ReelStorage's standard privacy request process described in the Privacy Policy. Rosie-specific data is included in the scope of these requests. Account-deletion requests trigger immediate hard-deletion of all conversation content and metadata owned by that user, overriding the §5.4 retention schedule. Submit requests to [email protected].

7. Changes to This Addendum

ReelStorage will publish updates to this Addendum at a new versioned URL (e.g., /legal/ai-data-flows/v1.1) when material changes occur — for example, adding new data categories, adding new AI providers, changing the processing region, or changing the retention model. Material changes require your organization owner to review and re-sign the new version before Rosie continues to function for your organization. Changes to the list of sub-processors are also notified in accordance with our Sub-Processors page.

Non-material clarifications (e.g., correcting a typographical error or adding a contact email) may be published as updates to this page without triggering a re-consent flow; in those cases, the "Last updated" date at the top of this page will change but the version number will not.

The consent record stored for your organization always references the exact version your owner signed, so the signed text is permanently available at its original URL regardless of future version changes.

8. Contact

For questions about this Addendum or ReelStorage's AI data practices, contact us at: