Data Weaver / Data protection

Know what
moves where.

Connected data is stored in the application's database. A scoped question may also send necessary evidence to an external AI provider. Your client's AI privacy mode changes what is sent—not where every part of the product runs.

Follow the data
01 / The journey

From source
to answer.

Follow the numbered steps in order. Not every question reads every source.

Illustrative data flow · third-party boundaries are explicitly marked
  1. 01 / Your sources

    Providers + CSV

    Marketing platforms supply authorized data. CSV files enter through an upload, not an OAuth connection.

  2. 02 / Connection boundary

    Authorize + select

    Nango is a third-party OAuth connection broker. After connecting, you explicitly select the accounts or assets to sync; selecting none syncs none.

  3. 03 / Data Weaver

    Backend + database

    The backend processes uploads and selected source data. Synced marketing data is stored in the application's database under its workspace and client scope.

  4. 04 / Send boundary

    Policy at send time

    The effective client AI privacy mode is checked for each send. It determines what context can be sent, stripped, or blocked.

  5. 05 / External provider

    AI inference

    A scoped request with necessary evidence may be sent to an external AI provider. Stripping changes that request; it does not keep all processing inside Data Weaver.

  6. 06 / Data Weaver app

    Answer returned

    The answer returns to the app. Some source media or display details may be enriched locally from authorized data rather than sent for AI inference.

Optional live reads · Some authorized questions can read a provider live in addition to using synced records. Those results still follow the scoped AI send boundary when included in an AI request.

Display enrichment · Some media or labels can be added for display in the app from authorized data after an answer. This is separate from what an AI request needs to contain.

02 / The choice

Three modes.
Different context.

These are request-handling choices, not promises of anonymity or identical answer quality.

01 / Default

Standard

What may be sent

Existing context-rich requests, including identifying details and available evidence, go to the configured external AI provider without additional stripping by this mode.

When it may stop

Normal scope and safety checks still apply. The default request limit is 256 KiB and can be configured lower.

What may change

Can include names and more source detail when evidence supports them. Reports and presentations may retain richer identifying context.

02 / Minimized

Partial strip

What may be sent

Detected identifiers are replaced or removed. When necessary for a supported request, one exact database-verified campaign name or supported creative caption (currently a synced TikTok video title, up to 80 characters) may be sent; arbitrary pasted names, raw records and other identifiers are not excepted.

When it may stop

A clearly identified unknown name that cannot be safely classified, even in system-role text, an unsupported request category, or a request above 48 KiB can block a send. The configured limit may be lower.

What may change

May use a temporary label, have less source detail, or name one verified campaign/caption where allowed. Reports and presentations can be less specific or unavailable.

03 / Strictest

Full strip

What may be sent

Known client names and detected direct identifiers are stripped before AI inference. There is no direct-identifier exception, including for campaign names and captions.

When it may stop

A request with a clearly identified unknown name, even in system-role text, or one above 48 KiB, may not be sent. The configured limit may be lower.

What may change

Can discuss a trend without direct names, but some named analysis, reports or presentations may be less detailed or unavailable.

Stripping is not anonymity. Metrics, timing, and remaining context may still identify a business. These modes do not change the external provider's retention or model-training policy.

03 / In practice

One question.
Different limits.

Fictional, illustrative possibilities only—not model responses, client data, or a guarantee of how a future request will be answered. No example is sent to an AI provider on this page.

Performance summary

“How did fictional Northstar's launch perform this week?”

Standard

May use Northstar and detailed scoped evidence.

Partial strip

Northstar becomes a temporary label; may describe the trend with less identifying context.

Full strip

Direct identifiers are stripped; may describe a trend without naming the client.

Campaign question

“What changed for the fictional Spring Launch campaign?”

Standard

May name Spring Launch and use the available evidence.

Partial strip

May name one exact database-verified campaign when necessary; otherwise use a label or be unable to complete the request.

Full strip

No name exception; may discuss results without the campaign name.

Unverified name

“Review fictional Elara Voss's performance. (Name not verified in the database.)”

Standard

The pasted name may be sent as part of the question.

Partial strip

An unfamiliar name in free text may still be sent; a clear unknown name claim that cannot be safely classified is blocked before AI.

Full strip

An unfamiliar name in free text may still be sent; a clear unknown name claim that cannot be safely classified is blocked before AI.

04 / Your controls

A choice for
each client.

Data is scoped to the authorized workspace and client. Connections sync only explicitly selected accounts or assets. A workspace admin can choose a mode per client in the app; Standard is the default for existing and new clients.

For a question spanning multiple clients, the strictest applicable mode wins. The saved policy is checked again at each external AI send. Changing it affects future sends, not requests or answers already processed.

Restricted modes may reduce available context and the detail or quality of answers, reports, and presentations. They do not change how data is ingested or stored.

Admins: open Client settings to choose and preview modes
The next conversation starts here

Find the throughline.

Understand what enters the workspace, what can leave for AI inference, and where your team makes the choice.

Join the pilot

Pilot requests are reviewed before invitations are sent. Requesting access does not create an account.