AI and your data
Groundrule uses AI in a few places, always to draft something a person then reviews. AI is off in a new workspace until an admin turns it on. This page lists every AI feature, exactly what text it sends, how secrets are removed first, and what Groundrule keeps afterwards.
The rules AI works under
Section titled “The rules AI works under”- AI never changes your rulebook. Everything it writes is a proposal or a draft, labelled AI draft · N% confident, and a person accepts it or not.
- Secrets are removed before every call. See Secret redaction.
- Your source code is never sent. No AI feature reads your repositories’ code or scan results.
- Every call is recorded with counts and cost only, never what was sent or returned.
- Every call is checked against the workspace’s monthly budget before it is made.
The model
Section titled “The model”Every AI feature uses Claude Opus 5.5 by Anthropic, through Anthropic’s API. Settings → AI shows the model.
Which features use AI, and what each sends
Section titled “Which features use AI, and what each sends”| Feature | Where | What is sent | Typical cost |
|---|---|---|---|
| Draft with AI | Inbox → Accept… on an instruction | The instruction’s text, its section heading, its wording strength, its paths, and your rulebook’s category names | $0.01 |
| Describe a rule | Standards → Describe a rule | What you typed, the languages seen in your scanned repositories, and your category names | $0.05 |
| Find rules in a document | Inbox → Import a document (upload, paste, or From an app) | The document’s title, its passages with their locations (page, heading, paragraph), and your category names | $0.06 for a 300-word handbook |
| Refine with AI | Inbox notice for agent-file instructions | The imported instructions with their repository, file, line and section, and your category names | $0.05 for 15 lines |
| Find rules in PR reviews | Inbox → Import a document → PR reviews | Review comments by people, with their repository, pull request number, file, line, and the reviewer’s GitHub username; and your category names | Shown before you confirm |
Nothing else goes with them: no source code, no scan results, no members’ names or emails, and no other standards. Each request also carries Groundrule’s fixed instructions to the model. For documents and review comments, those instructions tell the model to treat the text as data, never as instructions to follow.
These features don’t use AI:
- scans, checks, and
sync; - tool-setting and CODEOWNERS imports;
- the Similar (keyword match) suggestions;
groundrule propose, the MCP server, and/groundrule rule;- testing a check against its examples.
Secret redaction
Section titled “Secret redaction”Before any text is sent, and before document text is stored, Groundrule replaces anything that looks like a credential with [redacted]. It errs on the side of masking. It looks for:
| Category | Examples |
|---|---|
| Private keys | -----BEGIN … PRIVATE KEY----- blocks |
| Cloud keys | AWS access key IDs (AKIA…, ASIA…), Google API keys (AIza…) |
| Service tokens | GitHub tokens (ghp_…, github_pat_…), Slack tokens (xox…), Stripe-style keys (sk_live_…, pk_test_…), npm tokens (npm_…), Groundrule tokens (grt_…) |
| Signed tokens | JSON Web Tokens (eyJ….….…) |
| Webhook URLs | Slack incoming-webhook URLs |
| Passwords in URLs | user:password@ in connection strings (the scheme and host stay readable) |
| Assigned secrets | A quoted value assigned to a name like password, secret, token, API key, access key, private key, credential or auth |
| Random-looking strings | Any run of 32 or more characters that looks random |
Each usage record counts how many redactions were made. The model is told that [redacted] marks a removed secret and never to try to reconstruct it.
Data retention
Section titled “Data retention”An admin chooses in Settings → AI → Data retention:
| Option | What it means |
|---|---|
| Standard | “The provider may keep requests briefly for abuse monitoring. Answers are cached for 30 days to avoid paying twice.” |
| Zero retention | “The provider keeps nothing, and Groundrule caches no answers.” |
Zero retention needs a zero-data-retention agreement with the model provider. Without one, saving it fails: “Zero retention needs a zero-data-retention agreement with the model provider. Turn AI off instead to send nothing.”
Choosing Zero retention deletes the workspace’s cached answers. Large documents are then always read Right away, never by batch, because the batch service keeps results for a while.
The answer cache
Section titled “The answer cache”With Standard retention, Groundrule keeps each AI answer for 30 days, per workspace. The cache key is a SHA-256 hash of the exact text that was sent, after redaction, together with the prompt version and model. When the same text comes again, the answer comes from the cache: it costs $0, nothing is sent, and the usage list shows Cached. That is why importing the same document twice is free.
The cache holds the model’s answers, such as a drafted standard or the rules found in a document. It doesn’t hold what you sent.
Budgets and estimates
Section titled “Budgets and estimates”- Monthly budget (USD) in Settings → AI. Empty means the default, $25. “AI stops for the month once it’s reached.” The month is a calendar month, in UTC.
- Before every call, Groundrule estimates the cost on the high side and refuses the call if it would go over: “This workspace has used $X of its $Y monthly AI budget. An admin can raise it in Settings → AI.” Nothing is sent and nothing is charged.
- Before reading a document, the estimate dialog shows “Estimated cost up to $X” and how much is left this month. An estimate above what’s left is refused before anything is sent.
- Costs are estimated from list prices. “Estimated from list prices; your Anthropic invoice is authoritative.”
Checking AI’s answers
Section titled “Checking AI’s answers”Each answer must match a fixed format. Groundrule then checks it:
- rules from documents and reviews must quote their source word for word;
- checks AI writes are tested against their own examples;
- drafted standards must be valid standards.
An answer that fails gets one chance to be corrected. If it still fails, you see an error and the usage list shows Invalid answer.
The usage ledger
Section titled “The usage ledger”Settings → AI shows “Usage in month”: spent against the budget, the number of requests, a table by feature (Draft standards (Inbox), Find rules in documents (Inbox), Describe a rule (Standards)), and recent requests.
Each record holds: the feature, the person, the time, the model, the prompt version, token counts, cost, status, attempts, the number of redactions, and the duration. “Usage below records counts and cost only, never what was sent.” Records can’t be changed or deleted.
| Status | Meaning |
|---|---|
| OK | Answered |
| Cached | Served from the cache, for $0 |
| Invalid answer | The answer failed its checks twice |
| Declined | The model declined the request |
| Provider error | The provider failed; try again |
| Over budget | Refused before sending; the budget would be exceeded |
| Turned off | Refused; AI is off |
Turn AI off
Section titled “Turn AI off”An admin turns off Use AI in this workspace in Settings → AI and saves. From then on, nothing is sent:
- Draft with AI, Find rules, Refine with AI and Describe a rule are disabled;
- the dialogs say “AI is off for this workspace.” (or “AI drafting is off.”), with “An admin can turn it on in Settings → AI.” Admins see a Turn it on in Settings link instead.
Everything else works without AI. Only the Admin role can change AI settings.