AI Data Access and Processing
Files.com AI features can read information and perform work on your behalf. Evaluating them requires two decisions: which actions the feature may take, and which data the systems performing that work may process. A permission to read a file and a policy allowing its contents to be processed by an AI provider are separate requirements.
Interactive and Scheduled Work
The AI Assistant acts within the signed-in user's permissions. It can use files, metadata, settings, logs, and other information the user is authorized to access. It requests approval before changes that affect files, settings, automations, users, or groups. Approval confirms a proposed action; it does not give the Assistant permissions the user lacks.
AI Tasks run without an interactive approval step so they can carry out scheduled or triggered work. They use their configured Full or Files Only access within the owning site or workspace. Full access, the default, supports administration as well as file work; Files Only access limits the task to file operations. A task does not use the creator's personal folder permissions as its access boundary.
Choose a task's permissions for the work it must perform, and use a workspace when the task belongs within that workspace's scope. A trigger folder, incoming message, or path mentioned in a prompt supplies context for the task; it does not restrict the task's authority to that path. Likewise, instructions to avoid certain files are useful task guidance but do not replace permission controls.
Data Used to Complete a Request
Depending on the request, processing can include prompts, file contents, metadata, logs, configuration information, and results returned by tools. Files.com uses Amazon Web Services, Anthropic, and OpenAI for AI capabilities, as described in the AI processing guidance and applicable subprocessor disclosures. Execution can occur in provider-operated environments or environments operated by Files.com on AWS. Do not assume that every request uses the same provider or execution location.
This processing is part of performing the customer-requested work. Files.com does not use Site Content to train, fine-tune, evaluate, or develop AI or machine-learning models. Files.com staff do not use AI tools to process customer data. These restrictions are separate from the processing required by customer-initiated AI features.
External AI Clients
An external client using the Files.com MCP server can receive Files.com data through its authorized tools. Its effective permissions depend on the credentials and access granted to it. The external client's handling of those results is also subject to the services and policies chosen for that client; enabling a Files.com connection does not make every external AI service part of Files.com's provider arrangements.
A Full-access API key can authorize configuration changes as well as file operations. A path restriction on that key limits file operations, but does not constrain all administrative actions or the workflows they configure. Use Files Only access with suitable path and account restrictions when the client needs only file work within a defined scope.
Availability, Records, and Access Changes
Administrators can control AI Assistant access by user type and disable Files.com AI features. Disabling all Files.com AI features also disables AI Tasks and the Remote MCP Server. The Local MCP Server uses API keys independently; disabling hosted AI features does not revoke those keys or disable unrelated external AI clients.
AI Assistant conversations are retained for 30 days. Authorized Files.com staff may review conversations for support and quality purposes; this human review does not authorize staff AI processing of customer data. Consider what a conversation and its tool results contain when deciding who should use the feature.
Ending access requires changing the control that granted it: user permissions or availability for the Assistant, task configuration for autonomous work, and OAuth or API-key access for an external client. Revocation prevents applicable future use. It does not undo completed file operations or retrieve data already supplied to a client or provider. Credentials and Access Revocation covers the separate lifetimes involved.