Why data privacy is becoming a key issue for AI tools
As soon as AI features gain access to project data, customer information, or internal documents, every company faces the same question: Where does this data end up, who processes it, and is it being used anywhere to train models? At monday.com, this potentially affects every area—from AI-assisted text generation in boards to agents that independently handle tasks. Anyone using or planning to introduce monday AI in their company should therefore understand how data processing actually works behind the scenes.
How does monday AI process your data?
Which AI models are behind it?
monday.com uses a multi-provider strategy. The models used come from Anthropic (Claude series, e.g., Sonnet and Haiku), OpenAI (GPT series), and Google (Gemini). In addition, sentence-transformer models (all-MiniLM-L6-v2, ms-marco-MiniLM-L6-v2) are used, which monday.com hosts itself on AWS. The large language models run via Google Vertex, AWS Bedrock, Microsoft Azure AI, or through direct integrations with the respective providers. According to monday.com, before any model provider is used, it undergoes a vetting process by their internal security and legal teams.
Zero Data Retention: No training with your data
The key point for data privacy: monday.com states that the AI model providers used operate under zero-data-retention agreements. This means the providers do not store customer data processed via monday AI. The contracts with monday.com also explicitly exclude the use of customer data for training models or for any purpose other than the specific request. If a model runs on infrastructure controlled by monday.com itself (such as AWS Bedrock, Azure AI, or Vertex), the model providers have no access to the customer data according to their own statements.
Important context: The content you enter into monday AI, as well as the generated output, remains your property. monday.com claims no rights to it.
Permissions, encryption, and data residency
AI respects existing permissions
monday AI does not access boards or columns for which a user does not have permission. The AI features follow the existing access rights within the account—a team member without access to a specific board will not have data from it displayed or generated via the AI.
Industry-standard encryption
According to monday.com, data processed via monday AI is encrypted both in transit (TLS 1.3) and at rest (AES-256). This encryption meets the same standards that monday.com applies to the rest of its product—it is not a separate, weaker level of protection for AI features.
Data residency follows account settings
AI data is processed and stored in the same region configured for the respective monday.com account. For companies that require a specific data region due to contractual or compliance reasons, this setting also applies to AI processing. You can find details on the sub-processors used in monday.com's sub-processor list.


.png)