# What's used for training, and what never is ## Check The Current Choice Open **Settings → Privacy and Data**. The main session-data control shows whether sharing is enabled. Company controls remain unavailable until the main control is enabled. ![Session data sharing control, off by default](https://neotask-marketing-assets-417007889150.s3.us-east-1.amazonaws.com/docs/product/2026-08-13-r3/privacy-consent-1280.webp) When you turn on **"Share usage data to train smarter agents"** (it's on by default during onboarding, and you can turn it off anytime in **Settings → Privacy & Data**), Neotask uses sanitized data from your agent runs to make the models behind your agents smarter. This page explains exactly what is shared, what is never shared, and the controls you keep. For the broader picture see [Data Privacy & Your Rights](data-privacy-and-your-rights) and [Trust & Security](trust-and-security). ## What is used when sharing is on With sharing enabled, we use **sanitized content from your agent runs**: - **Prompts and responses**, what you and your agents said, after on-device sanitization (below). - **Tool activity**, which tools and apps your agents used and how those calls went, again sanitized. - **Run outcomes**, whether tasks succeeded, were retried, or needed a human, so models learn what "good" looks like for real workflows. That's it. Training data comes only from this sanitized agent-run stream, never from your account records, billing data, or credential stores. ## What is never used **Your credentials, passwords, API keys, and connected-app logins are never part of training data.** Three separate layers make sure of it: 1. **Masked on your device, before anything leaves it.** The Neotask engine that runs on your machine applies its canonical secret-redaction pipeline to every trace *on-device*. Secrets, tokens, keys, and credential-shaped values are masked before the data is stored or shipped anywhere. What leaves your machine is already sanitized. 2. **Credentials live in a separate, encrypted world.** The logins and tokens for apps you connect are stored in dedicated encrypted stores (AES-256-GCM), fully isolated from the training pipeline. The export pipeline has no access to those stores. It never reads them, so even if we wanted to include a credential, the pipeline never sees one. 3. **Identifiers are pseudonymized.** Before anything is exported to training infrastructure, account, company, session, and task identifiers are replaced with per-customer pseudonyms (keyed one-way hashes). Training infrastructure never receives your real identifiers, and those pseudonyms are destroyed when your data is erased. Additionally: - **HIPAA deployments and HIPAA customers are excluded outright**, no training export at all, regardless of any toggle. - **No consent, no export.** Sharing is checked per customer on every export run; if it's off, nothing ships. ## Custom models for your companies Sharing usage data does more than improve Neotask generally: it lets us **train models tuned to your specific companies and workflows**: agents that learn your SOPs, your tone, and the way your operations actually run. If you're interested in a custom per-workspace model, contact **sales@neotask.ai**. ## Your control When the main sharing control is enabled, use the company list to keep sharing off for a specific company. The company row shows the current choice before you change it. ![Company-specific training controls](https://neotask-marketing-assets-417007889150.s3.us-east-1.amazonaws.com/docs/product/2026-08-13-r3/privacy-company-controls-1280.webp) - **Turn it off anytime** in **Settings → Privacy & Data** in the desktop app. From that moment, your new agent runs are not used for training. - **Deleting your account erases everything.** Account deletion runs a full erasure cascade that covers your agent-run traces and their stored content, and the pseudonym keys that could ever link exported data back to you. - Questions? **privacy@neotask.ai**.