Is my data safe with AI? Four checks before you share it
No AI tool can promise perfect security. Check who processes your inputs, who on your team sees them, who can open outputs, and how keys are kept.

Your data is only as safe as the specific AI tool's handling of it, and no tool can promise perfect security. Break "safe" into four checks: who at the company and its model providers processes your inputs, who in your own team can see them, who can open the files it generates, and how your credentials are protected.
This post answers the four checks for Sume from its Privacy Policy (last updated September 13, 2026), its Terms of Service, the Authentication docs and the Embed a Format cookbook, all read on 2026-09-29, plus current code where noted. It is not a security audit or legal advice.
Who at the AI company can process my data?
The company and the providers it uses. Sume's Privacy Policy says agent and generation workflows may require Sume or its providers to process prompts, scripts, product images, uploaded files, voice input, media URLs and generated outputs. It lists AI model providers for image, video, avatar, speech and language generation among its service providers, and says they may process information only as needed to provide services to Sume, comply with legal obligations, or as otherwise permitted by law.
On protection, the policy names "access controls and encryption in transit" among its safeguards and adds: "No method of transmission or storage is perfectly secure." Neither the policy nor the Terms mentions encryption at rest or a security certification, so ask for those in writing if your review needs them.
Who on my team can see my data?
In a shared workspace, your teammates, by role. The Privacy Policy says threads, Formats, brands, assets, API keys, jobs, usage records and billing activity in an organization are visible to other members according to their role. In current code there are three roles; the rows below are the ones that decide who sees your data. AI video generator for business covers the rest of each role.
| Action | Admin | Creator | Member |
|---|---|---|---|
| Read the shared libraries, including assets | Yes | Yes | Yes |
| Message and run workspace chats | Yes | Yes | No (view only) |
| Read every member's usage event rows | Yes | Own only | Own only |
| See per-member spend totals | Yes | Yes | Yes |
| Invite, remove and re-role members | Yes | No | No |
Are AI-generated files private?
Not always. Ask whether output links need a sign-in. On Sume, the Embed a Format cookbook says a Format run's artifact URLs are durable media.sume.com URLs, and warns: "A durable URL is a public URL. Anyone who has it can fetch it." If customer A must never see customer B's output, it says to proxy the bytes through your own authenticated route or copy them into your own storage.
Do AI-generated video URLs expire? covers which Sume URLs are durable and which are signed.
How do I keep API keys safe?
Keys need the same care as the data they unlock. Sume's Terms say to use API keys only from server-side or otherwise secure environments, and never to share, publish, sell or expose them. The Authentication docs spell out the rules:
- Keep keys on trusted servers, CI secret stores, or local developer machines.
- Never put them in frontend JavaScript, mobile apps, support tickets, or screenshots.
- Rotate from the dashboard if a key is exposed; Exposed API key? Revoke it walks through it.
- Give agents read-only commands first, and require explicit confirmation before write or paid generation commands.
What should I not send to an AI tool?
Anything you don't need to send. Sume's Privacy Policy asks you not to submit sensitive personal information unless it is necessary for your authorized use, and says inputs and outputs may be retained as needed to provide the Services. Under the Terms you also represent that you have the rights and permissions for what you submit, including permission to use any person's likeness or voice.
What Sume keeps and for how long is covered in Zero data retention for AI video APIs.
Sources
Related posts
More in Developers
- Is my data used to train AI? Where the answer is written
It depends on the tool: the training answer sits in its terms' content license and its privacy policy's use section. What to search for, and what Sume's say.
- Java HttpClient timeout: no default, so set two of them
Java's HttpClient has no request timeout unless you set one: connectTimeout on the client, timeout on each request, and HttpTimeoutException.
- JSON to video API: render an MP4 from a timeline document
A JSON to video API renders one MP4 from a document that says which clips play when, over which audio. How Sume's Timeline 1.0 does it, and costs.
- Kling API rate limit: concurrency by package and error 1303
Kling's API limits concurrent tasks by resource package, not requests per second. Over the cap, a create fails with HTTP 429, code 1303.
Written by Sume