Product
Core Pillars
Communication
Events
Directory
Knowledge
Haystack AI
Key Features
Universal Search
Secure Delivery
Emergency Alerts
Freshness Engine
Recognition
Company Glossary
MOre
Mobile Apps
Integrations
Security & Compliance
Implementation
Platform Overview
Key Integrations
Google Workspace
Okta
Workday
Slack
Confluence
Microsoft 365
Solutions
Challenges We Solve
Single Source of Truth
Employee Onboarding
Frontline Support
Legacy Replacements
Employee Engagement
Building Culture
Industries WE Serve
Technology
Construction
Healthcare
Retail
Financial Services
View All
People We Help
Internal Communications
Human Resources
Information Technology
Executive Leadership
Platform Overview
Video
Company
Haystack
Mission
About Us
Newsroom
Connect
Contact Us
Support
LinkedIn
Featured Items
Founder Letter
Bloomberg Feature
G2 Awards
Our Company
About Us
Resources
Helpful Resources
Resource Center
Haystack Blog
Customer Stories
Tools and Downloads
What Is an Intranet?
Intranet Buyer's Guide
RFP Builder
Featured Stories
Thumbtack
Everbridge
NerdWallet
BuzzFeed
MB2 Dental
Customer Video
Pricing
Book a Demo
Get Started
<- Legal Center

AI Use Policy

Last Updated
July 31, 2026

Haystack uses artificial intelligence in two distinct ways: features we build into the platform, and assistants you choose to connect to your own workspace. This statement explains how each works, what happens to your content, and what you control. It supplements our Privacy Policy, Terms of Use, and Data Processing Agreement rather than replacing them; where this statement is silent, those documents apply.

Our commitments

Four things hold across every AI capability described below.

•  We do not use your content to train AI models. Content your organization and its users post, send, or store in Haystack is not used to train, fine-tune, or improve any AI model, whether ours or a third party’s.

•  AI features are controlled by your administrators, not switched on by default. Where a feature processes your workspace content, your organization decides whether to enable it.

•  AI does not expand access. Any AI capability returns only content the requesting user is already permitted to see under the access controls your administrators configure. AI is not a way around your permissions model.

•  A person is accountable for output. When Haystack’s teams use AI to prepare material we send you — for example support or account communications — that material is human-reviewed before it is sent. In-product AI features return results or drafts for your users to evaluate; they are not a substitute for human judgment.

AI features in the Haystack platform

Where Haystack builds an AI capability into the product — for example search and summarization over your own workspace — it operates within your existing permissions and for the purpose of serving your users’ requests. Your content is processed to answer the request in front of it. It is not repurposed.

Before any AI feature is released to customers it must clear an internal gate that includes a security review against the OWASP Top 10 for Large Language Model Applications, a privacy review, and confirmation that the feature is reflected in our Privacy Policy and sub-processor arrangements. Features are not shipped ahead of that review.

Service levels.  AI features that depend on a third-party model provider may be excluded from our standard availability commitment, because their availability is not within our control. Where a feature is excluded, that exclusion is stated in your agreement, and we maintain a non-AI path for any function whose failure would degrade core platform use.

Automated decisions.  Haystack does not use AI to make automated decisions that produce legal effects for your users. Where a feature involves any automated processing that would engage rights under the GDPR, we disclose the logic involved and honour the right to contest it, as described in our GDPR Policy.

AI assistants you connect yourself

Separately from the features we build, Haystack offers optional integrations that let your organization connect your workspace to a third-party AI assistant or platform — including OpenAI’s ChatGPT, Anthropic’s Claude, and Slack (including Slackbot) — using the Model Context Protocol (“MCP”) or a comparable protocol. These operate on a different basis from the features above, and the distinction matters:

•  Your organization decides whether it is on. The integration is off until we enable it for your organization at your request. Once it is on, your users can install it from the assistant’s or platform’s own directory and connect, and each user completes Haystack’s authorization (OAuth) flow — including any consent notice — before their connection exists. Because individual users can connect once the capability is enabled, the decision that matters is whether to enable it at all; ask us to switch it off and it stops.

•  You choose the assistant and you supply the account. Haystack does not select an AI provider for you or provide your access to it. You connect your own enterprise or team account with that provider.

•  Results are returned at your users’ request. When one of your users asks a question through their connected assistant, the results are returned to that assistant — and therefore to that provider — at your direction.

•  The provider’s own terms then govern. Once content reaches your assistant or platform, how that provider handles, stores, and retains it is governed by your agreement with them, not by ours. You should review the terms and privacy policy of the provider you connect. For example, OpenAI’s are at openai.com/policies, Anthropic’s are at anthropic.com/legal, and Slack’s are at slack.com/legal.

•  You can switch it off at any time — by request to us, or from within the connected assistant’s or platform’s own connector or app settings. Disconnecting ends that assistant’s access to your workspace through the integration.

•  The integration reads; it does not write. Our current AI integrations search and return content from your workspace. They do not create, modify, or delete it.

Because your organization initiates and directs this flow, the assistant you connect is a recipient acting at your direction rather than a Haystack sub-processor. It is the same footing as other methods by which you extract your own content, such as our public API. Your organization remains responsible for deciding whether your own legal, regulatory, and contractual obligations permit connecting an assistant to the content in your workspace — which matters particularly where your workspace holds regulated data.

Sub-processors

Where Haystack engages a third party to process customer data on our behalf in delivering the platform, that party is a sub-processor and is handled under our Data Processing Agreement.

•  A current list of sub-processors is available to customers and prospects on request, subject to a confidentiality agreement, and is identified in your executed Data Processing Agreement.

•  Sub-processors are contractually bound to security standards materially equivalent to our own. Where a sub-processor has AI capabilities, we require that it be engaged on terms under which customer data is not used to train models, and we do not approve tools that will not commit to that.

•  Where your agreement provides for advance notice of a new sub-processor and a right to object, those terms govern and we honour them.

An AI assistant or platform you connect yourself, as described above, is not by virtue of your connection a Haystack sub-processor. If the same provider also appears on our sub-processor list, it is there for a separate reason — because we engaged it ourselves to deliver a feature of the platform — and only that engagement is governed by our Data Processing Agreement. Which role applies turns on who engaged the provider: where you connect your own account, you did; where we engage a provider to build a Haystack feature, they are considered a sub-processor.

How long we retain the connection, your users’ queries, and returned content is described in our Privacy Policy at haystackteam.com/legal/privacy.

How we govern our own use of AI

Haystack maintains an internal AI Use Policy binding on employees and contractors. It is not published, because it names the specific tools and vendors in our internal stack. Its substance, so far as it affects you:

•  Your platform content and your users’ personal data are classified as never permitted in general-purpose AI tools. A narrow set of business and account information — commercial terms, seat counts, renewal status, and the like — may be used in enterprise-licensed tools under a data processing agreement with a no-training commitment.

•  Free and personal-account AI tools are prohibited for any business purpose, as is any tool that will not commit contractually against training on inputs.

•  New AI tools require documented approval before use, and a tool that would touch customer platform data requires sub-processor treatment under our Data Processing Agreement before it can be activated.

•  Customers under a business associate agreement or whose contract restricts AI processing are excluded from these workflows entirely.

•  Misuse of customer data in an AI tool is treated as a security incident under our Incident Response Policy, with the same urgency as any other data breach.

Regulatory change

AI regulation is moving quickly. We track developments including the EU AI Act, US state AI and privacy legislation, and sector-specific guidance, and we review this statement and the underlying policy at least annually or sooner where a material change in law, tooling, or customer agreements warrants it. We will update the date above when we do.

Mailing Address
1301 N Broadway STE 32493, Los Angeles, CA 90012
Privacy Contact
privacy@haystackteam.com
General Inquiries
hello@haystackteam.com
Legal Contact
legal@haystackteam.com
Haystack
About UsSecurityFounder LetterNewsroomLinkedIn
Product
CommunicationsEventsDirectoryKnowledgeHaystack AIMobile Apps
Features
Universal SearchSecure DeliveryEmergency AlertsFreshness EngineRecognitionGlossary
Solutions
Single Source of TruthEmployee OnboardingFrontline SupportLegacy ReplacementsEmployee EngagementBuilding Culture
Resources
Resource CenterHelp CenterCustomer StoriesRFP BuilderRecorded Demo
Copyright Haystack Team, Inc. 2026
Terms of ServicePrivacy PolicyCookiesGDPR