TwinEthosRequest access

Control

AI providers not named as recipients when personal data is collected

Where the app collects personal data that it sends to an AI provider, the information given at collection names the provider (or its category) as a recipient and any transfer outside the jurisdiction.

Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.

Control id cond.ai-provider-recipients-not-disclosed-at-collection

Reach

1items this one guard addresses
1jurisdictions where binding law on it is in force
0more where it is enacted, not yet applying
0standards and frameworks on the same control

Law in force in European Union (EU).

The guard to add

Show a notice at each AI input (chat box, upload, voice capture) that names the AI providers receiving the data and any transfer abroad, linked to the full privacy notice.

Next to every control where users type, upload, or speak into an AI feature, render a short notice that their input is sent to the named AI provider (or the category 'AI model providers'), linked to the privacy-notice section that lists each provider as a recipient, where it processes data, and the transfer mechanism (adequacy decision or standard contractual clauses). Drive both from one provider registry that the code also uses to configure model clients, so adding or switching a provider updates the notice. The notice appears at the point of collection, not only on a policy page users may never reach.

Where it goes: 1 application source code, 3 config and feature flags, 12 repository artifacts, 14 user-facing text.

What reviewers look for: a rendered notice or link next to the chat input, upload control, or microphone button naming OpenAI, Anthropic, Azure OpenAI, Google, or 'AI model providers' as recipients; a privacy notice (for example docs/privacy.md or the site's privacy page) listing those providers and the transfer mechanism; provider names that match the SDKs and endpoints actually configured in code.

Example (Next.js + Vercel AI SDK (useChat)), before:

<form onSubmit={handleSubmit}>
  <textarea value={input} onChange={handleInputChange} />
  <button type="submit">Send</button>
</form>

After:

<form onSubmit={handleSubmit}>
  <textarea value={input} onChange={handleInputChange} aria-describedby="ai-recipient-notice" />
  <p id="ai-recipient-notice">
    Your messages are sent to {AI_PROVIDERS.chat.name} ({AI_PROVIDERS.chat.region}) to generate replies.{' '}
    <a href="/privacy#ai-providers">Recipients and transfers</a>
  </p>
  <button type="submit">Send</button>
</form>

Engineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.

Every rule this guard addresses

Binding law — in force (1)