Skip to content

Commit de87d0b

Browse files
coolguyzoneAlex Krawiecsfanahata
authored
Update AI Privacy Docs (#14998)
<!-- Use this checklist to make sure your PR is ready for merge. You may delete any sections you don't need. --> ## DESCRIBE YOUR PR Applied updates from notion, see https://sentry-docs-git-ai-privacy-updates.sentry.dev/product/ai-in-sentry/ai-privacy-and-security/ and https://sentry-docs-git-ai-privacy-updates.sentry.dev/security-legal-pii/security/service-data-usage/ ## IS YOUR CHANGE URGENT? Help us prioritize incoming PRs by letting us know when the change needs to go live. - [ ] Urgent deadline (GA date, etc.): <!-- ENTER DATE HERE --> - [ ] Other deadline: <!-- ENTER DATE HERE --> - [ ] None: Not urgent, can wait up to 1 week+ ## SLA - Teamwork makes the dream work, so please add a reviewer to your PRs. - Please give the docs team up to 1 week to review your PR unless you've added an urgent due date to it. Thanks in advance for your help! ## PRE-MERGE CHECKLIST *Make sure you've checked the following before merging your changes:* - [ ] Checked Vercel preview for correctness, including links - [ ] PR was reviewed and approved by any necessary SMEs (subject matter experts) - [ ] PR was reviewed and approved by a member of the [Sentry docs team](https://github.com/orgs/getsentry/teams/docs) ## LEGAL BOILERPLATE <!-- Sentry employees and contractors can delete or ignore this section. --> Look, I get it. The entity doing business as "Sentry" was incorporated in the State of Delaware in 2015 as Functional Software, Inc. and is gonna need some rights from me in order to utilize my contributions in this here PR. So here's the deal: I retain all rights, title and interest in and to my contributions, and by keeping this boilerplate intact I confirm that Sentry can use, modify, copy, and redistribute my contributions, under Sentry's choice of terms. ## EXTRA RESOURCES - [Sentry Docs contributor guide](https://docs.sentry.io/contributing/) --------- Co-authored-by: Alex Krawiec <[email protected]> Co-authored-by: Shannon Anahata <[email protected]>
1 parent 55b60ee commit de87d0b

File tree

2 files changed

+37
-42
lines changed

2 files changed

+37
-42
lines changed
Lines changed: 17 additions & 12 deletions
Original file line numberDiff line numberDiff line change
@@ -1,16 +1,14 @@
11
---
2-
title: AI Privacy and Security
2+
title: AI Privacy Principles
33
sidebar_order: 40
4-
description: "Learn about how AI features in Sentry handle your data securely and protect your privacy."
4+
description: "Learn about how Sentry handles your data and protects your privacy when it comes to AI."
55
---
66

7-
Generative AI features in Sentry, including Seer, are designed with your privacy and security in mind. We take the following measures to ensure that your data is handled securely:
7+
Generative AI features in Sentry, including Seer, are designed with your privacy in mind. Here are the core principles that apply to how we handle your data when it comes to our generative AI features.
88

9-
## Data Processing for Generative AI
9+
## Transparency in Data Processing
1010

11-
We use the data listed below to provide insights, analysis, and solutions for your review. Your data will not be used to train any generative AI models by default and without your express consent, and AI-generated output from your data is shown only to you, not other customers.
12-
13-
Our generative AI features are powered by large language models (LLMs) hosted by subprocessors identified on our [subprocessor list](https://sentry.io/legal/subprocessors/). Our subprocessors are only permitted to use the data as directed by us.
11+
Our generative AI features use some of the data you've configured to collect and send to your Sentry instance. This provides additional insights, analysis, and solutions for your review.
1412

1513
The data used for these features includes:
1614

@@ -22,12 +20,19 @@ The data used for these features includes:
2220
- Profiles
2321
- Relevant code from linked repositories
2422

25-
For [EU region customers](/organization/data-storage-location/), data is stored in the European Union.
23+
### No Training on Your Data
2624

27-
You can learn more about our data privacy practices [here](/security-legal-pii/security/ai-ml-policy/#use-of-identifying-data-for-generative-ai-features).
25+
By default, your data will not be used to train generative AI models unless you give permission.
26+
If you want to help improve the Sentry service, including Seer, you may opt-in to further use of your data for product improvement. Learn more about [how your data is protected and used](/security-legal-pii/security/service-data-usage/#use-of-identifying-data-for-generative-ai-features).
2827

29-
## Privacy Guarantees
28+
## Limited Access by Authorized Third Parties
3029

31-
### No Training on Your Data
30+
By default, our generative AI features are powered by third-party large language models (LLMs) that are hosted within Sentry's production infrastructure and not accessible by the underlying third-party model providers. This is enabled by the infrastructure providers set forth on our [subprocessor list](https://sentry.io/legal/subprocessors/). For any features that rely on LLMs hosted outside Sentry's production infrastructure, we will identify the applicable subprocessors.
31+
32+
In all cases, our subprocessors are only permitted to use the data as directed by Sentry and in accordance with the commitments we make to you for the Sentry service, including for [data retention](https://sentry.io/security/#data-retention) and [data storage location](/organization/data-storage-location/).
33+
34+
Further, by design, the Sentry AI-generated outputs from your data inputs are shown only to you, and never shared with other customers.
35+
36+
## Data Controls and Generative AI
3237

33-
Your data will **not** be used to train any generative AI models by default and without your express consent, and AI-generated output from your data is shown only to you, not other customers.
38+
Sentry offers an administrative level control to [disable all generative AI features](/product/ai-in-sentry/#disabling-generative-ai-features) for your organization.
Lines changed: 20 additions & 30 deletions
Original file line numberDiff line numberDiff line change
@@ -1,22 +1,22 @@
11
---
22
title: "Service Data Usage"
33
sidebar_order: 10
4-
description: "Learn about Sentry's approach to AI/ML"
4+
description: "Learn about Sentry's approach to your data"
55
---
66

7-
## Delivering a better user experience
7+
## Delivering a Better User Experience
88

9-
Sentry processes your service data, the data you configure to be collected and reported to your Sentry instance, to provide our service to you. As Sentrys service has evolved, however, prior heuristics-based approaches cannot deliver the product value weve come to expect. To train and validate models for grouping, notifications, and workflow improvements, Sentry will need access to additional [service data](https://blog.sentry.io/terms-of-service-update/) to deliver a better user experience.
9+
Sentry processes your service data, the data you configure to be collected and reported to your Sentry instance, to provide our service to you. As Sentry's service has evolved, however, prior heuristics-based approaches cannot deliver the product value we've come to expect. To train and validate models for grouping, notifications, and workflow improvements, Sentry will need access to additional service data to deliver a better user experience.
1010

11-
You can update these settings within the “Service Data Usage” section of the Legal & Compliance page in [Sentry](https://sentry.io/orgredirect/organizations/:orgslug/settings/legal/), which is located within the “Usage & Billing” Settings.
11+
You can update these settings within the “Service Data Usage” section of the [Legal & Compliance page in Sentry](https://sentry.io/orgredirect/organizations/:orgslug/settings/legal/), which is located within the “Usage & Billing” Settings.
1212

13-
### Use of non-identifying data
13+
### Use of Non-Identifying Data
1414

15-
In accordance with our Terms of Service, Sentry may use non-identifying elements of your service data for product improvement. For example, we may aggregate web vitals data to show your sites performance against a Sentry-built benchmark. The data accessed for the benchmark cannot be linked back to any particular project or customer, making it non-identifying.
15+
In accordance with our Terms of Service, Sentry may use non-identifying elements of your service data for product improvement. For example, we may aggregate web vitals data to show your site's performance against a Sentry-built benchmark. The data accessed for the benchmark cannot be linked back to any particular project or customer, making it non-identifying.
1616

17-
### Use of aggregated identifying data
17+
### Use of Aggregated Identifying Data
1818

19-
For upcoming features like priority alerts or ML-based grouping, if authorized by you, Sentry may access the following forms of service data for product improvement:
19+
With your authorization, Sentry may use certain types of service data to improve our product. These include:
2020

2121
- Error messages
2222
- Stack traces
@@ -25,36 +25,26 @@ For upcoming features like priority alerts or ML-based grouping, if authorized b
2525

2626
## Use of Identifying Data for Generative AI Features
2727

28-
For generative AI features like [Seer](/product/issues/issue-details/sentry-seer/) or issue summary, Sentry may access the following forms of service data to provide insights, analysis, and solutions for your review. Your data will not be used to train any generative AI models by default and without your express consent, and AI-generated output from your data is shown only to you, not other customers.
29-
30-
- Error messages
31-
- Stack traces
32-
- Spans and traces
33-
- Logs
34-
- DOM interactions
35-
- Profiles
36-
- Relevant code from linked repositories
37-
38-
For [EU region customers](/organization/data-storage-location/), data is stored in the European Union.
28+
For generative AI features like [Seer](/product/ai-in-sentry/seer/) or issue summary, Sentry may access your service data to provide feature functionalities to you, including generative AI output. By default, your data will not be used to train any generative AI models without your permission. AI-generated output from your data is shown only to you, not other customers. For more details about Sentry, AI, and privacy, see our [AI Privacy Principles](/product/ai-in-sentry/ai-privacy-and-security/).
3929

4030
## Data Access Summary
4131

4232
| **Access Type** | **Is the underlying data identifiable?** | **Who will this data (or any output) be shared with?** | **Will this data be used for training Sentry models?** | **Will this data be used to train 3rd party models?** |
43-
|-------------------------------------------------|------------------------------------------|--------------------------------------------------------|--------------------------------------------------------|-------------------------------------------------------|
44-
| **Non-identifying data** | No | Other Sentry customers* | Yes | No |
45-
| **Aggregated identifying data** | Yes | Approved subprocessors | Yes | No |
46-
| **Identifying data for generative AI features** | Yes | Approved subprocessors | No | No |
33+
| ----------------------------------------------- | ---------------------------------------- | ------------------------------------------------------ | ------------------------------------------------------ | ----------------------------------------------------- |
34+
| **Non-identifying data** | No | Other Sentry customers\* | Yes | No |
35+
| **Aggregated identifying data** | Yes | Approved subprocessors | No (unless authorized) | No |
36+
| **Identifying data for generative AI features** | Yes | Approved subprocessors | No (unless authorized) | No |
37+
38+
\*_In these cases we don't share the underlying data, only aggregations or output generated from the data_
4739

48-
**In these cases we don't share the underlying data, only aggregations or output generated from the data.*
40+
## Our Data Handling
4941

50-
## Data Handling
42+
Where we are authorized to use service data for product improvement:
5143

52-
In addition to the consent mechanisms mentioned above:
44+
1. We'll continue to encourage all customers to use our [various data scrubbing tools](/security-legal-pii/scrubbing/) so that service data is sanitized before we receive it.
5345

54-
1. We'll continue to encourage all customers to use our [various data scrubbing tools](/product/data-management-settings/scrubbing/) so that service data is sanitized before we receive it.
5546
2. We'll apply the same deletion and retention rules to our training data as we do to the underlying service data. This means that if you delete service data, it will also be removed from our machine learning models automatically.
47+
5648
3. We'll scrub data for PII before it goes into any training set.
57-
4. We'll ensure that the only service data presented in the output of any generative AI feature belongs to the customer using the feature.
58-
5. We'll only use generative AI models built in-house, deployed in our production cloud, or provided by our existing trusted [third-party subprocessors](https://sentry.io/legal/subprocessors/) who have made contractual commitments that are consistent with the above.
5949

60-
We're confident that with these controls in place, we'll be able to use service data to improve and provide our products through AI while at the same time protecting that data.
50+
We're confident that with these controls in place, we'll be able to use service data to improve and provide our products while at the same time protecting that data.

0 commit comments

Comments
 (0)