Should you worry about data privacy if your agency partner uses AI?
Date Published

If your agency uses AI to build faster, that is a good sign. It means they are not charging you for repetitive work a machine can handle. But it also raises a fair question: what happens to your data, your code, and your customer information along the way?
The short answer: you should not have to worry — if the agency is set up correctly. The risk is not that they use AI. It is how they use it.
Here is what to look for, and how we handle it at Onion Creative.
AI IS NOT ONE BIG BLACK BOX
Most privacy concerns come from confusing consumer AI with enterprise-grade AI infrastructure.
Consumer apps — the public web versions of ChatGPT or Claude — log conversations by default and may use them to train future models. That is a real risk, and it is why we never paste client data into consumer chat interfaces.
Developer APIs from the same providers work under different legal terms. By contract, they cannot train on API submissions. The default still stores prompts for around 30 days for abuse monitoring, but that logging can be turned off.
We configure Zero Data Retention (ZDR) on every project so prompts live only in volatile memory and are purged immediately. Same models. Different rules. Stronger privacy.
WHAT TO ASK YOUR AGENCY PARTNER
Not every project needs the same infrastructure. A good agency should be able to explain which setup fits your data, your compliance needs, and your comfort level. Here is how we think about it at Onion Creative.
Standard client work: direct APIs with ZDR
For most projects, direct model APIs — OpenAI, Anthropic — with ZDR enabled are enough. This gives us the speed of AI without adding unnecessary cost or complexity.
Higher-security clients: enterprise cloud endpoints
If your organisation prefers stronger isolation, we can route AI calls through enterprise cloud AI services:
- Azure OpenAI for GPT-4o / o3
- AWS Bedrock for Anthropic Claude
These sit inside your existing cloud agreements — SOC 2, ISO 27001, HIPAA BAA where applicable. Data stays within private VPCs, encrypted with customer-managed keys, and does not cross the public internet.
Client-owned keys for liability transfer
For enterprise clients, we can operate under API keys generated inside your own cloud tenant. The compliance boundary stays with you; we execute under your infrastructure and policies.
ASK ABOUT AI CODING TOOLS AND PROXY ROUTES
Some AI coding tools route traffic through intermediary services. That can create a middle-man concern, and it is a valid one to ask your agency about.
We use OpenCode Go as one of our development tools. Their terms are strict: they only work with partners that have Zero Data Retention in place, and their setup is designed so that prompts are not retained or used for model training.
For clients who still prefer to remove any extra hop, we configure Bring-Your-Own-Key (BYOK) so the tool routes directly through our or the client's own Bedrock or Azure endpoint. If your security team wants an even tighter setup, we can move the entire AI layer to an enterprise endpoint you control.
The goal is simple: your agency should give you the delivery speed of AI without forcing you to accept a privacy model you are not comfortable with.
HUMANS STILL OWN EVERY DECISION
AI accelerates the work. It does not own the outcome.
Every architecture choice, every commit, and every client deliverable is reviewed and approved by a senior engineer. AI handles repetition and boilerplate; humans guarantee confidentiality, quality, and accountability.
That is the Onion Creative difference: AI-augmented delivery, human-accountable execution.
CHOOSING THE RIGHT AGENCY PARTNER
You do not need to become an AI infrastructure expert to hire one. You just need an agency that can answer these questions clearly:
- Do you use consumer AI apps for client work?
- Do you enable Zero Data Retention by default?
- Can you route AI calls through our enterprise cloud or under our own API keys?
- Which AI coding tools do you use, and how do they handle our data?
If the answers are transparent and backed by real configuration — not vague reassurances — you are in good hands.
At Onion Creative, we treat this as part of the engagement, not a last-minute concern. Whether you are bound by a strict NDA, working in a regulated industry, or simply cautious with your IP, we align our AI setup to your standards.
**Your vision. Our execution. Accelerated.**