Skip to main content

AI Reports: What happens to your data

A detailed breakdown of what's sent to Anthropic when you generate an AI Report, how it's processed and stored, and what happens when a report is deleted.

Note: This information was compiled from details provided by Anthropic as of 09.09.2026. We will continue to monitor for any changes and update this help note should there be significant developments.


This article sets out, in detail, what happens to your data when someone generates an AI Report, what's sent to Anthropic, how and where it's processed, and what does and doesn't happen when a report or its underlying session is deleted. It's intended for IT, security and privacy teams assessing the feature before enabling it.


What gets sent to Anthropic

Three things are sent when a report is generated:

  • The request itself, the report name, description, your instructions, the date range and the output format.

  • The project records the assistant retrieves in order to write it, stakeholders, interactions, complaints, commitments, tasks, form responses, outgoing communications and project properties, including any free-text notes and personal details they contain.

  • The finished Word and PDF file, which is produced on Anthropic's side and then copied back to us.

Anthropic cannot use this connection to reach other projects or information outside of what that specific report is permitted to access.


Who processes it

Anthropic PBC, under their commercial terms for business customers, not the terms that apply to personal Claude accounts. The model is Claude Sonnet 5, running on Anthropic's Managed Agents platform.

  • Each of our regions has its own isolated Anthropic workspace.

  • The assistant's sandbox can only reach one destination, our own data endpoint, and cannot install software.

  • Its credential is a 10-minute token, scoped to a single report run.


Access boundaries

A report can only ever contain what the person requesting it could already open in Simply Stakeholders. Project scope, confidentiality levels, organisation and date window are all enforced by our server, not by the AI. Asking the assistant for more doesn't widen what it gets back.


Training

Anthropic's published commitment is that customer data is never used for model training without express permission. We haven't given that permission, and won't. Nothing from your data becomes part of a Claude model, and it can't appear in another organisation's report.


Where it's stored

Anthropic currently only offers US-based storage for this platform, so stored data sits in the United States regardless of whether you're on our EU, UK, Australian or Canadian instance. Our per-region workspaces separate one region's data from another's, they don't move it out of the US.

Model processing is also not restricted to a single territory by default. Anthropic offers a US-only processing option and we can enable it on request, but it isn't on by default and doesn't follow automatically from your hosting region.

Because this involves stakeholder data leaving the EU, EU-based clients must give explicit consent to the US data transfer before AI Reports is enabled for their account. Your Customer Success Account Manager can talk you through this and arrange it.


How long it's kept

On our side, generated report files (Word, PDF and preview images) are kept in our storage indefinitely, until the report is deleted or a file is manually removed.

On Anthropic's side, two different things are handled differently:

  • The checkpointed working files from the run, including the copies of the generated Word and PDF made while the report was being produced, fall under Anthropic's own 30-day platform limit for sandbox state.

  • The session history, every prompt, tool call, tool result and AI response, i.e. the actual data sent to generate the report, is now deleted from Anthropic immediately after the report finishes generating.

Separately, and for all Anthropic customers: if their automated safety systems flag a session, or a legal obligation applies, they may retain inputs and outputs for up to two years. That can't be configured away, by us or by you.


Deleting a report

Deleting a report in Simply Stakeholders removes it from the list and withdraws access immediately. A scheduled nightly cleanup then deletes the report's Word, PDF and preview files from our storage, and confirms that Anthropic's copies of those same files have also been removed.

Because the underlying AI session is already deleted from Anthropic immediately after the report was generated (see How long it's kept above), there's no separate session left to close out at deletion time, deleting a report only cleans up the generated files, session data is already gone by then.


If you're doing a risk assessment: real stakeholder data leaves our environment to generate a report, and is stored and processed in the United States. It is not used to train Anthropic's models. As of September 2026, the underlying AI session, which contains the data sent to create the report, is deleted from Anthropic immediately after the report is generated, not retained indefinitely. The generated files themselves are cleaned up when you delete a report. Existing Simply Stakeholders permissions still apply, a report can never contain more than the requester could already see. The feature is optional and can be left switched off for your organisation. EU clients need to give explicit consent before enabling it, due to the US data transfer. If you have data residency obligations, a restriction on data leaving your jurisdiction, or a defined retention limit for stakeholder records, raise it with your Customer Success Account Manager before enabling it.


For more help

Contact our Customer Success team via email [email protected].

Did this answer your question?