01-projects/printables-product

AI vendor data policy comparison — vault access decision

2026-09-06·status: delivered — awaiting founder decision on sandbox change
securityask-modelcodexgrokprivacy

Context

Founder pushback (2026-09-06 22:14 ET): "I'm not sure we should shackle the OpenAI and grok models like that. It should be able to read the vault. We do want these agents to have the same infrastructure you do. When we create a subagent they aren't limited."

Question asked back and answered directly: "What do you make of their privacy policies? How is it different than your own? Should I be giving any of this information to any of these companies?"

Scope: the account types actually in use, not the enterprise/API zero-data-retention tiers — Claude Max (this session), personal ChatGPT via auth_mode: chatgpt (Sol/codex CLI), personal X/xAI login (Grok CLI).

Findings

Anthropic — Claude Max + Claude Code

OpenAI — personal ChatGPT + Codex CLI (Sol)

xAI — personal Grok account + Grok CLI ("Grok Build")

Verdict delivered to founder

Grok CLI: categorical no on vault access — documented credential-exfiltration behavior independent of settings, not a policy-language concern.

Sol (Codex/ChatGPT): stay cautious — workable only with both training toggles off, and even then the 2025 court-order precedent shows retention promises aren't absolute once litigation hits.

Same-vendor trust extended to Claude subagents doesn't transfer to Sol/Grok — the reasoning isn't about intent, it's about independently observed behavior (Grok) and structural risk (both).

Open: awaiting founder's actual decision on whether/how to adjust the ask-model.sh sandbox. No sandbox change made as of this writing.