Data privacy
AI and GDPR: using Claude and ChatGPT with your data.
You want Claude or ChatGPT to know your projects, clients and decisions – and you wonder what the GDPR has to say about it. This guide walks you through it calmly: where your data goes, what to check, and what’s in your own hands.
Reading time: 9 minutesUpdated:
01
Two places your data goes
When an AI agent works with your notes, there are almost always two providers involved. The first stores your notes – with WhyVault, a data centre in Frankfurt. The second runs the agent, such as Anthropic for Claude or OpenAI for ChatGPT. It processes everything that comes up in the conversation: your question, the answer, and any notes the agent pulls in to answer it.
Most talk about “AI and data privacy” looks at only one of the two. A vault in Frankfurt doesn’t help much if you’ve never looked at the AI provider. And the most careful AI contract is worth little if your notes live somewhere you can’t account for.
The good news: for both places there’s a short list of questions you answer once. After that, you can just work.
02
What the GDPR asks for, in plain words
The GDPR applies as soon as you process personal data for work: names, email addresses, notes about clients or applicants. Four ideas cover most of it.
A good reason
Every use of personal data needs a legal basis, such as a contract with the client or a legitimate interest. “The AI should know” isn’t one – “I need it to run the project” often is.
Only what you need
Data minimisation: write down what you need for the work, not everything you know. A decision rarely needs someone’s private phone number.
Contracts with providers
Anyone who processes data on your behalf needs a DPA (Art. 28 GDPR). That goes for your notes service just as much as for the AI provider.
Data outside the EU
If data goes to a third country such as the US, there has to be a basis for it – for example an adequacy decision or the EU Standard Contractual Clauses.
03
What the AI provider sees when your agent reads
A perfectly ordinary moment. You ask, the agent searches the vault and reads a note:
You: Where are we with the proposal for Berger Logistics?
- Tool: read_note · “Berger Logistics – proposal”
Claude: According to the note, you sent a proposal for three workshops on 18 September. Your contact is Ms Kaya (purchasing). Still open: whether the November date works.
You: Please note that she’s confirmed the date.
- Tool: append_to_note · “Log”
Claude: Done. I’ve added under “Log”: November date confirmed by Ms Kaya.
04
What doesn’t belong in your vault
The simplest privacy measure is the note you don’t write.
The GDPR protects some data especially strictly: health, religion, political opinions, trade union membership, sexual orientation and a few more (Art. 9 GDPR). That kind of information about other people – clients, employees, applicants – has no place in a notebook that AI agents read. Not even “just for now”.
For everything else, one habit helps: write about decisions, not about people. “We’re starting with three workshops because the budget only arrives in Q1” is valuable. How your contact is doing privately isn’t part of it. Where names aren’t needed, roles will do: “the buyer”, “client B”.
Rooms and folders help you keep order, but they’re not walls: a connected agent can read the whole vault. So whatever an agent shouldn’t see simply doesn’t go in.
05
Check your AI provider
AI providers change their terms regularly. Rather than give you a snapshot that’s out of date tomorrow, here’s where to look for yourself.
- 1
Pick the right plan
Providers often distinguish between personal and business plans, with different rules for your data. For work with client data, look at the business or team offerings and read what they commit to.
- 2
Check the training setting
Open the privacy settings of your account and see whether your conversations may be used to train models. Set it the way you want it, and check again whenever the terms change.
- 3
Put the provider’s DPA in place
Look for the Data Processing Addendum (DPA) in the provider’s terms and make sure it covers your plan. It’s often part of the business terms.
- 4
Find out where data is processed
Check where the provider processes and stores data, and on what basis data goes to a third country. Some providers offer EU data residency, often only on certain plans.
- 5
Write it down
Add your notes service and your AI provider to your record of processing activities, and name them in your privacy policy where needed. A short note in your vault on what you checked and when makes a good reminder.
---type: rule---# Privacy## When writing- No health data and no private details about other people.- Clients and contacts by role and company, never private numbers.- Applications and HR topics only as a decision, no reasoning about the person.## When reading- Only read the notes you need for the question.- Don’t quote personal data when a summary will do.Last checked: [[2026-09-29 AI provider checked]]
06
Your rules, read by every agent
Every connected agent gets the rules from 9_System when it starts. That’s where you can write down how to handle personal data:
A rule in your vault doesn’t replace a setting with the provider – but it makes sure every connected agent knows the same limits.
The link to a dated note records when you last looked at the plan, training setting and DPA.
Agents usually follow rules like these, but not always. So the first rule still stands: what isn’t written down can’t be read.
07
In the chat’s memory or in your own vault?
Claude and ChatGPT can remember things on their own. That’s convenient – but it’s a different place with different rules.
| – | Memory inside the AI assistant | Your own vault with WhyVault |
|---|---|---|
| Where the knowledge lives | With the AI provider, under their terms | In Frankfurt, with a DPA for businesses |
| What exactly is stored | More or less visible, depending on the provider | Plain Markdown notes you can read any time |
| Several agents | Each assistant has its own memory | Claude, ChatGPT, Cursor and co. share the same notes |
| Who changed what | Usually hard to trace | Every change in the history with the agent’s name, and undoable |
| Taking it with you, deleting | Depends on the provider’s features | Export as a zip any time, deleting is up to you |
- Where the knowledge lives
- Memory inside the AI assistantWith the AI provider, under their terms
- Your own vault with WhyVaultIn Frankfurt, with a DPA for businesses
- What exactly is stored
- Memory inside the AI assistantMore or less visible, depending on the provider
- Your own vault with WhyVaultPlain Markdown notes you can read any time
- Several agents
- Memory inside the AI assistantEach assistant has its own memory
- Your own vault with WhyVaultClaude, ChatGPT, Cursor and co. share the same notes
- Who changed what
- Memory inside the AI assistantUsually hard to trace
- Your own vault with WhyVaultEvery change in the history with the agent’s name, and undoable
- Taking it with you, deleting
- Memory inside the AI assistantDepends on the provider’s features
- Your own vault with WhyVaultExport as a zip any time, deleting is up to you
Worth saying: even with your own vault, the AI provider processes whatever the agent reads during the conversation. The vault changes where your knowledge lives for good – not the need to check the provider.
08
What WhyVault takes care of
For the storage side, WhyVault handles a lot for you. The details are in the privacy policy and under History, export and privacy.
Hosted in Frankfurt
Database, sign-in and files live with Supabase in Frankfurt; website and server functions run on Vercel in the Frankfurt region. Operated by Ohrlaf GmbH, Germany.
DPA included
If you use WhyVault as a business, the DPA becomes part of the contract – no signature needed, with a list of all subprocessors.
No training, no ads
WhyVault uses your notes only to run the service: not for advertising, not to train AI models, never sold.
Permissions per connection
With an access key (for Claude Code or Cursor, say), an agent can be set to read only. You can revoke any connection at any time.
History, not a black box
Every change is a version with the agent’s name on it. Agents can’t delete anything via MCP, and if one writes unusually much, it gets stopped and you get an email.
Take everything with you
Plain Markdown, exportable as a zip any time – even without a subscription. Your knowledge isn’t tied to any provider, including us.
Privacy with AI doesn’t mean sharing nothing. It means knowing who sees what.
09
Checklist before you connect an agent
Go through it once, then work in peace:
- You know where your notes are stored and – as a business – have a DPA with your notes service. For WhyVault: DPA.
- You use an AI plan that fits work use, and you’ve found its DPA.
- The training setting in your AI account is the way you want it.
- You know where the AI provider processes data and on what basis it goes to a third country.
- Your vault holds no health data and no sensitive details about other people.
- Tools that only need to look things up get an access key set to read only.
- A rule note in
9_Systemtells every agent how to handle personal data. - Your notes service and AI provider are listed in your record of processing activities.
?
Frequently asked questions
Is this legal advice?
No. This guide explains the core ideas of the GDPR and shows what you can check. For your specific case – say, with health data or client files under professional secrecy – ask your data protection officer or a lawyer.
Is Claude or ChatGPT GDPR compliant?
It depends less on the tool than on how you use it: which plan, which settings, which contract, which data. Check the provider’s plan, training setting, DPA and processing location – and only put in what’s needed.
Do I need a DPA with WhyVault?
If you use WhyVault for work with personal data, yes. It becomes part of the contract automatically as soon as you use WhyVault as a business – no signature required. You’ll find the text under data processing agreement.
Does WhyVault train AI models on my notes?
No. WhyVault doesn’t run AI models over your content and doesn’t use it for training. What a connected agent reads, though, is processed by its provider under their own terms – so it’s worth checking your settings there.
Can I give an agent read-only access?
Yes, for connections with an access key, such as Claude Code or Cursor. Connections via sign-in, like Claude or ChatGPT in the browser, can read and write – but no agent can delete, and you can revoke any connection at any time. Connecting agents
Can I put client data in my vault?
Business contact details and project notes you need for the work are usually fine, as long as the legal basis and contracts are in place. Special-category data under Art. 9 GDPR and private details about other people don’t belong in it.
Keep reading
All guidesWhat is MCP?
The Model Context Protocol in plain English, and how to connect an MCP server to Claude or ChatGPT.
ReadRun your company with AI
How I run several ventures from one vault that Claude, Claude Code and ChatGPT all read.
ReadDecision log
A template for decisions you’ll still understand six months from now – with a filled-in example to copy.
Read
Your knowledge, in a place you know.
Hosted in Frankfurt, with a DPA, history and export. Connect Claude or ChatGPT in five minutes – free up to 20 notes.