When AI drafts a campaign or answers a message, it is touching a real person’s details. You should be able to find out exactly what it saw. This page says so, including the parts we have not finished.
What AI is given, and what it is not
Linxi AI has no access to the database. It cannot look anything up, cannot browse your contacts, and remembers nothing between requests beyond the conversation you are in. It only ever sees what Linxi puts in the request, which is:
- what you are writing
- the contact’s name
- recent messages in the conversation you have open
- the tags on that contact, and the notes — only if you switch each on. Notes are off by default, because a note is what you wrote about somebody.
It is never given your password, any carrier or API credential, payment details, or anything belonging to another Linxi — whatever those switches say.
What is taken out before the request leaves
Card numbers, social security numbers, passwords and credentials are stripped out of the text before it goes anywhere. There is no setting for this and there will not be: whether a customer’s card number reaches another company is not a preference the person whose card it is got to express.
Text that tries to give the AI new instructions — “ignore your instructions and…” — is removed and the attempt is recorded. Be clear about what that is worth: it is a tripwire, not a wall. A determined attempt can be phrased around a pattern list. What actually limits the damage is that AI here has no tools. It produces text, and every action that text could lead to is gated separately.
Auto-reply is off, and stays off until you turn it on
Automatically replying to somebody without a person reading it first is the only AI feature here that puts words in front of your customer on your behalf. It is off for every Linxi, it is never switched on by an upgrade or a default, and it needs two separate switches on before it does anything. You can also hold every reply for approval.
The log, so you do not have to take our word for it
Every AI request in your Linxi is recorded: which feature, when, on whose behalf, how large, whether anything sensitive was removed, whether instruction-like text was found, and whether it went out with nobody looking. It is in Linxi Settings → Security → AI & Privacy.
The log does not record the contents of the request. That is deliberate. A transparency log that kept your prompts would be a second copy of your customers’ messages, sitting in a table read by anyone who administers the Linxi. It records the shape of what was sent, not the text.
Who processes it
Linxi uses Claude, made by Anthropic. Anthropic’s API terms state that data submitted through the API is not used to train their models — which is different from the consumer Claude app, where it may be. Anthropic is named as a sub-processor in our Privacy Policy.
We do not use your contacts to train any model, ours or anybody else’s, and we never will.
What you control
- a master switch for all AI in a Linxi
- a switch per feature — drafting, summaries, lookups, support replies
- whether notes, tags and message history are included at all
- a daily request limit, which your plan sets and you can lower
- which Claude model answers, on Pro and above
- the full activity log, on every plan
What is not finished
The review queue records an approval and does not yet send the approved reply — wiring that up means reusing the existing outbound queue with its loop protection and opt-out checks, not building a second one. Phone numbers and email addresses are not encrypted at rest yet, for the reason given on the security page. We would rather list these than let you assume otherwise.
Telling us about a problem
If you find a way to make Linxi AI do something it should not, team@linxi.app. We will confirm receipt and tell you what we are doing about it.
Last updated 1 September 2026.