> ## Documentation Index
> Fetch the complete documentation index at: https://campus.agile-academy.com/docs/llms.txt
> Use this file to discover all available pages before exploring further.

# AI and your data

> What the AI coach can see, what leaves the EU, and how to stay anonymous.

Campus uses AI in two visible places: Henrik, the coach that learners talk to, and the invite-only [Agents beta](/docs/en/features/agents), where a user can build personal AI agents. This page explains what the AI can see, what crosses a border, and how an organization keeps identifiable information out of the AI layer.

## Never used to train AI

Content from Campus is never used to train AI models. When Henrik processes a learner's message, it does so under enterprise data-processing terms with our AI provider, Anthropic. Those terms prohibit using the content for model training.

## The transfer to the AI provider

Henrik runs on Anthropic (Claude) in the United States, so content sent to the coach crosses from the EU to the US. That transfer is governed by Standard Contractual Clauses, included in Anthropic's data-processing terms. The same applies to personal agents in the Agents beta: what you give an agent is processed by Anthropic under the same terms.

Separately, search uses OpenAI to generate embeddings of course content, a second narrow flow to a US provider. See [Subprocessors](/docs/en/security/subprocessors) for what each provider receives.

<Note>
  Platform and storage data stays in Frankfurt. Content you send to the AI features — Henrik, and your personal agents if the Agents beta is enabled for you — is the cross-border flow. See [Hosting and infrastructure](/docs/en/security/hosting).
</Note>

## Staying anonymous

Campus works fully without revealing who you are. A learner can give a sector instead of a company name, and describe a team structure in general terms instead of naming individuals. Henrik can coach learners toward this anonymous-by-default way of working, and the practice can be built into onboarding.

This reduces what is shared, but it is not a guarantee: a learner can still type a name or a client into a conversation, and an account carries identifiers such as the learner's email. Customers remain responsible for what their learners enter.

## A single, controlled assistant

Henrik is a single assistant that we operate. It is not user-configurable, and learners cannot repurpose it to do things we do not permit.

Content access is a security boundary, not a usability rule. The assistant can only work with content a learner already has access to. Locked or un-purchased material is never retrieved and never reaches the AI provider.

## Personal agents (beta)

The [Agents beta](/docs/en/features/agents) is the deliberate exception to the single-assistant model: an invite-only feature, off by default, where a user builds personal AI agents. Its boundaries are individual rather than platform-wide:

* An agent belongs to exactly one user. Its runs, files, and memory are visible to that user alone — not to trainers or administrators.
* An agent acts only with access its owner has explicitly granted. Every external tool (Notion, Slack, GitHub, …) is authorized by the owner directly with that service, and can be disconnected at any time. When a tool is connected, data flows between it and the agent under that authorization.
* Agents get no access to course content, to other learners' data, or to anything in Campus beyond their owner's own workspace.

## Conversation privacy

Coaching conversations are private to the individual learner. Trainers, cohort leaders, and customer administrators cannot read a learner's conversations with Henrik; their visibility extends to learning progress, not conversation content. See [Permissions & access](/docs/en/security/permissions).
