guide
Intercom Promises an AI Training Opt-Out Its Own Contract Does Not Contain
The security page and the contract disagree — and at one vendor the contract is the generous one.
Intercom's security page says you can opt out of Fin fine-tuning on your data at any time, with the data deleted within 30 days.
We searched Intercom's Data Processing Addendum for the word train. Five occurrences in 1.2MB. The only substantive one reads: "Training. Intercom requires annual security and privacy training for all employees with access to Customer Data." That is staff training. There is no provision about model training, fine-tuning or machine learning on Customer Data, and no opt-out mechanism anywhere in the document.
Its Additional Product Terms do address AI training, once: Intercom contractually restricts Third Party AI Providers from using Customer Data for training or otherwise improving their services.
Third parties. So the only enforceable training commitment Intercom publishes is about OpenAI. The commitment about Intercom's own fine-tuning, and the opt-out you were offered, live in marketing copy.
This is not an accusation
Intercom is very likely honouring what it wrote. Companies routinely operate to a higher standard than their contracts oblige, and the security page reads like a description of real practice.
But a marketing page is not a promise you can enforce, and the person on your side who cares about that distinction is the one who will read the DPA rather than the security page. Two documents on one domain answering the same question differently is a procurement problem regardless of intent.
What we did not expect is how often the gap runs the other way.
Decagon's contract promises more than its website does
Decagon's public security page makes the modest claim. It says Decagon enforces zero-day retention with AI providers like OpenAI and Anthropic, so no conversation data is stored or used for training. Scope: the third party. Same shape as everyone else.
Annex 4 to Decagon's DPA, the security annex, goes further. After the same sentence about third-party providers under zero-retention agreements, it adds one more:
“Customer data is never used to train or fine-tune any AI models.”— Decagon, Annex 4 – Security, file dated 30 March 2026
Unqualified, no carve-out for Decagon's own models, and contractual. It is the strongest training commitment we have found in this category and it is not on the marketing site.
The annex beats the website on two other things as well. It offers EU-only data residency on request, which the security page does not mention. And it commits to breach notification within forty-eight hours of confirmation, with an incident response plan tested annually through tabletop exercises and severity levels P1 through P4. None of that is on the page a buyer is sent to.
One Decagon sentence runs the other way and is worth reading closely. On audit logs, the security page says logs are "accessible only to senior engineering leadership". Read literally that is Decagon's leadership, not your administrator. If you need a customer-accessible audit log for your own compliance scope, no other Decagon page contradicts this one.
Zendesk answers the question three times, three ways
Zendesk publishes more about AI data use than almost anyone, which is how you end up with three documents that do not agree.
| Document | What it says | Updated |
|---|---|---|
| AI Data Use Information | Heading: "No generative content trained on customer data". Two paragraphs later: data is sanitised "before using it to train any of our models that could be used by other customers" | 27 May 2026 |
| AI Trust at Zendesk | "These models may be trained on customer data to the extent instructed by the customer", and its table says customers control whether their data is used for model training | 7 July 2026 |
| Generative AI at Zendesk | Third-party LLMs "are not trained on Zendesk data" | 20 Aug 2026 |
The first heading is load-bearing on the word generative. Zendesk's proprietary classifier models are trained on customer data, across customers, and that document describes the sanitisation while naming no opt-out and no customer control. The second document says the customer controls it. Neither names the setting, the default, or where in Admin Center it lives.
Meanwhile a buyer who reads only the trust centre learns none of it. Cross-customer training on your tickets is not mentioned there at all.
Freshworks: silent where you look, explicit where you do not
Freshworks' security page and its trust centre say nothing about model training. Its Privacy Notice does:
“It is also in our legitimate interests to process Personal Data in this way in order to perform analytics, train our algorithms, improve, enhance, develop, support and operate the Services … develop new products and services using machine learning technologies.”— Freshworks Privacy Notice, read 21 August 2026
The legal basis is legitimate interest rather than consent, which means it is not something you agreed to so much as something you were notified of. The opt-out exists and is narrow: for products other than Freshchat, Freshworks and Freshmarketer, customers may opt out of analytics by writing to the data protection officer.
You would only ever find this by reading the privacy notice, and you would only read the privacy notice for cookie compliance.
Freshworks buries the whole subject, incidentally. Its security page runs about a thousand words on VPCs, blue-green deployment and DNS without naming SOC 2, ISO 27001 or any certification once. Every credential is one click further out.
Sierra has better evidence than its own marketing claims
Sierra's trust page says the company is committed to maintaining the highest compliance standards including SOC 2, HIPAA, GDPR, PCI, FedRAMP High, CCPA, CSA STAR, ISO 27001 and ISO 42001. Committed to maintaining is aspirational phrasing, and SOC 2 with no Type stated is precisely the ambiguity procurement teams are trained to catch.
The trust centre resolves it in Sierra's favour. It lists a SOC 2 Type II audit report from 2026, a HIPAA audit report from 2026, ISO 27001:2022, ISO 42001:2023 and PCI DSS 4.0.1. Every one of them is behind a request-access form.
So the strong claim is gated and the weak one is public, which is the wrong way round. On training, Sierra is simply silent: the word train appears zero times on its trust and reliability page, and the nearest statement is about tenancy rather than training.
Who actually answers the question you asked
There are two questions and they get conflated constantly. Does the model provider underneath train on your data, and does the vendor train its own models on your data. The first is easy to answer and mostly reassuring. The second is the one that matters.
| Vendor | Answers about its own models? | What it says |
|---|---|---|
| Genesys | Yes | Opt-in, and the MSA opts you out by default |
| Chatbase | Yes | Never, for either party — uses retrieval rather than fine-tuning |
| Intercom | Yes, on the security page only | Yes with a 30-day opt-out, absent from the contract |
| Decagon | Only in the DPA annex | Never, unqualified — stronger than the website |
| Salesforce | No | Zero retention by third-party LLMs; own models unaddressed |
| Ada | No | Sentence sits under a third-party zero-retention heading |
| Zendesk | Yes, contradictorily | Three documents, three answers |
| Freshworks | Only in the privacy notice | Trains algorithms under legitimate interest |
| Sierra, NICE, Gorgias | No | Silent |
Genesys publishes the clearest sentence anyone has written on this, and it is worth quoting in full because it names the default:
“Data is sampled and fully anonymized in the production environment before it can be used for AI model training purposes. By default, the Genesys Master Service Agreement (MSA) opts customers out of any data donation.”— Genesys Cloud AI FAQs, read 21 August 2026
Gorgias is the cleanest absence. Its security page, its Data Processing Agreement and its Supplemental Terms together contain zero occurrences of the word train and zero of artificial intelligence. Not evasion, just a question that was never anticipated.
Genesys also publishes the thing nobody else does
While reading these documents we went looking for what happens when a deployment goes wrong. Almost nothing is published anywhere. Genesys is the exception, and it publishes an automatic rollback trigger:
“Model Life Cycle Orchestration defines SLAs on certain metrics and rolls back newly deployed active models to the previous version when the number of prediction errors exceeds defined thresholds.”— Genesys Cloud AI FAQs, read 21 August 2026
Alongside it: predictive routing has a failsafe that routes to a pool of agents when the model cannot pick one in time, and predictive engagement has a pacing failsafe that limits engagements when the model targets too large an audience. No other vendor in this set publishes a rollback threshold at all.
And nobody, including Genesys, publishes a runbook for the case that actually worries support leaders: the agent told a customer something wrong and the customer acted on it. Refund liability, correction procedure, customer notification. Absent from all eleven.
How to read this without hiring a lawyer
The pattern is consistent enough to be a method. Whichever document you are reading, you are probably reading the wrong one.
- Open the DPA and the security annex, not the security page. Search both for the word train. If the only hits are about employee training, the commitment you were shown is not in the contract.
- Search the privacy notice too, separately. That is where Freshworks' answer lives, and legitimate interest is a legal basis you should notice.
- When a vendor says data is never used for training, read the heading above the sentence. At Ada and Salesforce that heading is about third-party providers, which changes what the sentence covers.
- Ask which of the vendor's own models are trained on customer data, whether it is pooled across customers, and where the setting is. Zendesk's own documents disagree on whether that setting exists.
- If the strong evidence is behind a request-access form, ask for it during the trial. Sierra's audit reports are better than its marketing and cost you one form.
The useful reframe: a SOC 2 report tells you how carefully data is handled. It says nothing about what it is used for. Those are different questions and only one of them is answered by a certification.
Every document above was fetched and searched directly on 21 August 2026, and the absences are occurrence counts on full page bodies rather than impressions. If a vendor has published a clearer position since, send it over and the record gets corrected and re-dated.
Frequently Asked
Does Intercom train Fin on my customer data?
Its security page says Fin can use anonymised customer data for model fine-tuning and that you can opt out at any time, with data deleted within 30 days. Its Data Processing Addendum contains no provision about model training at all — the only substantive occurrence of the word is about annual staff security training — and its Additional Product Terms restrict only Third Party AI Providers from training on your data. So the promise is real but it is published where it cannot be enforced.
Which AI support vendor has the strongest contractual position on training?
Decagon, and it is not on their website. Annex 4 to Decagon's DPA says plainly that customer data is never used to train or fine-tune any AI models, unqualified and covering Decagon's own models. The public security page only claims zero-day retention with third-party providers. Genesys is the strongest public position: data donation is opt-in and the master service agreement opts you out by default.
Does Zendesk train its models on my tickets?
Yes, its proprietary models, potentially across customers. One Zendesk document is headed "No generative content trained on customer data" and then describes sanitising data before using it to train models that could be used by other customers — the heading is load-bearing on the word generative. A second document says customers control whether their data is used. Neither names the setting or the default, and the trust centre does not mention it.
Why does it matter whether the promise is in the DPA or on the security page?
Because only one of them is a contract. A security page describes current practice and can change without notice; a DPA is an obligation you can hold the vendor to. Several vendors here make their strongest statements in the document with no legal force and their weakest in the one that has it.
What should I actually ask a vendor about AI training?
Four things. Do you train your own models on our conversation data, and is it isolated to our account or pooled across customers? Which model provider handles inference, and is our data excluded from their training by contract rather than by their current default? Can we opt out, and what breaks if we do? How long is data retained at every layer? A good answer names the split and the trade-off. A bad answer is a link to a SOC 2 report.
Tools Mentioned
Full reviews, pricing tiers and where each one breaks.
Fin (formerly Intercom)
SalesforceThe most polished autonomous agent on the market, attached to the pricing model buyers complain about most — and now being bought by Salesforce.
Decagon
Enterprise agent with deep configurability. Sales-led, so expect a procurement cycle rather than a signup form.
Zendesk AI Agents
The default incumbent, now consolidating the category by acquisition. Strongest if you already live in Zendesk.
Genesys Cloud CX
The other default enterprise suite, with agentic features layered onto existing routing.
You Can Also Look Into
4 of 10 AI Support Vendors Won't Say If Your Data Trains Their AI
We read ten vendors' AI terms, trust pages, DPAs and privacy policies to answer the question legal always asks. Half of them cannot be answered from published material.
Can a HIPAA-Compliant AI Agent Actually Update Your Records?
Sixty platforms here can change something in a system of record. Twenty-one of them either state they do not support HIPAA or say nothing at all. Here is the overlap between what a tool can do and what data it is allowed to touch, plus a second pattern: supporting HIPAA makes a vendor half as likely to publish a price.
20 Questions to Ask an AI Customer Service Vendor Before You Sign
The questions that determine your invoice, your exit, and whether the demo resembles what you will actually get — with what a good answer sounds like.
How to Choose an Enterprise AI Customer Service Vendor (2026 Checklist)
Four platforms will make your shortlist and none will tell you what they cost. Here is what to compare instead, including which are likely to still be independent in three years.
SOURCES
WRITTEN BY AR · UPDATED 2026-08-21
I read the fine print. Vendor pricing pages, billing definitions, terms, funding filings and acquisition notices — then I do the arithmetic nobody publishes: what a platform actually costs at your volume, what its headline metric is really counting, and who owns it now. I do not run benchmarks, and no page here pretends otherwise.