AI Transparency
Which PlatoForms features use AI, what data each one sends, and how to turn them off.
At PlatoForms Pty Ltd, we are committed to being transparent about how we use artificial intelligence (AI) within our platform. This page explains which features involve AI, what data each feature sends, whether it is on by default, and how to turn it off.
AI services we use
PlatoForms uses a combination of third-party hosted large language models, including models from Anthropic’s Claude series, OpenAI’s GPT series, and open models such as the Gemma series hosted on Amazon Web Services (AWS) Bedrock.
We may change or add model providers over time as capabilities and pricing evolve. The authoritative, current list of the third parties that process customer data is maintained in our subprocessor list. Customers with a Data Processing Agreement (DPA) in place receive advance written notice of new subprocessors and may object, as set out in that agreement. To request the current list, contact support@platoforms.com.
Which features use AI
| Feature | What it sends | Default state |
|---|---|---|
| PDF recognition | The content of the PDF document you upload | Runs only when you use the feature |
| Form generation | The document or description you provide | Runs only when you use the feature |
| Form translation | The form content you ask us to translate | Runs only when you use the feature |
| AI assistant access (MCP) | Account identity, form names and field definitions, submission data, generated-document metadata, and time-limited file links — only for the action you request | On by default; off by default for HIPAA-enabled teams |
| Voice form filling (PlatoForms VF) | The voice input you provide while filling a form, and the form fields being completed | On by default; off by default for HIPAA-enabled teams |
PDF recognition, form generation, and form translation are actions you start yourself. If you do not use them, no form or document content is sent to an AI provider for those purposes.
AI assistant access (MCP) lets an assistant you connect — such as ChatGPT, Claude, Cursor, or OpenAI Codex — read and act on your PlatoForms data at your direction. Tool inputs and results are sent to the AI provider you chose, which processes them under its own terms and privacy policy. A team owner controls this for the whole team in Account → API.
Voice form filling is provided through the PlatoForms VF app for iOS and Android. Voice input is processed to convert speech into form field values.
Data handling in AI processing
- AI processing happens only for the feature you are using, and only with the data that feature needs.
- We do not use your data to train third-party AI models. Our AI providers do not use customer inputs or outputs submitted through their APIs to train their models.
- All data transmitted to AI providers is encrypted in transit and processed in accordance with each provider’s security standards.
- Data sent for processing is not retained by the AI service beyond what is necessary to complete the request.
- For AI assistant access (MCP), the MCP service is a stateless relay to the PlatoForms API. It does not keep a separate copy of form or submission content after a request completes, and it does not receive your AI chat history.
For AI assistant access, the AI provider you connect receives the tool inputs and results and applies its own retention rules and account settings. After data is delivered to that provider, its handling is governed by your agreement and settings with them.
Your control
- PDF recognition, form generation, translation — these run only when you choose to use them.
- AI assistant access (MCP) — a team owner can enable or disable it for the whole team in Account → API, and you can revoke the OAuth connection from the connected AI service at any time.
- Voice form filling — a team owner can enable or disable it for the team; you can also simply not use voice input.
HIPAA-enabled teams
For teams with HIPAA compliance enabled, AI assistant access (MCP) and voice form filling are off by default. A team owner may choose to turn them on.
Before enabling either feature on a HIPAA-enabled team, note that data sent to a third-party AI provider through these features is not covered by the PlatoForms Business Associate Agreement (BAA). It is your responsibility as the covered entity to determine whether the disclosure is permissible under the HIPAA Rules and to hold any agreement you require directly with that AI provider.
See HIPAA compliance for how HIPAA mode works.
Questions
Data handled through these features is subject to our Privacy Policy and the security practices described in our Trust Center. If you have any questions about our use of AI, please contact us at Email: (support@platoforms.com).