Skip to main content

AI & Data Privacy in Insights

Learn how Insights’ AI features handle data securely, ensuring privacy with minimal sharing and no AI training by AWS

Written by Ashley Dehertogh

At FLYR Hospitality, we understand that data privacy and security are top priorities for our customers. As we integrate AI-powered features into Insights to help you explore data more efficiently, we remain committed to transparency and responsible data handling.

This article explains how Insights uses AI, what data is shared, and how we ensure your data stays protected.

How AI is Used in Insights

AI features in Insights are designed to simplify your workflow, helping you get to answers faster. You can:

  • ✔️ Ask questions about your data using natural language

  • ✔️ Get help generating queries and building calculations

  • ✔️ Instantly summarize query results for faster insights

All AI functionality in Insights is powered by a single provider:

  • Amazon Web Services (AWS) Bedrock – using hosted Claude models.

This allows us to offer seamless AI assistance while keeping your data within the same secure infrastructure and region.

🔒 Your data privacy is our priority: Any data sent to these AI models is never used for training by AWS.

What Data is Shared & How It’s Protected

We’re intentional about what data is sent to AI models—and what isn’t. Here's how data is handled depending on the AI interaction:

When you enter a natural language prompt, Insights sends metadata only—never raw data—to Bedrock. This includes:

Note:

  • 🚫 No raw data, relational data, or query results are ever shared with Bedrock.

  • 🚫 AWS does not retain data for training

AWS Bedrock’s hosted Claude model is used when you request a data summary within Insights. In these cases, Insights shares:

  • ✔️ The same metadata noted above (see table above).

  • ✔️ A CSV of the query’s results to generate accurate summaries.

🛡️ Regional Deployment for Privacy: AI models are deployed in the same region as your data. If you’re in the EU, for example, AWS ensures your data never leaves your region.

🚫 All data shared with AWS remains within AWS infrastructure and is never used for training.

Ensuring Security & Compliance

At FLYR Hospitality, we are committed to protecting your data. Our AI-powered features are designed to be secure, transparent, and privacy-conscious.

  • Data Access Controls: AI-generated queries always respect your permissions, ensuring users cannot access data outside their allowed topics.

  • Minimal Data Sharing: Only metadata and user prompts are shared—never raw data or relational details. For summaries, a CSV of the current query’s results is shared in addition to metadata.

  • Regional Data Protection: AWS Bedrock models are region-specific, ensuring data remains within compliance zones.

  • No AI Training: FLYR Hospitality does not allow AWS to use your data for model training.

Model Integrity & Prompt Safety

Customers sometimes ask whether the AI model behind Insights could be "poisoned" or manipulated through user prompts. Here's how that risk is addressed:

  • No training on customer prompts: As noted above, FLYR Hospitality does not allow AWS to use customer data, including prompts entered into Insights, to train or fine-tune the underlying model. Since the model is never retrained on what customers type, there is no mechanism for a user's input to alter the model itself, for other users, or over time. This rules out model poisoning in the traditional sense, where an attacker corrupts a model by manipulating its training data.

  • Each prompt is handled independently: Insights' AI processes every prompt as a fresh, self-contained request scoped to the requesting user's own session. There is no shared, persistent state that one user's prompt could write into and another user's prompt could later read. A crafted or adversarial prompt is contained to the session that submitted it: it cannot alter how the AI behaves for other users, and it cannot leave anything behind for a future session to inherit.

  • Permissions are enforced regardless of prompt content: AI-generated queries always run within the requesting user's existing data permissions, which are set through role-based access controls. A prompt cannot be used to bypass those controls or reach data outside a user's allowed topics, no matter how the prompt is worded.


📌 Need more information? Reach out to our Advisory team via the chat with any questions about AI and data privacy in Insights.

Did this answer your question?