# User Privacy Issues

**URL:** <https://community.pickaxe.co/t/user-privacy-issues/652>\
**Category:** General\
**Created:** [July 23, 2024, 3:13pm UTC](https://community.pickaxe.co/t/user-privacy-issues/652 "2024-07-23T15:13:42Z")\
**Posts on this page:** 14\
**Page:** 1

<div class="post-metadata">

**Author:** ![DavidOswald](https://yyz2.discourse-cdn.com/flex004/user_avatar/community.pickaxe.co/davidoswald/32/183_2.png) [@DavidOswald](https://community.pickaxe.co/u/DavidOswald)\
**Post date:** [July 23, 2024, 3:13pm UTC](https://community.pickaxe.co/t/user-privacy-issues/652/1 "2024-07-23T15:13:42Z")

</div>

I think this might be two issues, so my apologies. Admins feel free to amend, edit or delete as appropriate.

I think the only thing that is really holding me back from launching is in respect of user privacy. There are two issues regarding privacy.

Firstly, in a studio, users provide their email address. Because of this, in Europe we really need a way to delete all details related to that user if they submit a request. So I can just delete their user account, but does Pickaxe store any details about the user account? Is it anonymised after a user is deleted?

Secondly, how long does pickaxe store chats and any files a user may have uploaded? Are all chats and files deleted when a user account is deleted from a studio?

I’m working on a studio for HR people, so CVs/Resumes, job descriptions amongst other relative sensitive material may be uploaded. I need to be able to reassure users their data is secure and is not used for any future use.

Thanks in advance for reading a rather lengthy post!!

---

<div class="post-metadata">

**Author:** ![NoName](https://avatars.discourse-cdn.com/v4/letter/n/58f4c7/32.png) [@NoName](https://community.pickaxe.co/u/NoName)\
**Post date:** [July 23, 2024, 4:53pm UTC](https://community.pickaxe.co/t/user-privacy-issues/652/2 "2024-07-23T16:53:31Z")

</div>

Very good point. I’m UK based so this is of interest to me too.

---

<div class="post-metadata">

**Author:** ![kasperwood](https://yyz2.discourse-cdn.com/flex004/user_avatar/community.pickaxe.co/kasperwood/32/249_2.png) [@kasperwood](https://community.pickaxe.co/u/kasperwood)\
**Post date:** [July 23, 2024, 5:18pm UTC](https://community.pickaxe.co/t/user-privacy-issues/652/3 "2024-07-23T17:18:40Z")

</div>

Also very relevant for me in Denmark

---

<div class="post-metadata">

**Author:** ![kitsune86](https://avatars.discourse-cdn.com/v4/letter/k/bbe5ce/32.png) [@kitsune86](https://community.pickaxe.co/u/kitsune86)\
**Post date:** [July 23, 2024, 10:36pm UTC](https://community.pickaxe.co/t/user-privacy-issues/652/4 "2024-07-23T22:36:45Z")

</div>

I am writing this from Canada but the Pickaxe I am working on involves sensitive topics like anxiety and mental health. I really should have an option to obfuscate the chat history because just exposing the exact email and what people are talking about is a privacy nightmare.

---

<div class="post-metadata">

**Author:** ![admin\_mike](https://yyz2.discourse-cdn.com/flex004/user_avatar/community.pickaxe.co/admin_mike/32/283_2.png) [@admin\_mike](https://community.pickaxe.co/u/admin_mike)\
**Post date:** [July 28, 2024, 7:47pm UTC](https://community.pickaxe.co/t/user-privacy-issues/652/6 "2024-07-28T19:47:26Z")

</div>

Currently you cannot delete user details.

As a Studio owner, you can delete certain accounts. Under the **Monitor** tab click the “Manage users” buttons. From there you can click on an email and then click “remove”. This will delete the user. If you delete a user from your studio, it deletes those associated records from our database as well.

I’ve included a screenshot below.

 ![Screenshot 2024-07-28 at 12.43.28 PM](https://canada1.discourse-cdn.com/flex004/uploads/pickaxeproject/original/1X/85f0e577e515d5f800514a45b37982713b3e0ab9.png)  
 ![Screenshot 2024-07-28 at 12.41.49 PM](https://canada1.discourse-cdn.com/flex004/uploads/pickaxeproject/original/1X/794f1cefef0881f626391d12a6517396f485a9d9.png)

As far as user chats and end-user document uploads, the same applies. if you delete a user and their chats, then those files are deleted from our database as well.

---

<div class="post-metadata">

**Author:** ![DavidOswald](https://yyz2.discourse-cdn.com/flex004/user_avatar/community.pickaxe.co/davidoswald/32/183_2.png) [@DavidOswald](https://community.pickaxe.co/u/DavidOswald)\
**Post date:** [July 29, 2024, 7:24am UTC](https://community.pickaxe.co/t/user-privacy-issues/652/7 "2024-07-29T07:24:44Z")

</div>

That’s great @admin_mike . I’m no GDPR expert, but if deleting the user deletes associated records that’s a great help.

I think the only other things from a privacy perspective that matter are being able to show what details we store about users as EU and UK citizens can request to see what details are held about them.

But I’m sure there are other people on here that can advise on other elements that need to be considered for EU/UK citizens.

Thanks for being so active on here supporting us with our queries.

---

<div class="post-metadata">

**Author:** ![admin\_mike](https://yyz2.discourse-cdn.com/flex004/user_avatar/community.pickaxe.co/admin_mike/32/283_2.png) [@admin\_mike](https://community.pickaxe.co/u/admin_mike)\
**Post date:** [July 29, 2024, 7:33pm UTC](https://community.pickaxe.co/t/user-privacy-issues/652/8 "2024-07-29T19:33:42Z")

</div>

Happy to help! If you find out other good solutions, it’s always very helpful to write a post labeled like “How to follow GDPR compliance on Pickaxe Studios” or something. Other users would benefit from such a thing!

---

<div class="post-metadata">

**Author:** ![landed](https://avatars.discourse-cdn.com/v4/letter/l/a88e57/32.png) [@landed](https://community.pickaxe.co/u/landed)\
**Post date:** [October 16, 2024, 4:58pm UTC](https://community.pickaxe.co/t/user-privacy-issues/652/9 "2024-10-16T16:58:44Z")

</div>

In the same privacy space if a user enters their email and this goes across the API to openai how is it processed? As I write this I realise I need to ask on their dev forum. But maybe you guys already know. TY

---

<div class="post-metadata">

**Author:** ![admin\_mike](https://yyz2.discourse-cdn.com/flex004/user_avatar/community.pickaxe.co/admin_mike/32/283_2.png) [@admin\_mike](https://community.pickaxe.co/u/admin_mike)\
**Post date:** [October 16, 2024, 8:59pm UTC](https://community.pickaxe.co/t/user-privacy-issues/652/10 "2024-10-16T20:59:24Z")

</div>

All Pickaxe data sent to OpenAI is under a special agreement of a 30-day deletion policy and is not used to train models. The email address would hit OpenAI, but would be handled under those two assurances. Worth asking on their forum as well.

---

<div class="post-metadata">

**Author:** ![james.yeoh](https://avatars.discourse-cdn.com/v4/letter/j/b2d939/32.png) [@james.yeoh](https://community.pickaxe.co/u/james.yeoh)\
**Post date:** [January 16, 2025, 2:45pm UTC](https://community.pickaxe.co/t/user-privacy-issues/652/11 "2025-01-16T14:45:42Z")

</div>

I have concerns that I can see my client’s prompts and results in Pickaxe. Is there a way for me not to see it? I need to give my clients confidence that I cannot see their data.

---

<div class="post-metadata">

**Author:** ![conrad](https://yyz2.discourse-cdn.com/flex004/user_avatar/community.pickaxe.co/conrad/32/428_2.png) [@conrad](https://community.pickaxe.co/u/conrad)\
**Post date:** [February 10, 2025, 11:18pm UTC](https://community.pickaxe.co/t/user-privacy-issues/652/12 "2025-02-10T23:18:10Z")

</div>

@admin_mike I have the same question. In products where privacy is crucial, like therapist bots, etc. It’s quite unethical if we see their dialogues.

---

<div class="post-metadata">

**Author:** ![admin\_mike](https://yyz2.discourse-cdn.com/flex004/user_avatar/community.pickaxe.co/admin_mike/32/283_2.png) [@admin\_mike](https://community.pickaxe.co/u/admin_mike)\
**Post date:** [February 10, 2025, 11:39pm UTC](https://community.pickaxe.co/t/user-privacy-issues/652/13 "2025-02-10T23:39:12Z")

</div>

You’ll be very excited for the redesigned system then.

For each Studio, there will be an option for Studio Owners to decide whether to “collect responses” or “not collect responses”. This feature is motivated by the many Pickaxe users working in fields where HIPAA matters. This ‘collect/do not collect’ setting will be a toggle you set on a studio by studio basis. If you select ‘do not collect’, then the responses are simply not collected for you to see.

 ![Screenshot 2025-03-01 at 9.45.45 AM](https://canada1.discourse-cdn.com/flex004/uploads/pickaxeproject/original/2X/8/8a719b33087ce01c58705568a854ad269564ee2d.png)

---

<div class="post-metadata">

**Author:** ![conrad](https://yyz2.discourse-cdn.com/flex004/user_avatar/community.pickaxe.co/conrad/32/428_2.png) [@conrad](https://community.pickaxe.co/u/conrad)\
**Post date:** [February 11, 2025, 12:11am UTC](https://community.pickaxe.co/t/user-privacy-issues/652/14 "2025-02-11T00:11:58Z")

</div>

So happy to hear that, thanks!

---

<div class="post-metadata">

**Author:** ![historicalcelt](https://yyz2.discourse-cdn.com/flex004/user_avatar/community.pickaxe.co/historicalcelt/32/1116_2.png) [@historicalcelt](https://community.pickaxe.co/u/historicalcelt)\
**Post date:** [March 1, 2025, 5:24am UTC](https://community.pickaxe.co/t/user-privacy-issues/652/15 "2025-03-01T05:24:22Z")

</div>

Would pickaxe be storing that information though? Or just sending to openai and then deleting after 30 days?
