/

Case Studies

The sentence GitBook deleted from its AI policy

Stani Mihov

Founder & CEO

·

TL;DR

Vendor: GitBook
Document: AI Policy
Date: August 12, 2026
Key change: The five-sentence AI policy promising that "Customer data is never shared with OpenAI or used to train any AI models" was replaced by a standalone policy that maps where data actually goes: questions and page content to OpenAI, embeddings to Turbopuffer, caching through Cloudflare, with zero-data-retention varying by endpoint and prompts sent unfiltered. A new "Open in ChatGPT / Claude" action operates outside GitBook's enterprise AI terms entirely.

The deleted sentence held two promises. The sharing promise is gone. The training promise survived and got broader: no AI training on any customer content without prior written consent, plus new organization- and site-level switches that stop content from being sent to AI providers at all.

The change

On August 12, 2026, GitBook replaced its AI policy. The old version was five sentences long and carried a single, bolded promise: "Customer data is never shared with OpenAI or used to train any AI models."

In its place stands a new, standalone GitBook AI Policy that runs several pages and describes, feature by feature, where data actually goes. For a platform that hosts the documentation of thousands of software teams, including internal and customer-facing knowledge bases, this is one of the more consequential policy rewrites of the year, and it cuts in both directions.

What changed

The deleted sentence contained two promises. The first, that customer data is never shared with OpenAI, did not survive. The new policy says GitBook uses OpenAI's enterprise API across its AI features: GitBook Assistant sends visitor questions and retrieved site content to OpenAI, and AI Search sends documentation pages for embedding "in large chunks," where "a chunk can contain a full page." The resulting embeddings are stored in Turbopuffer, a third-party vector database, and embedding requests are routed through Cloudflare AI Gateway, whose caching "can retain page content chunks."

Zero data retention is no longer a blanket condition either. The policy states coverage varies by endpoint: the content-scrubbing pipeline runs with store=false, while "GitBook Agent and Channels use store=true. These endpoints do not have zero data retention coverage." Questions, responses, and session identifiers are stored for AI Insights.

Two more disclosures deserve attention. On input handling: "GitBook sends user inputs to the AI provider as entered. GitBook does not filter or redact queries before they reach the LLM." And a new "Open in ChatGPT / Claude" page action sends the current page to those services under the visitor's own account, with the policy stating plainly that "GitBook's zero-retention, retention, and no-training terms do not apply" to that handoff.

One promise deleted, the other strengthened

The second half of the deleted sentence, the training promise, came back stronger. The new policy commits that GitBook does not use customer data to train AI or machine learning models and "will not do so without prior written consent," covering documentation, API specifications, and internal knowledge bases, whether AI features are enabled or not.

The rewrite also adds controls that did not exist on paper before. Organization admins can turn off GitBook AI for every member; site owners can separately disable AI Search and GitBook Assistant, and the policy states that "GitBook does not send that site's content to AI providers" when the features are off. Site owners can also disable the "Open in ChatGPT / Claude" action specifically. And GitBook Agent gets an explicit permission boundary: it "cannot access content unavailable to the requester."

Why this matters

If your team keeps documentation in GitBook, the question changed shape this month. Under the old policy the question was "does our content leave GitBook?" and the written answer was no. Under the new one the question is "which features send what, where, and under which terms?" and the answer is a map with three named providers and per-endpoint retention rules.

There is an honest reading of this rewrite: the one-sentence promise was simple, but as AI features multiplied it was no longer a description of reality, and GitBook chose to publish an accurate map instead of a comfortable sentence. That is transparency, and the map includes genuine, enforceable protections. As we argued in the Perplexity case study, a commitment written in the document is one you can hold a vendor to, and GitBook's expanded no-training clause is exactly that. But the deletion is equally real: teams that relied on the written assurance that their content never reaches OpenAI no longer have it, and finding that out requires reading the document when it changes, not the marketing page.

Potential impact

Teams running documentation on GitBook may want to review:

  • whether published or internal content contains sensitive material, before enabling AI features; the policy itself notes published-site AI features include site content in model context

  • the organization- and site-level AI switches, so what is enabled matches internal data policy

  • whether to keep the "Open in ChatGPT / Claude" action, which operates outside GitBook's enterprise AI terms, and how that interacts with the MCP endpoint setting

  • the expanded no-training commitment, worth recording as a written protection in the next vendor review

Mapping which vendor features move data to which subprocessors is the daily work of continuous vendor risk monitoring, and this change shows why a policy read once at procurement is not a policy known today.

How Venpo detected it

Venpo picked up the rewrite in GitBook's site policy on August 12: nine substantive changes, which our evaluation layer classified as three negative and six positive. We then verified the diff against the live document before writing this: the new GitBook AI Policy page matches the captured text word for word, and every quote above traces to inserted or deleted text in the redline.

The full side-by-side redline is available on our public feed: GitBook AI Policy, August 12, 2026.

Business outcome

Teams that caught this change early were able to:

  • audit their GitBook AI settings against internal data policy before the new defaults settled in

  • decide deliberately about the "Open in ChatGPT / Claude" action instead of discovering it live on their docs

  • brief documentation owners on which content flows to OpenAI, Turbopuffer, and Cloudflare

  • record the expanded no-training commitment as a written protection in their vendor file

The alternative is relying on a sentence that no longer exists.

Key takeaway

A one-sentence promise is easy to trust and easy to outgrow. GitBook traded a blanket promise for an accurate map, which is better for anyone who reads the map, and worse for anyone still quoting the promise. The only way to know which side you are on is to be reading the document when the sentence disappears, which is the case for automated monitoring over scheduled manual review.

The change

On August 12, 2026, GitBook replaced its AI policy. The old version was five sentences long and carried a single, bolded promise: "Customer data is never shared with OpenAI or used to train any AI models."

In its place stands a new, standalone GitBook AI Policy that runs several pages and describes, feature by feature, where data actually goes. For a platform that hosts the documentation of thousands of software teams, including internal and customer-facing knowledge bases, this is one of the more consequential policy rewrites of the year, and it cuts in both directions.

What changed

The deleted sentence contained two promises. The first, that customer data is never shared with OpenAI, did not survive. The new policy says GitBook uses OpenAI's enterprise API across its AI features: GitBook Assistant sends visitor questions and retrieved site content to OpenAI, and AI Search sends documentation pages for embedding "in large chunks," where "a chunk can contain a full page." The resulting embeddings are stored in Turbopuffer, a third-party vector database, and embedding requests are routed through Cloudflare AI Gateway, whose caching "can retain page content chunks."

Zero data retention is no longer a blanket condition either. The policy states coverage varies by endpoint: the content-scrubbing pipeline runs with store=false, while "GitBook Agent and Channels use store=true. These endpoints do not have zero data retention coverage." Questions, responses, and session identifiers are stored for AI Insights.

Two more disclosures deserve attention. On input handling: "GitBook sends user inputs to the AI provider as entered. GitBook does not filter or redact queries before they reach the LLM." And a new "Open in ChatGPT / Claude" page action sends the current page to those services under the visitor's own account, with the policy stating plainly that "GitBook's zero-retention, retention, and no-training terms do not apply" to that handoff.

One promise deleted, the other strengthened

The second half of the deleted sentence, the training promise, came back stronger. The new policy commits that GitBook does not use customer data to train AI or machine learning models and "will not do so without prior written consent," covering documentation, API specifications, and internal knowledge bases, whether AI features are enabled or not.

The rewrite also adds controls that did not exist on paper before. Organization admins can turn off GitBook AI for every member; site owners can separately disable AI Search and GitBook Assistant, and the policy states that "GitBook does not send that site's content to AI providers" when the features are off. Site owners can also disable the "Open in ChatGPT / Claude" action specifically. And GitBook Agent gets an explicit permission boundary: it "cannot access content unavailable to the requester."

Why this matters

If your team keeps documentation in GitBook, the question changed shape this month. Under the old policy the question was "does our content leave GitBook?" and the written answer was no. Under the new one the question is "which features send what, where, and under which terms?" and the answer is a map with three named providers and per-endpoint retention rules.

There is an honest reading of this rewrite: the one-sentence promise was simple, but as AI features multiplied it was no longer a description of reality, and GitBook chose to publish an accurate map instead of a comfortable sentence. That is transparency, and the map includes genuine, enforceable protections. As we argued in the Perplexity case study, a commitment written in the document is one you can hold a vendor to, and GitBook's expanded no-training clause is exactly that. But the deletion is equally real: teams that relied on the written assurance that their content never reaches OpenAI no longer have it, and finding that out requires reading the document when it changes, not the marketing page.

Potential impact

Teams running documentation on GitBook may want to review:

  • whether published or internal content contains sensitive material, before enabling AI features; the policy itself notes published-site AI features include site content in model context

  • the organization- and site-level AI switches, so what is enabled matches internal data policy

  • whether to keep the "Open in ChatGPT / Claude" action, which operates outside GitBook's enterprise AI terms, and how that interacts with the MCP endpoint setting

  • the expanded no-training commitment, worth recording as a written protection in the next vendor review

Mapping which vendor features move data to which subprocessors is the daily work of continuous vendor risk monitoring, and this change shows why a policy read once at procurement is not a policy known today.

How Venpo detected it

Venpo picked up the rewrite in GitBook's site policy on August 12: nine substantive changes, which our evaluation layer classified as three negative and six positive. We then verified the diff against the live document before writing this: the new GitBook AI Policy page matches the captured text word for word, and every quote above traces to inserted or deleted text in the redline.

The full side-by-side redline is available on our public feed: GitBook AI Policy, August 12, 2026.

Business outcome

Teams that caught this change early were able to:

  • audit their GitBook AI settings against internal data policy before the new defaults settled in

  • decide deliberately about the "Open in ChatGPT / Claude" action instead of discovering it live on their docs

  • brief documentation owners on which content flows to OpenAI, Turbopuffer, and Cloudflare

  • record the expanded no-training commitment as a written protection in their vendor file

The alternative is relying on a sentence that no longer exists.

Key takeaway

A one-sentence promise is easy to trust and easy to outgrow. GitBook traded a blanket promise for an accurate map, which is better for anyone who reads the map, and worse for anyone still quoting the promise. The only way to know which side you are on is to be reading the document when the sentence disappears, which is the case for automated monitoring over scheduled manual review.

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago

Real-time change notifications

Stay ahead of every legal change

Get updates, product news and expert tips on navigating legal changes

Stripe updated Terms of Service

Dispute resolution clause now requires mandatory arbitration in all regions

High Impact2 hours ago
AWS modified Privacy Policy

Data retention period extended from 2 years to 5 years for all services

Medium Impact5 hours ago
Shopify revised Acceptable Use Policy

New restrictions on AI-generated content in product descriptions

Review1 day ago
Slack changed Data Processing Agreement

Third-party data sharing expanded to include analytics partners

High Impact1 day ago