All field guidesPortfolio evidence governance · Prove and scale

A privacy request asks what the AI cost log knows about a visitor

A field-level response map distinguishes identifiers, pseudonymous signals, counters, transient content, and data the system does not store.

Updated 2026-09-01 · 4 min read
Written for
Finance, procurement, or privacy lead
Article format
Field-level privacy diagnosis
Take-away
data-request response map

Start with the request and applicable process

Record the requester, requested scope, received date, jurisdiction, identity-verification status, deadline, and privacy owner. This article supplies a technical evidence map, not jurisdiction-specific legal advice; use the organization's established rights-request process to decide what must be searched and disclosed.

Clarify which site, date range, email or account, and interaction the person means. Search proportionately across systems reasonably capable of linking records to that requester. Do not export an entire operational log merely because the original request is broad.

Classify fields before searching values

Create a current inventory from schema, configuration, and a controlled request. For each field, state whether it is a direct identifier, pseudonymous signal, aggregate counter, transient input, secret, or not stored; then record purpose, source, location, retention, access, and possible lookup key.

The published design states that raw prompts, responses, and API keys are not persisted by the cost log. Verify the deployed version and settings before repeating that statement in a response. 'Not designed to store' and 'confirmed absent from this deployment' are different claims.

Field classExampleSearch methodResponse treatment
Direct identifieraccount or contact reference if configuredexact authorized systemsreview and disclose as applicable
Pseudonymous signaloptional keyed HMAC-SHA256 digestrecompute only if key and policy allowexplain uncertainty and purpose
Operational counterattempts/tokens by periodaggregate querydo not attribute to person without linkage
Transient inputprompt in request memorynot searchable after processingstate verified storage behavior
SecretAPI keynever search by exposing valueexclude and protect

Interpret pseudonymous evidence carefully

A keyed digest can support repetition analysis without storing the original input, but it is not automatically anonymous. Whether a requester can be linked depends on available keys, reference data, rotation, and purpose. Record those limits rather than asserting either certain identity or zero personal data.

Human, Bot, and Unknown are operational classifications with uncertainty, not facts about a person's identity or intent. If included in a response, explain the signals, purpose, and limitations and avoid presenting Unknown as suspicious behavior.

Search narrowly and preserve other people's confidentiality

Log systems searched, queries or linkage method, date, operator, results, and exclusions. Review records for third-party information, security details, trade secrets, and unrelated incidents before disclosure. Redact or summarize only under the applicable process and document the reason.

Do not weaken security by exporting API keys, raw authentication data, or digest secrets. If the cost log cannot reliably connect aggregate counters to one visitor, say that no reliable individual attribution is available rather than manufacturing a per-person usage total.

Produce a response map, not a data dump

For every requested category, the final map states stored or not stored, purpose, source, retention, search result, confidence, disclosure decision, and evidence location. Add the deployed version and retention configuration so the answer is tied to the actual system at the request date.

Close when identity verification, searches, review, response, and any authorized correction or deletion are recorded, with a deadline owner. Link the current privacy policy so the requester can see the product's stated data practices, while preserving the case-specific evidence behind the answer.

Use the data-request response map from “A privacy request asks what the AI cost log knows about a visitor” on a real first installation. Download AI Cost Circuit Breaker for free, begin in Monitoring, and move to enforcement only after the expected signals and rollback are verified.

Primary sources checked

Next field guidePrepare an evidence pack for an insurer, auditor, or client after a cost incident