Start with the request and applicable process
Record the requester, requested scope, received date, jurisdiction, identity-verification status, deadline, and privacy owner. This article supplies a technical evidence map, not jurisdiction-specific legal advice; use the organization's established rights-request process to decide what must be searched and disclosed.
Clarify which site, date range, email or account, and interaction the person means. Search proportionately across systems reasonably capable of linking records to that requester. Do not export an entire operational log merely because the original request is broad.
Classify fields before searching values
Create a current inventory from schema, configuration, and a controlled request. For each field, state whether it is a direct identifier, pseudonymous signal, aggregate counter, transient input, secret, or not stored; then record purpose, source, location, retention, access, and possible lookup key.
The published design states that raw prompts, responses, and API keys are not persisted by the cost log. Verify the deployed version and settings before repeating that statement in a response. 'Not designed to store' and 'confirmed absent from this deployment' are different claims.
| Field class | Example | Search method | Response treatment |
|---|---|---|---|
| Direct identifier | account or contact reference if configured | exact authorized systems | review and disclose as applicable |
| Pseudonymous signal | optional keyed HMAC-SHA256 digest | recompute only if key and policy allow | explain uncertainty and purpose |
| Operational counter | attempts/tokens by period | aggregate query | do not attribute to person without linkage |
| Transient input | prompt in request memory | not searchable after processing | state verified storage behavior |
| Secret | API key | never search by exposing value | exclude and protect |
Interpret pseudonymous evidence carefully
A keyed digest can support repetition analysis without storing the original input, but it is not automatically anonymous. Whether a requester can be linked depends on available keys, reference data, rotation, and purpose. Record those limits rather than asserting either certain identity or zero personal data.
Human, Bot, and Unknown are operational classifications with uncertainty, not facts about a person's identity or intent. If included in a response, explain the signals, purpose, and limitations and avoid presenting Unknown as suspicious behavior.
Search narrowly and preserve other people's confidentiality
Log systems searched, queries or linkage method, date, operator, results, and exclusions. Review records for third-party information, security details, trade secrets, and unrelated incidents before disclosure. Redact or summarize only under the applicable process and document the reason.
Do not weaken security by exporting API keys, raw authentication data, or digest secrets. If the cost log cannot reliably connect aggregate counters to one visitor, say that no reliable individual attribution is available rather than manufacturing a per-person usage total.
Produce a response map, not a data dump
For every requested category, the final map states stored or not stored, purpose, source, retention, search result, confidence, disclosure decision, and evidence location. Add the deployed version and retention configuration so the answer is tied to the actual system at the request date.
Close when identity verification, searches, review, response, and any authorized correction or deletion are recorded, with a deadline owner. Link the current privacy policy so the requester can see the product's stated data practices, while preserving the case-specific evidence behind the answer.
Use the data-request response map from “A privacy request asks what the AI cost log knows about a visitor” on a real first installation. Download AI Cost Circuit Breaker for free, begin in Monitoring, and move to enforcement only after the expected signals and rollback are verified.