No. Using Tenera does not expose your firm's intellectual property (IP): you keep ownership of every report and template you put in, nothing you put in trains an AI model, and your files sit encrypted, with access restricted, logged, and deletable on request. Each of those is a separate promise with a separate mechanism behind it, and this article takes them one at a time. Compared to what most firms actually run today, an engineer with a personal ChatGPT account, Tenera does better on all three.
Who owns the report?
You do, and using Tenera does not change that. The question here is whether feeding your findings, your section structure and your firm's way of describing a defect into someone else's system gives that system a claim on them.
It does not, and it helps to know who "someone else" actually is. Two parties handle your content: Tenera, and the AI model provider our software calls to do the drafting, which for us is OpenAI. On our side, your data is yours; nothing you put in or get out becomes ours. On the provider's side, OpenAI's enterprise terms state plainly that you retain all rights to the inputs you provide and own the outputs you receive, and that the rights they take are only those needed to run the service and comply with law. Your methodology stays yours. Your report stays yours, whichever route it took.
Is your data used to train an AI model?
No, on both legs of the journey, and the two legs are governed differently, so it is worth taking them separately.
Our leg. We do not use your content to train AI models, ours or anyone else's. Your data is used only to deliver the service to you.
The model provider's leg. Tenera uses commercial API agreements with our AI model providers. Under those agreements your data is not used to train their models, and retention is contractually limited. That is not a favour anyone negotiated for us: it is the published API default. OpenAI's own position is that data from their API platform has not been used to train their models since March 2023 unless a customer explicitly opts in to share it.
Consumer ChatGPT runs the opposite default. On a personal Free, Plus or Pro account, data sharing is on unless the individual has gone into Settings, found Data Controls, and switched off "Improve the model for everyone." Most people never open that menu. And the opt-out is forward-looking only: turning it off later does not remove anything a model has already learned.
So the same sentence describes both routes and means different things. Through a business tool, exclusion from training is the default and it sits in a contract. Through a personal account, exclusion is a setting one person has to remember to change on their own device.
Where does your data actually sit?
Two copies exist, and they follow different rules. This is the part most explanations skip, and skipping it is what makes the answer feel evasive.
Our copy holds the report. It runs on Amazon Web Services in us-east-1, which means the physical security of the data centres, the hardware lifecycle and network isolation are handled by an operator with far more resources than any software company our size. Everything in transit travels over TLS 1.2 or higher; everything at rest (reports, photos, videos, documents) is encrypted with AES-256. Backups run automatically, are encrypted, and restores are tested periodically, so that "we have backups" means something.
That copy stays. It is the product. A report that vanished after a month would be useless to a firm carrying record-retention obligations.
Deletion is a separate lever, and it works two ways. You can delete a specific project or record through the application, and it is removed from active systems and ages out of backups on the standard cycle. If you stop being a customer, you can export your reports and the associated files, and on request we will delete your data from active systems within 60 days, with backups ageing out on the same normal cycle.
The model provider's copy is a different thing entirely: a working copy governed by API terms rather than consumer ones, with retention limited by contract rather than by a setting. Against that, a personal account has one copy and it is not transient. It sits in that individual's chat history until they delete it, on an account the firm does not administer.
One straight answer worth stating plainly rather than burying: our infrastructure is currently based in the USA. If data residency is a requirement in your client contracts, raise it early and we will tell you what we can support rather than discover it at signature.
Who at Tenera can see your data?
A small number of named staff, only when operating the service or handling a support request you have raised. Not our sales team, and not on a routine basis. Administrative access to production systems is restricted, protected by multi-factor authentication, and granted on a least-privilege basis.
That is a narrower answer than "nobody but you," and the narrower answer is the true one. Any vendor telling an engineering firm that literally no one on their side can reach production data is either describing a system nobody can support or hoping the question does not get a follow-up.
Inside your own account, access is per project and role-based: a field engineer, a reviewer and an administrator each see what their job requires. Activity is logged.
You cannot audit a personal ChatGPT account
Not in the encryption. In whether anyone can verify it.
An engineer who has turned training off, uses temporary chat and never pastes a client's name has closed most of the technical distance on their own. Credit where it is due: that person is being careful.
What they cannot do is make it checkable. The setting is per-account and per-person. A managing principal cannot audit it, cannot enforce it across eleven engineers, and cannot produce evidence of it to a client who asks. There is also no contract in play. A consumer account comes with no data processing agreement; OpenAI executes DPAs for API and business customers in support of GDPR and other privacy law, and we will sign a DPA or complete your security questionnaire on request. We keep a current list of our subprocessors, hosting, model providers, and a small number of operational services, and will provide it if you ask.
So the difference is less about what happens on a good day and more about what you can demonstrate on a bad one. For a firm carrying professional liability, that distinction is the whole point.
The exposure most firms already have: file sprawl
Most of the real risk in field work is not dramatic. It is sprawl.
One site visit can end up spread across a phone's camera roll, a WhatsApp thread, an email attachment, a draft on someone's desktop, a shared-drive folder whose permissions have not been reviewed in three years, and a link that never expires. Nobody decided that should happen; it happens because the work is fast and the tools are whatever is at hand.
The consequences are ordinary and expensive. You cannot secure, produce or confirm the deletion of files you cannot locate. Offboarding disables an email account, not the copies on a departing employee's laptop and phone. And when the only copy of something lives on a phone, losing the phone is both a data loss and a potential disclosure.
Consolidating that work does not make those problems disappear on its own. It makes them addressable: access granted per project and revoked in one place, activity logged, and a lost phone reduced to an inconvenience because the data was never only on the phone.
The duty that stays with the firm
The duty to the client, which no supplier agreement transfers. Your client (the building owner, the developer, the condominium corporation, sometimes counsel) did not choose your software and in most cases does not know it exists.
That means the firm still decides what may be captured on a client's site, what may leave it, and what gets redacted first. A tool can make those decisions easier to enforce. It cannot make them for you, and "our vendor said it was fine" is not a position you want to be arguing from.
What to ask any AI vendor, in writing
Ask whoever you are evaluating, including us, for four things in writing: whether your content reaches a third-party model provider and on what terms; what the retention and deletion behaviour actually is, including whether deletion covers backups; where the infrastructure sits; and what you can export if you leave. Then ask the same questions about the personal accounts your team may already be using, where the answers are public and worth reading before the next site visit.
Ready to use AI to write reports in a responsible, safe way?
That is what Tenera is built for: your reports stay yours, nothing trains on your content, and the data questions have written answers. Book a demo and put the four questions to us directly, or start with our security page. We will sign a DPA or complete your security questionnaire on request.