AI Policy
Effective Date: August 14, 2026 · Version 1.1Cloud Army Network, Inc. ("CloudArmy") is committed to the responsible development and deployment of artificial intelligence. The Reactor™ platform — including Reactor Studio and Reactor Self Service — integrates AI capabilities to enhance research efficiency while maintaining the highest standards of privacy, security, and ethical use. This policy explains the principles we follow, what data AI features process, and the controls you have.
1. Our Core AI Principles
Transparency. We clearly identify when AI is being used. Each AI feature is documented with its purpose and data usage — there is no hidden AI. Users are always aware when AI processes their data.
Data minimization. AI features only access the data required for their specific function, preferring structural metadata over actual content wherever possible.
Customer data protection. Customer data is never shared between customers and is never used to train AI models without explicit consent.
Grounded results. Studies run with real, authenticated human respondents — never AI imagining what people might do. AI accelerates analysis and packaging, but findings are tied back to your actual data with citations and supporting evidence. AI never invents the findings.
Aggregate insight, never individual inference. AI is not used to administer test protocols or to calculate results — measurement and scoring use published cognitive-association methods, and AI synthesizes meaning and summaries from those computed results. Insights describe significant trends in populations; Reactor never uses its data to infer the emotions or likely behavior of any individual participant.
Human oversight, and honest labelling of it. AI does not administer tests, calculate results, or perform the analysis — those use published cognitive-association methods. Where AI does contribute, by summarizing findings and helping present the work, the output says so: reports identify which findings have been reviewed by a human and which have not, so you are never left guessing which is which. We would rather tell you exactly what has been checked than claim that everything has.
Marked outputs, readable by people and machines. AI-assisted content carries both a human-visible indication and invisible machine-readable marks. A visible label protects a reader; it does nothing for an automated system that ingests the report, and it does not survive being copied onward. Marking the content itself means its provenance travels with it.
User control. You maintain control over AI features and AI data protections, with the ability to adjust them at any time.
2. Where AI Is Used
Reactor Self Service. AI agents handle the analysis and packaging of completed studies — generating charts, conclusions, and presentation-ready reports. This work is always grounded in the study data your project collected, and PanelGuard protects the quality of that data during fielding.
Reactor Studio. The Studio AI Assistant is a conversational interface for exploring findings, interrogating your data, generating hypotheses, and creating analyses and outputs. It connects to leading AI models through Reactor MCP, CloudArmy's Model Context Protocol server, which manages every model connection through one controlled workflow.
3. The Sanity Agent Privacy Wall
Reactor Studio protects confidential information with the Sanity Agent Privacy Wall. When the wall is on:
- Confidential values — such as personal names, email addresses, customer and project names, respondent identities, and secret- or financial-shaped values — are replaced with pseudonymous tokens before text is sent to an external AI model.
- The mapping between tokens and real values is held in an encrypted registry that is never exposed to AI models. You see your real names on screen; models see tokens.
- Finished deliverables are produced with real values restored as the final step.
The wall is on by default in generally available releases. It is a user-controllable setting: if you switch it off, information is sent to AI models as entered. Automated detection cannot guarantee that every confidential value is recognized — when the system is unsure about a value, it asks you to confirm whether it is confidential, and you remain responsible for what you choose to send.
4. AI Service Providers
Reactor connects to a range of third-party AI model providers through Reactor MCP. For all providers:
- Data is processed under the provider's terms and our data processing agreements.
- We do not permit customer data to be used for training AI models without explicit consent.
- All data transmission to AI services is encrypted in transit.
- Data sent to AI services is not retained by us beyond the processing duration.
When using AI features, data may be processed on servers in other countries, including the United States. We maintain appropriate safeguards, including Standard Contractual Clauses (SCCs) and data processing agreements with AI service providers.
5. Auditability
We log AI feature usage — which user used which feature, and when — as audit records. AI interaction logs are retained for 90 days for security and troubleshooting. Organizations can request logs of their AI interactions for audit purposes.
6. Your Rights and Controls
As a Reactor platform customer, you have the right to:
- know which AI features process your data;
- control AI features and data protections, including the Privacy Wall setting;
- request audit logs of AI usage for your organization;
- receive notification of any AI-related incidents affecting your data;
- request human review of any AI output; and
- request deletion of AI-processed data.
7. Accuracy and Appropriate Use
AI-generated output may be incomplete or incorrect. It is provided to assist your work, not to replace your judgment. You are responsible for reviewing AI output before relying on it, and for ensuring your use of AI features complies with your own policies and any obligations to your research participants.
8. Incident Response
If an incident affects an AI feature or the data it processes, we disable the affected feature, notify impacted customers, investigate the root cause, and remediate before re-enabling. Incidents are documented and reviewed.
9. Policy Review and Updates
This policy is a living document. We review it regularly and update it as our AI capabilities and the regulatory landscape evolve. Material changes will be indicated by a revised version number and effective date and communicated through the Services.
10. Contact
For questions about this policy or AI use in the Reactor platform: privacy@cloud.army — Support: support@cloud.army — General: info@cloud.army.
© 2026 Cloud Army Network Inc. All rights reserved.