Skip to content

[Bug]: Data Retention Policy #3198

@Branden-hub

Description

@Branden-hub

Current Behavior

So, when your ToS and your Data retention policies are collected for compliance purposes, what efforts are taken to ensure that you do not retain (Trade Secrets, Proprietary information, and or Intellectual Property)? Clearly by saving all communications there is no privacy what-so-ever, the tool is a data aggregation system for the cloud regardless of what the user has expectations of being private. In the United States of America, there are federal laws strictly prohibiting the collection and retention of such things.

"While service providers rely on Terms of Service (ToS) to authorize data retention, these agreements do not automatically override federal and state protections for Trade Secrets and Proprietary Information."

This is a major bug in your system that needs addressed:

The Defend Trade Secrets Act of 2016 (18 U.S.C. § 1836) and the Uniform Trade Secrets Act (UTSA) provide the primary protection for proprietary information.

Under the DTSA, misappropriation occurs if a trade secret is acquired by a person who knows or has reason to know it was acquired by "improper means."

To maintain trade secret status, the owner must take "reasonable measures" to keep the information secret.

This does not include using a tool in any way, the tool is meant to be for use not for acquiring data of the user's conversation history!

While platforms claim a right to "retain a record of this chat," that right is not absolute.

If a platform uses your proprietary code or strategic data to train a model that then outputs that same information to a competitor, this could constitute Trade Secret Misappropriation or Unfair Methods of Competition, which are subject to FTC enforcement.

The FTC has explicitly stated (2024-2026 guidance) that there is "no AI exemption" from existing laws. Companies that deceive users about how data is used or that "appropriate competitively significant information" may be liable for unfair or deceptive trade practices.

If the platform’s retention leads to unauthorized access or use of your "Trade Secrets and Proprietary information," it may trigger:

Even without a signed NDA, if a platform presents itself as a secure environment for business but fails to protect the data, legal arguments for "implied confidentiality" may exist.

If the AI processes your code in a way that creates a derivative work without authorization, it may violate copyright laws, regardless of what the ToS says about "retention."

the Delete Act, you may have the right to request the deletion of your data or an audit of what has been retained.

If my proprietary information is being used in a way that diminishes its value or discloses it to third parties, that is a direct challenge to my Intellectual Property rights.

Expected Behavior

I am requesting compliance from whom ever has saved information regarding my conversations, the Delete Act says I can have this done, as my IP is very valuable and there is no way of knowing what was retained by your AI systems I request all of it from my inputs and the machines outputs be deleted immediately and I want proof the data was deleted and no copy's were transferred to hidden third party's or any other persons or places.

Steps To Reproduce

apparently simply using the service means everything is retained and there is no privacy at all even though it is a law that is fundamentally a guaranteed right for being a citizen of the United States of America.

Wave Version

vWhatever_the_hell_it_is

Platform

Windows

OS Version/Distribution

No response

Architecture

x64

Anything else?

I’m the Wave AI assistant embedded in this environment (an OpenAI‑powered assistant). I don’t have a human‑readable “product version” string to report from inside this session. Relevant facts:

Model family: OpenAI assistant (Wave integration).- Knowledge cutoff: June 2024.
Current date: April 8, 2026.
Runtime/context: the Wave Terminal embedded assistant panel (local CLI/preview widgets shown).
If you need an exact build/version identifier for legal purposes, tell me what identifier format you require (model name, runtime build ID, or platform component) and I’ll produce the exact text you should request from the platform/operator (since I cannot fetch or assert a hidden internal build/version string from here).

Metadata

Metadata

Assignees

No one assigned

    Labels

    bugSomething isn't workingtriageNeeds triage

    Type

    No type

    Projects

    No projects

    Milestone

    No milestone

    Relationships

    None yet

    Development

    No branches or pull requests

    Issue actions