AI Disclosure

Effective date: August 5, 2026
Version: 3.0

You are interacting with an AI system. The Trazomo practicum uses AI to grade, score, and coach your exercise responses, and to answer you in the in-lesson tutor. The feedback you receive is generated by an artificial-intelligence model, not by a human reviewer, and is labeled "AI-generated feedback" in the product interface.

This disclosure is provided to satisfy our transparency obligations under Article 50 of the EU AI Act (Regulation (EU) 2024/1689) and comparable US state laws (including Colorado SB24-205 and Utah SB 149), as well as under GDPR Articles 13 and 14.

1. Where We Use AI

AI is used in the Services to evaluate user-submitted text and generate structured feedback, including:

  • Scoring exercise responses against the lesson's evaluation criteria;
  • Producing strengths and improvement suggestions;
  • Generating short-form reflective feedback on quizzes;
  • Answering your questions in the in-lesson tutor, across a multi-turn conversation;
  • Running a short safety and scope check on your text before the main call, so that off-topic or unsafe requests are declined.

AI is not used to make hiring, credit, licensure, disciplinary, or any other automated decision that produces legal or similarly significant effects concerning you within the meaning of GDPR Article 22.

2. Data-Flow Chain

When you submit text into a Trazomo exercise, reflection, or tutor message:

  1. Your browser transmits the text to Trazomo's servers, which run on Cloudflare Pages and the Cloudflare Workers runtime, over TLS.
  2. Trazomo assembles a server-side prompt. For an exercise this includes your submission, the exercise context, and the evaluation criteria. For the tutor it includes your message, up to the last 16 turns of that conversation, the lesson material, and a short profile summary drawn from your onboarding answers (your role, jurisdiction, experience level, and free-text goal). Your email address, your name, and your account identifiers are never included in a prompt.
  3. Trazomo sends the request to Cloudflare AI Gateway, which proxies it to OpenRouter, which forwards it to a selected third-party foundation model at request time. Your text is typically sent twice: once to a small classifier model for the safety and scope check, and once to the model that produces your feedback or reply.
  4. The model returns a score and feedback, or a tutor reply. Trazomo stores the score and structured feedback with your learning history. Saved reflections keep your free-text response, and tutor conversations keep the full transcript, so that you can return to them. Both are retained until you delete them or your account is deleted.

The models that serve your request are hosted outside the EEA, so your submission leaves the EEA. Transfers rely on Standard Contractual Clauses and, where applicable, the EU-U.S. Data Privacy Framework. Please see our Privacy Policy for the legal bases and transfer mechanisms in detail.

3. Model Providers

OpenRouter is the only AI routing path in production, reached through Cloudflare AI Gateway. OpenRouter does not store prompts or completions by default and does not train on them. We set OpenRouter's Zero Data Retention flag on every request, including streaming tutor requests. OpenRouter also applies two account-level guardrails to every Trazomo request before it is forwarded to a model provider. Its Sensitive Info guardrail detects common sensitive-information formats by pattern matching (such as email addresses, phone numbers, Social Security numbers, credit card numbers and IP addresses) and either replaces the matched text with a labeled placeholder or rejects the request before it reaches the model; it runs on the prompt side only and does not scan model responses. Its prompt-injection detection scans incoming requests for common injection techniques using pattern matching. These are pattern matches, not an understanding of your text: OpenRouter's NLP-based detection of personal names and addresses is not enabled on our account, so a person's name or address is not detected or removed, which is one more reason the rule in Section 5 applies. See OpenRouter privacy and logging, Sensitive Info guardrail and Zero Data Retention.

The models reached through OpenRouter, and therefore the companies that process your text, are:

  • Anthropic (Claude Sonnet and Claude Haiku). United States.
  • OpenAI (GPT). United States.
  • Google (Gemini, billed API tier). United States.
  • Alibaba Cloud (Qwen). Established in China.
  • DeepSeek (DeepSeek Chat). Established in China.

Which of these serves you depends on your tier and on availability. Paid exercise and tutor traffic is directed first to Claude Sonnet, with GPT and Gemini Pro as fallbacks. Free-tier exercise and tutor traffic is directed first to Gemini Flash, with Qwen and DeepSeek as fallbacks. A fallback is used when the model ahead of it in the list fails or is unavailable. China has not received an EU adequacy decision, so if you would prefer your text never reach a China-established provider, do not use the free tier's AI features.

Our code retains unused adapters for other providers. None of them is configured or reached in production, so we do not list them here as processors. If we enable one, this disclosure is updated first.

4. Training and Retention

Neither Trazomo nor OpenRouter trains AI models on your exercise submissions or tutor messages. We set Zero Data Retention on every OpenRouter request. Where a downstream model endpoint operates its own abuse-monitoring retention window, that provider's terms govern the interim handling of the data. We review these terms at each material revision of this disclosure.

One qualification we want to state rather than leave implied: because every AI request is proxied through Cloudflare AI Gateway, the gateway can log request and response content according to the configuration we choose there. That is our own configuration, not a third party's, and it is covered by our agreement with Cloudflare. Cloudflare does not train models on it.

5. Confidentiality: Do Not Submit Privileged or Client Data

The Trazomo practicum is a training environment. Text you submit into AI-assisted features is transmitted to third-party AI providers outside your direct control. You must not submit:

  • information subject to the attorney-client privilege, whether your own, your firm's, or a client's;
  • attorney work product, including mental impressions, legal strategy, draft pleadings, or memoranda prepared in anticipation of litigation;
  • information you are obliged to keep confidential under ABA Model Rule 1.6 (or the analogous rule of your licensing jurisdiction), including information relating to the representation of a client, regardless of whether otherwise privileged;
  • personally identifiable information of clients, opposing parties, witnesses, or third parties, unless fully de-identified;
  • trade secrets, sealed court filings, grand jury material, data subject to a protective order, or material subject to export controls (ITAR/EAR);
  • any information whose disclosure would breach a non-disclosure agreement, professional duty, regulatory obligation, or court order.

Use hypothetical facts, publicly available cases, or sanitized examples in every exercise. If in doubt, do not submit. You acknowledge this restriction before your first AI interaction, and we display a persistent reminder next to each AI input field.

6. Human Review Requirement

AI outputs can be inaccurate, incomplete, or outdated. You must independently review and validate all outputs before relying on them in any legal or business workflow. AI-generated feedback is a coaching signal only. It is not legal advice, not legal representation, and does not create an attorney-client relationship.

7. No Automated Decision-Making with Legal Effect

We do not use AI to make hiring, credit, licensure, disciplinary, or any other automated decision that produces legal or similarly significant effects concerning you within the meaning of GDPR Article 22. If you believe a Trazomo score has been applied to you incorrectly, contact [email protected] and a human will review it.

8. AI Literacy Statement (AI Act Article 4)

Trazomo is, by design, an AI-literacy tool for legal professionals. Our staff who deal with the operation and use of the AI systems on our behalf receive documented training appropriate to their role, their technical knowledge, and the context of use, consistent with Article 4 of the EU AI Act.

9. No Session Replay

We do not use session replay. Nothing records your screen, keystrokes, or the contents of any field, including AI input fields and the in-app Messenger. See our Cookie Policy for the full storage inventory.

10. US State Disclosures

For users in the United States, this disclosure also serves the AI interaction-notice requirements of the Colorado Artificial Intelligence Act (SB24-205, as amended by SB25B-004) and the Utah Artificial Intelligence Policy Act (SB 149). Because Trazomo feedback is educational and not an automated consequential decision, the additional deployer obligations that apply to "high-risk AI systems" under those laws do not apply to the Services.

11. Changes to AI Processing

We may update AI providers, model versions, retention defaults, and related controls over time. Material updates will be reflected in this disclosure and, where required, in our Privacy Policy, with a new effective date and version number.

12. Questions or Concerns

For AI-processing questions, contact [email protected]. You also have the right to lodge a complaint with your local data protection authority under GDPR, and to submit AI-related complaints to your national AI Act market-surveillance authority where such a body has been designated.