AI settings and sensitive data
What Settings → AI shows, which model runs Poppy and content generation, the fallback, your own API key, and how mail, Google, files and audience messages stay on OpenAI with no fallback.
Settings → AI shows what Poppy, AI posts, video scripts and the other AI features run on for your workspace right now. It reads the same routing the product uses, so what you see is what runs.
Active AI
| Row | What it means |
|---|---|
| Primary | The model your turns run on. On the platform key it uses your AI credits; on your own key it says "These turns don't use credits." |
| Fallback | Used automatically when the primary fails (rate limits, billing or key errors, outages, timeouts). None means failed calls are not retried elsewhere. |
| Platform default | Shown only when you use your own key: what the workspace would run on without it. |
| Sensitive data | The route for Google, mailbox, customer-message and request-file features: OpenAI only · No fallback. Unavailable means no OpenAI key is configured, so those features are off. |
| Embeddings | Indexes files attached to Delegated requests so Poppy can search them. |
On the platform keys, Pointerly runs on OpenAI as the primary provider and DeepSeek as the fallback. Both are listed on the Subprocessors page.
Sensitive data stays on OpenAI
Some data is more sensitive than your own links and stats, so it is handled separately:
- Google data (Gmail, Calendar, Drive, Sheets, Meet, Analytics) and YouTube analytics,
- connected mailboxes (Outlook, IMAP) and connected workspaces (Notion),
- files attached to Delegated requests,
- messages and comments from your audience (for example WhatsApp shopper messages).
AI features that read this data run only on OpenAI: on your own OpenAI key if you added one, otherwise on Pointerly's OpenAI account. They never go to DeepSeek and never fail over to another provider. If OpenAI is not available, the feature tells you so instead of using another provider.
Once a Poppy conversation has used sensitive data (an email, a calendar event, an attached file), every later turn of that conversation stays on OpenAI only.
Bring your own key
Under the provider cards you can save your own OpenAI or DeepSeek key. Keys are encrypted at rest and never shown again. Turns on your key do not use AI credits. With more than one key saved, the one marked In use runs. Pick a model for the provider, or leave the default.
A DeepSeek key never runs sensitive-data features; an OpenAI key can.
Common questions
Does Pointerly train AI on my data? Pointerly does not train its own AI models on your content. How OpenAI may use content sent through Pointerly's account is described in the Privacy Policy. To keep your content under your own agreement with OpenAI, add your own OpenAI key.
Why does Poppy say email or calendar is not available? OpenAI could not be reached, and these features never switch to another provider. Try again in a moment, and contact support if it keeps happening.
Why did a reply come from the fallback? The primary failed (a timeout, a rate limit, a key or billing error). Sensitive-data turns never use the fallback.
What Poppy can do
Poppy can explain these settings from this article. It cannot change your provider, model or keys: do that in Settings → AI.