> Fetch the complete documentation index at: https://sopwow.com/llms.txt

---
title: "How SopWow Handles Client Data | SopWow"
description: "What SopWow records, what it never captures, what gets redacted in your browser, what AI models see, and what we do not claim yet. Plain answers."
url: https://sopwow.com/security
---

*Data handling*

# What happens to client data when SopWow records a workflow?

> **Quick answer:** Less than you might expect. The recorder captures which page, field, and button you used, plus screenshots of the recorded tab. It does not capture what you type into fields. Data with a recognizable shape, such as Social Security or policy numbers, is redacted in your browser before text goes to an AI model. Screenshots never go to an AI model. Redaction can miss things, so a person checks every SOP before approval. SopWow claims no SOC 2, HIPAA, or other certification.

This page is written for the person who has to say yes before anyone records a workflow with client data on screen: the agency principal, the practice manager, the firm's operations lead. It says what happens, where the gaps are, and what we do not claim.

## What does the recorder capture?

Only what it needs to write the procedure. During a recording, SopWow captures:

- **Element descriptors.** Which button you clicked, which field you used, which page you were on. This is how SopWow knows "the CSR opened the certificate screen and filled in the holder name field" without knowing what name was typed.
- **Screenshots of the recorded tab.** These build the visual step-by-step guide.
- **What you type into SopWow itself.** The short description of the task at the start, your answers to the AI's questions, and your edits in review.

Recording starts when you click Start recording and ends when you click Stop and generate SOP. A visible REC indicator shows which tab is being captured. There is no always-on capture.

## What does SopWow never capture?

| Never captured | Why it matters |
|---|---|
| Values typed into fields | The premium you entered, the patient's date of birth, and the account number stay out of the recording text. |
| Other browser tabs | Only the tab showing REC is recorded. Your email in the next tab is not. |
| Desktop applications | A desktop accounting program or a local spreadsheet is outside the recorder's reach. |
| Remote desktop and Citrix sessions | Work inside a remote session is not captured. |
| Camera or microphone | No video of you, no audio, no narration. |
| Paper and phone steps | Add them by hand in review if the procedure needs them. |

## How does redaction work, and what can it miss?

Redaction runs in your browser, before any text is sent to an AI model, an export, or the portal sync. It is pattern based: it looks for data with a recognizable shape and strips it.

It is built to catch identifiers such as:

- Social Security numbers
- Payment card numbers
- Policy numbers
- Email addresses
- Phone numbers
- Street addresses

Pattern-based redaction has a known weakness. It can miss data that has no recognizable shape. The usual cases:

- **Names in free text.** A client's name in a page heading, a note, or a button label reads like any other words.
- **Unusual ID formats.** A carrier's internal reference, a practice's own patient ID, or a firm's matter number may not match a known pattern.
- **Anything inside a screenshot.** Redaction works on text. A screenshot shows whatever was on the screen.

We do not describe redaction as full anonymization, and it is not a guarantee. It lowers exposure. The human redaction check in review is what closes the gap, which is why nothing is approved without one.

## What do AI models see, and what do they not see?

AI models see text: the element descriptors from the recording (redacted in your browser first), the task description you typed, and the answers you give to the AI's questions. That is what the writer needs to produce steps and decision points.

AI models do not see:

- **Screenshots.** Screenshots are never sent to any AI model.
- **Field values.** They are never captured in the first place.
- **Other tabs, desktop programs, or remote sessions.** They are never recorded.

Which model? SopWow is model-agnostic. By default, the writer uses a model SopWow manages. Your organization can instead bring its own API key for a model provider it chooses, and the redacted text then goes to that provider under your own agreement with it. The rules above are the same either way: redaction runs in your browser first, and screenshots are not sent.

One practical rule follows. Anything you type into SopWow yourself becomes part of the text the writer uses. When you answer a question, describe the rule, not the client. "If the policy has no additional insured endorsement, stop and route to the account manager" is useful. The insured's name is not. The Answer step is walked through on [how SopWow turns a recording into an SOP](https://sopwow.com/how-it-works).

## What happens to screenshots?

Screenshots are used to build the visual guide, and they stay in your workspace. They are never sent to any AI model.

Because redaction does not reliably reach inside images, a screenshot can show whatever was on the screen at that moment: a client name, a claim number, a balance. Treat screenshots as the part of the SOP most likely to carry client data, and look at every one during the redaction check. The simplest fix is upstream: record with a test record, so there is nothing sensitive on screen to begin with.

## What does the SopWow portal sync?

The portal syncs SOP titles, step counts, and usage metering. That is what powers your account and billing views: how many SOPs you have approved this month, and what they are called.

It does not sync document contents. Because titles do sync, keep client names out of SOP titles. "Issue a certificate of insurance for an additional insured" is a good title. A title with the insured's name in it is not.

## Is my content used to train AI models?

Not your content itself. SopWow does not use your SOP text, screenshots, recordings, prompts, or outputs as training input for models. It does not disclose or reuse your SOPs or your specific procedures for other customers.

What SopWow does use to improve the product is narrower:

- **Content-free usage signals**, such as how many drafts are approved or rejected.
- **De-identified data**, derived by generalizing and combining information across multiple customers so it does not identify you or reveal your specific procedures. It is used to improve SopWow, including training models and building the general SOP templates new users start from. SopWow will not try to re-identify it.

Enterprise customers can opt out of de-identified data from their content being used for model training by emailing privacy@sopwow.com. The exact wording is in the terms and privacy policy.

## What controls do you have?

Most of the control sits with the person at the keyboard.

- **What gets recorded.** You choose the task, the tab, and the record on screen. Nothing records until you click Start recording.
- **When it stops.** Click Stop at any time. If something sensitive appeared, reject the draft and record again with a test record. Rejected drafts and re-recordings are free.
- **The review gate.** Every claim the AI added stays flagged until a person keeps or removes it. Nothing is saved, shared, or billed as finished until a person approves it.
- **Export.** You own your SOPs and can export them in every format: visual guide, Word, Markdown, and PDF.
- **Retention and deletion.** On a paid plan, SOPs are kept while your subscription is active. After you cancel, you get 90 days of read-only access with export, then they are deleted. Free trial SOPs are kept for 60 days from signup, with warnings before deletion and a PDF export available the whole time. The full rules, and the sub-processor list, are in the [SopWow privacy policy](https://sopwow.com/privacy).

## What does SopWow not claim?

Plainly:

- **No certifications.** SopWow does not hold SOC 2, ISO 27001, or PCI certification, and does not claim HIPAA compliance, GDPR certification, or a BAA. Nothing here is "bank-grade".
- **Not a compliance tool.** SopWow writes down how your office does a task. It does not certify that a procedure complies with any law, regulation, carrier rule, or accreditation standard.
- **No guarantee on redaction.** It is pattern based and can miss data, as described above.

If your policy requires any of these, SopWow may not fit that workflow. Ask us before you record rather than after.

## How should regulated teams record workflows?

If your office handles protected health information, nonpublic financial data, privileged legal material, or anything else governed by a rule you answer for, start here:

1. **Contact us first.** Tell us what the workflow touches before anyone records it.
2. **Record in a training or sandbox account** where your system offers one. Some systems offer one; your vendor can tell you.
3. **Use test records.** A fake insured, a test patient, a dummy client file. The steps and decisions are identical; the data is not real.
4. **Keep client names out of titles and answers.** Titles sync to the portal, and your answers go to the writer.
5. **Do the redaction check properly.** Read every step and look at every screenshot before approving.

Medical office teams can read more on the page about [SopWow for medical office admin teams](https://sopwow.com/industries/healthcare).

## Frequently asked questions

### Does SopWow record what I type into forms?

No. The recorder captures which field you used, not the value you typed. Identifying data with a recognizable shape that appears elsewhere in the captured text is redacted in your browser before anything is sent.

### Are screenshots sent to an AI model?

No. Screenshots are never sent to any AI model. They build your visual guide and stay in your workspace.

### Is SopWow HIPAA compliant, or will you sign a BAA?

SopWow does not claim HIPAA compliance and does not offer a BAA. Teams handling protected health information should contact us before recording and should record with test patients in a training environment.

### Can redaction miss something?

Yes. It is pattern based and can miss names in free text, unusual ID formats, and anything inside a screenshot. That is why a person reviews every SOP, including a redaction check, before approving it.

### Who owns the SOPs?

You do. You can export every SOP in every format: the visual guide, Word, Markdown, and PDF. SopWow does not use your SOP text, screenshots, or recordings as training input, and it does not reuse your procedures for other customers.

### Which AI model does SopWow use?

SopWow is model-agnostic. You can use SopWow's managed model, or bring your own API key for a model provider you choose. Either way, text is redacted in your browser first and screenshots are never sent to any AI model.

## Ready to try it on a test record?

Record a task against a test client and see exactly what SopWow captures before you decide anything. Questions first are welcome too.

[Start free: your first 3 SOPs](https://sopwow.com/login) · [Ask a data-handling question](https://sopwow.com/contact)
