What you log, and what you must not
You need prompts and completions to debug anything. They are also user content, sometimes personal, and now in three systems.
Debugging an AI feature without the actual prompt and completion is close to impossible, so you will log them, and the moment you do you are storing user content, potentially health details, financial information or someone name and address, depending on what they typed. That content is now in your logs, your traces and probably your eval dataset, each with different access and retention.
Decide the policy up front: what is stored, for how long, who can read it, and what is redacted before it lands. Redaction at write time is far cheaper than a deletion exercise later, and sampling, full payloads for a small percentage, metadata for everything, usually gives you what you need for debugging at a fraction of the exposure.
Then say so in the interface, in a sentence a person can read. If your feature sends content to a third-party provider, that is a fact users are entitled to know without opening a policy document, and telling them plainly costs you nothing and buys the trust that makes them willing to use it.
You should now be able to
- Decide a retention policy for prompts and completions
- Redact before storage rather than after an incident
- Tell users plainly what is sent and kept
Loading…