Skip to content

No consent management for AI providers #462

Description

@2witstudios

Problem

When users select cloud AI providers (OpenRouter, Google AI, Anthropic, OpenAI, xAI), there is no in-app consent dialog or disclosure that their prompts and conversation context will be sent to third-party services. The only mention is buried in the /privacy page.

Current State

What exists:

  • AI settings page (/settings/ai-api) allows configuring API keys and selecting providers
  • Model selector component for quick provider/model switching
  • Privacy policy page mentions third-party AI providers (lines 69-82)
  • API keys are encrypted with AES-256-GCM before storage

What's missing:

  • No consent dialog when a user first selects a cloud AI provider
  • No in-context disclosure when switching from local (Ollama/LM Studio) to cloud providers
  • No per-provider data processing acknowledgment
  • No clear indication in the chat UI which provider is currently processing messages
  • No granular consent for different data categories sent to providers

Impact

  • Users may not realize their workspace content is being sent to third-party services
  • Potential GDPR Art. 6/7 issues (lawful basis / consent for data processing by third parties)
  • Privacy policy disclosure alone is generally insufficient for informed consent

Proposed Solution

  1. Show a one-time consent dialog when a user first selects any cloud AI provider
  2. Clearly disclose what data is sent (prompts, context, page content used as tool context)
  3. Link to each provider's privacy policy from the consent dialog
  4. Show a persistent indicator in the chat UI for which provider is active
  5. Store consent timestamp per provider per user

Effort: Medium

References

  • AI settings UI: apps/web/src/app/settings/ai-api/page.tsx
  • Provider factory: apps/web/src/lib/ai/core/provider-factory.ts
  • Provider config: apps/web/src/lib/ai/core/ai-providers-config.ts
  • Model selector: apps/web/src/components/ai/ui/model-selector.tsx
  • Privacy policy: apps/web/src/app/privacy/page.tsx (lines 69-82)

Activity

  1. added a commit that references this issue on Feb 8, 2026
    5cfe6ce
  2. added a commit that references this issue on Feb 8, 2026
    ce7edcb
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions