Ask where your data is processed, not just where it's stored. They're different questions, and most security pages answer only the second. Storage is where a file sits at rest; processing is everywhere it travels to be worked on — and in an AI product, processing is where the interesting part happens.
I build one of these tools, so I know which question is comfortable to answer and which one isn't. This is the second kind. I'm not your lawyer and this isn't legal advice — it's the list of questions I'd want asked of us, written out so you can ask them of anyone.

Where it sits and where it travels are two different answers.
Why isn't "stored in Canada" the whole answer?
Because storage and processing can happen in different places, and a page can be entirely truthful about one while saying nothing about the other.
A product can store files on servers in one country and still send content elsewhere to be worked on — to a model provider, a transcription service, an analytics tool. Each of those is processing. "Stored in Canada" remains true throughout. It just isn't the answer to the question you were actually asking.
This is why I'd frame the request as a path rather than a location: walk me through where this content goes, step by step, from the moment I submit it to the moment I see the output. A vendor who can do that from memory has thought about it. A vendor who redirects to a compliance page has not.
What are the five questions?
1. Where is content processed at each step, by country? Not "in the cloud". Which steps, which jurisdictions. If any step leaves the country, which one and why.
2. Who are your sub-processors? The other companies involved in delivering the service. Many vendors publish a list; if one doesn't, ask directly. This is often the most informative document a vendor has, because it names everyone else touching the content.
3. What is retained at each step, and for how long? A number, and where that number is written down. "We don't retain anything" is a claim about one step; ask about all of them.
4. What leaves my device before anything is transmitted? In some designs, a meaningful amount of preparation happens locally — content can be reduced or stripped before it goes anywhere. That's a real difference, and it's worth knowing whether it applies.
5. Does the answer change on your enterprise tier? Sometimes processing arrangements differ by plan. Better to find that out now than after a procurement review.
What does a good answer sound like?
Specific, and slightly awkward.
Good answers name an exception, because almost every real architecture has one. A vendor telling you that everything happens in one country with no qualifications is either running an unusually simple product or hasn't looked closely. Neither is reassuring.
Here's ours, as an example of the shape rather than a claim you should accept from me: our documentation processing runs on edge infrastructure in Montreal. There is one step, in report drafting, where content transits a large-model provider outside Canada. Clients are aliased so we aren't holding direct identifiers, and content is encrypted in transit and at rest.
That single out-of-country step is the awkward sentence, and it's the one I'd want any vendor to volunteer rather than have you extract.

Almost every real architecture has an exception. A vendor who names theirs has thought about it.
Why does "Canadian" not settle it?
Because it's three separate claims wearing one word.
Who owns the company is a corporate fact. Where it's incorporated is a legal one. Where the servers sit is a technical one. All three can differ, and a marketing page that shows a flag is usually asserting the first while letting you infer the third.
Ask which of the three is being claimed. A vendor who distinguishes them without prompting is being careful with language, which is a decent proxy for being careful elsewhere.
Why does this land on me rather than the vendor?
Because that's how the accountability works, and it's the reason I'd rather you asked hard questions than took a badge at face value.
The Office of the Privacy Commissioner states plainly that "an organization is responsible for personal information in its possession or custody, including information that has been transferred to a third party for processing." Handing content to software doesn't move the obligation. You keep it, along with the job of having chosen well.
Which makes these five questions a form of due diligence rather than an interrogation. The vendors worth having will treat them that way. There's a wider set of criteria in how to choose documentation AI for a clinical practice, and the terms-of-service version of this exercise — finding out whether your content is used to improve a product — is in does an AI tool train on your client notes.
If you'd like to run all five at us, start here and then ask. I'd rather answer them than have you assume.
— Ian
