Permissions and data
What's shared and what's not, in plain language.
What Ehfina receives
When your AI assistant calls an Ehfina tool, only the specific data needed for that tool call is transmitted to Ehfina. For example:
- If you ask your assistant to record a dining experience, only the details of that specific experience (restaurant, date, your feedback) are sent to Ehfina.
- If you ask your assistant to find a restaurant recommendation, the tool assembles your preference context — but only what's needed for that specific request.
- If you state a preference directly, only that preference statement is transmitted.
What Ehfina does not receive
- Your ChatGPT or Claude conversation history
- Unrelated parts of your current conversation
- Your chat session metadata
- Information from other AI assistant sessions
- Your browsing history or location data
- Any data you haven't explicitly shared through a tool call
Tool-level data minimization
Each tool is designed to request and return only the minimum data necessary for its purpose. For example, the search_restaurants tool searches public restaurant data — it does not access your personal profile. The get_person_profile tool returns your taste profile but requires authorization that proves you own it or have been granted access to it.
Your controls
You can control what data Ehfina has access to by:
- Choosing what to tell your assistant (the assistant only shares what you tell it)
- Revoking the connection at any time (see data controls)
- Requesting deletion of your account and all data
- Withdrawing consent from any sharing arrangement
Who can see your data within Ehfina
Within Ehfina, your data is isolated to your account. Other Ehfina users cannot see your data unless you explicitly invite them into a sharing group and grant them access to specific parts of your profile. Ehfina enforces these permissions at the application level.
Back to documentation