Compliance on a Anthropic project, end to end
The clauses are the visible part. What makes them worth having is that they keep matching the code after you stop paying attention.
It finds it without being told
AutomaticAnthropic resolves from its package, its endpoint or its credential name — so an integration with no SDK installed is found like any other.
Clauses, not a template
The disclosures Anthropic forces are assembled from a library built from published regulatory text, and filled in from the catalog row rather than from a guess about what the vendor does.
Every clause explained
Beside each one, in plain English: what it means, why your product needs it, and which detected component put it there — with the file and line it was proved from.
It notices when this changes
DriftLater scans are diffed against the snapshot your documents were generated from, so removing Anthropic or adding something beside it becomes an update you approve.
Delivered where you work
As a pull request on a connected Git host, as an approval in the dashboard, or from your editor over MCP — the same six tools your agent can call without opening a browser.
Read in memory, not retained
The files a scan reads are processed in memory and dropped when the request ends; what is kept is the list of services it found. The MCP server goes further and scans on your own machine.
How Poliogo proves Anthropic is there
Detection is pattern matching over what is literally in your repository — dependency manifests, source files, configuration, edge functions and `.env.example` — not a model's opinion about your code. Anthropic resolves from any of the signatures below, so an integration written as a bare `fetch` with no package installed is found exactly like one with an SDK.
- ✓Detected three different ways — the api.anthropic.com endpoint, the @anthropic-ai packages, and a bare claude- model identifier in configuration — because one vendor reached three ways is still one sub-processor row.
- ✓The generated clause states that Anthropic does not train on data submitted through its API, and that inputs and outputs are retained up to 30 days unless a shorter term is agreed.
- ✓Anthropic, PBC processes in the United States, so an EU product owes a transfer clause for it whether or not it has any other American sub-processor anywhere in the stack.
What Anthropic changes in your documents
Anthropic processes your users' prompts — this adds AI transparency and retention notices. User data sent to an AI provider needs training, retention and automated-decision disclosures. That is why Anthropic moves your Privacy Policy — and it is the same sentence the Updates page shows when a scan finds it for the first time, because both are read from one place.
- ✓Privacy Policy — regenerated and shown as a diff before anything is published.
Training and retention: what Anthropic publishes
The EU AI Act asks you to say that an AI system is in use, and GDPR Article 22 asks whether a decision about somebody was made by a machine. Neither question is answered by naming the vendor, so the generated disclosure states the provider's published position rather than a reassuring paraphrase of it.
- ✓Training — Anthropic does not use data submitted through its API to train its models.
- ✓Retention — API inputs and outputs are retained for up to 30 days unless a shorter term is agreed.
- ✓Both sentences are drawn from the provider's own published terms, and both are shown to you before a word is published.
Anthropic in your sub-processor schedule
A sub-processor schedule names the legal entity, not the brand — Anthropic, PBC rather than "Anthropic" — because that is the name a customer's data protection agreement is checked against. The row below is what Poliogo generates and what your Trust Center publishes.
| Field | Value |
|---|---|
| Legal entity | Anthropic, PBC |
| What it receives | Prompts, uploaded files, conversation history, generated output |
| Purpose | Generating text and analysing user content |
| Processing location | United States |
| Their privacy policy | www.anthropic.com/legal/privacy |
Generated from the catalog entry, and published on your Trust Center alongside every other sub-processor a scan found.
Getting this onto a Anthropic project
Nothing is written or published until you have seen it. The scan proposes, you approve, and only then does anything reach your repository or your live pages.
Connect the repository, the host or the live address. The scan reads manifests, source, configuration and `.env.example` in memory and keeps the list of services it found, not the files it read.
A plain-English list of every service the scan proved, Anthropic among them, each with the file and the line it was found on. Correct anything wrong before a word is generated.
Privacy Policy, Cookie Policy and Terms, with the clauses Anthropic forces already in them, and a plain-language explanation beside each one saying which detected component put it there.
Later scans are diffed against the snapshot your documents were generated from, so a service added next month becomes an update you approve rather than a quiet inaccuracy nobody notices.
Questions people ask
Does Poliogo detect Anthropic on its own?
Yes. Anthropic resolves from the signatures in the detection library — the package name, the endpoint it is called at, and the credential name it uses in `.env.example`. Matching on the endpoint is the part that matters: an integration written as a bare `fetch` with nothing added to package.json is still found, and that is the case a dependency-only scanner misses entirely.
What does Anthropic actually receive from my users?
Prompts, uploaded files, conversation history, generated output — for generating text and analysing user content. That list is not written for this page: it is the catalog row the generated Privacy Policy prints, so what you read here is what your document will say, down to the categories.
Do I have to list Anthropic as a sub-processor?
If it processes personal data on your behalf, yes — and the row names Anthropic, PBC, the legal entity, rather than the brand, because that is the name a customer's data protection agreement is checked against. Poliogo generates the row and publishes it on your Trust Center alongside every other sub-processor a scan found.
Where does Anthropic process the data?
United States. That matters for the transfer clause rather than for the vendor list: an EU product sending personal data to a US processor owes a transfer disclosure whether or not anything else in the stack is American. The generated clause names the location from this same row rather than assuming one.
Does Anthropic need anything in my cookie banner?
Not on its own — the catalog carries no cookies for Anthropic, so it appears in your Privacy Policy and your sub-processor schedule rather than in the cookie table. Services are classified one at a time from what they actually set, which is why a product can owe a long sub-processor list and still have a short banner.
What happens when I add another service later?
A scan has to run first — manually on any plan including Free, or on your plan's schedule from Starter. When one finds a service your documents do not mention, the change arrives as a proposal with a plain-language diff: what changed, why, and which detected component triggered it. On a connected Git host it can also arrive as a pull request on a side branch, so changes reach your default branch only through a pull request you approve.
Is any of this legal advice?
No. Poliogo reads code and assembles clauses from a library built from published regulatory text; it does not weigh your circumstances, and no generated document settles whether a business is compliant — that turns on how the business actually handles data. What the product is for is making sure the documents describe what the software genuinely does, which is the part that goes stale on its own and the part a person cannot check by hand every week.
Compliance for the rest of your stack
See what a scan finds in your Anthropic project
Connect it and read the list before anything is generated. Free plan, no credit card, nothing published until you approve it. Poliogo automates the reading and the drafting, not the judgement — it is not a law firm and this page is not legal advice.
Start free — no credit cardPoliogo is an automated code analysis and document display tool, not a law firm. Poliogo does not provide legal advice, representation, or guarantees of statutory compliance, ADA/WCAG certification, or legal immunity. Visual banners and generated documents are advisory tools and do not substitute for professional legal review.