Is Qwen Safe for Confidential Work?

Qwen is not one product with one confidentiality policy. The safety of confidential work depends on whether you use Qwen Studio, QwenCloud, Alibaba Cloud Model Studio, Qwen Code, a third-party provider, or a self-hosted Qwen model.

Verdict: Do not paste unredacted trade secrets, client documents, private source code, credentials, regulated personal data, or legally sensitive material into the standard Qwen Studio consumer service. QwenCloud and Alibaba Cloud Model Studio may be suitable for approved business workloads when configured and contracted correctly. A self-hosted Qwen model offers the greatest technical control, but only if your organization secures the infrastructure, runtime, logs, tools, and network.

Qwen Studio’s standard Terms state that User Content is treated as non-confidential and that Qwen has no confidentiality obligation unless a separate direct agreement says otherwise. Its Privacy Policy also describes using de-identified User Content and feedback to improve its services, including AI models.

By contrast, Alibaba Cloud Model Studio states that customer content is not used to develop or improve its models without separate consent. QwenCloud publishes additional API controls, including in-memory request processing, optional response storage, workspaces, API-key management, encryption, and audit logs.

Important: Technical security does not automatically create contractual confidentiality. Before processing genuine trade secrets or regulated data, obtain written approval from your security, legal, privacy, and compliance teams. This guide is not legal advice.

Try-Qwen-AI.com is an independent resource and is not affiliated with, endorsed by, or operated by Alibaba Group, Alibaba Cloud, QwenCloud, or the Qwen team.

Qwen Confidentiality Verdict at a Glance

Qwen access methodUse with confidential data?Practical verdict
Qwen Studio consumer appNo for unredacted confidential dataUse public, synthetic, or carefully sanitized information only.
QwenCloud real-time APIConditionallyPotentially suitable after contract review, data classification, retention configuration, access controls, and security approval.
Alibaba Cloud Model StudioConditionallyOffers stronger enterprise controls, but region, logging, permissions, contracts, and cross-border processing still require review.
Qwen CodeDepends on the provider and toolsQwen Code itself is not the only data recipient. The configured model provider, MCP servers, extensions, shell tools, and logs determine exposure.
Self-hosted Qwen weightsPotentially the safest optionOnly when the model runs in a controlled environment with no unauthorized network egress, secure logs, vetted dependencies, and restricted access.
Third-party Qwen website or APIUnknown until reviewedThe third party’s policies, logs, region, subprocessors, and retention rules apply.
Qwen Confidentiality Verdict

The same Qwen model can be low-risk in an isolated internal deployment and high-risk when accessed through a free public chatbot. The model name alone does not determine confidentiality.

Why “Is Qwen Safe?” Is the Wrong First Question

A more useful first question is:

Which Qwen service will receive the data, under which contract, in which region, with which retention, logging, access, and tool settings?

Five organizations can use the same Qwen model and create five different risk profiles:

  • One employee pastes a contract into Qwen Studio.
  • A company sends a pseudonymized document through QwenCloud with response storage disabled.
  • An enterprise uses Model Studio through a private VPC endpoint and restricted workspace.
  • A developer runs Qwen Code with a third-party API and several MCP tools.
  • A regulated organization runs official Qwen weights inside an air-gapped environment.

Those scenarios use Qwen, but they do not have the same data recipient, confidentiality terms, storage, network path, or access controls.

Confidentiality vs Privacy vs Security vs Compliance

ConceptQuestion it answersExample
ConfidentialityIs the recipient contractually required to protect the information from unauthorized disclosure?An NDA, enterprise agreement, or confidentiality clause.
PrivacyHow is personal data collected, used, shared, retained, and transferred?Processing employee records or customer identities.
SecurityWhat technical and organizational controls protect the system and data?Encryption, API-key controls, PrivateLink, access logs, and isolation.
ComplianceDoes the complete use case meet the organization’s legal and regulatory duties?GDPR transfer rules, healthcare requirements, financial regulation, or client contracts.

A service can use strong encryption but still lack a contractual duty to treat your prompt as confidential. It can promise not to train on data while still retaining it for a feature, log, security process, or legal obligation.

What Counts as Confidential or Sensitive Information?

Confidential work includes more than passwords. It may include:

  • Trade secrets and unreleased product plans.
  • Customer lists, contracts, proposals, and pricing.
  • Private source code, architecture diagrams, and vulnerability reports.
  • API keys, passwords, tokens, certificates, and private keys.
  • Financial statements, bank information, and payment details.
  • Employee records, CVs, performance reviews, and payroll data.
  • Medical, biometric, genetic, or health information.
  • Legal advice, litigation strategy, privileged communications, and investigation material.
  • Government, defense, export-controlled, or critical-infrastructure information.
  • Personal identifiers such as passport numbers, national IDs, addresses, and phone numbers.

Never send credentials or private cryptographic keys to any AI model. They should be removed rather than merely masked visually.

Is Qwen Studio Safe for Confidential Work?

No—not under the standard consumer terms for unredacted confidential information.

Qwen Studio can be useful for public research, general writing, brainstorming, translation, image creation, and sanitized documents. It should not be treated as a confidential enterprise workspace merely because an account is private or a conversation is not publicly visible.

Suitable Qwen Studio inputs include:

  • Public website copy.
  • Published documentation.
  • Synthetic examples.
  • Generic templates without customer details.
  • Documents that have been properly anonymized and approved.

Inputs that should not be submitted include:

  • Unreleased business plans.
  • Customer contracts or support tickets containing identities.
  • Private repositories or vulnerability details.
  • Medical, HR, legal, or financial records.
  • Credentials, keys, tokens, or internal URLs.

For a broader consumer-service assessment, see Is Qwen Safe?

What Qwen Studio’s Terms Say About Confidentiality

The current Qwen Terms of Service state that User Content is deemed non-confidential and non-proprietary, and that Qwen is not under an obligation of confidentiality unless another direct agreement provides one.

This does not mean that every prompt is publicly posted. It means the standard consumer terms should not be treated as an NDA or enterprise confidentiality agreement.

For trade secrets and contractually protected information, private account access is not enough. Your organization needs written terms that explicitly cover:

  • Confidentiality obligations.
  • Permitted processing purposes.
  • Data retention and deletion.
  • Subprocessors and data locations.
  • Incident and breach notification.
  • Audit rights and security commitments.

How Qwen Studio May Use User Content

The current Qwen Privacy Policy describes User Content as material users provide through the service, including text, files, images, audio, and video.

The policy also lists de-identified User Content and Feedback as data that may be used to improve the accuracy and quality of Qwen’s services, including its AI models.

Feedback deserves separate attention. When a user rates a response, the related conversation may be stored as part of that feedback. Do not submit a rating on a sensitive conversation without first considering what the feedback process captures.

I did not find a clear consumer control in the reviewed Qwen Studio interface documentation that provides a dedicated model-improvement opt-out equivalent to controls offered by some other consumer AI services.

For a detailed analysis, see Does Qwen Use Your Data for Training?

Where Qwen Studio Data Is Processed

Qwen’s current Privacy Policy states that covered personal data is stored or processed in Singapore and Mainland China. It also describes limited remote access by certain corporate-group entities in those locations under security and authorization controls.

This creates questions that organizations must assess before processing personal or confidential data:

  • Does the transfer comply with applicable privacy law?
  • Does the customer contract permit that processing location?
  • Are required transfer mechanisms and notices in place?
  • Has the legal team assessed government-access and jurisdiction risks?
  • Is the use compatible with sector-specific or procurement restrictions?

Do not infer a data location merely from your physical location or interface language.

Is QwenCloud API Safe for Confidential Work?

Potentially, but only under an approved enterprise configuration and contract.

QwenCloud’s developer documentation provides stronger controls than the free Qwen Studio consumer interface. These include:

  • TLS 1.2 or later for API connections.
  • AES-256 encryption for stored account information and API keys.
  • Workspace-specific API keys and permissions.
  • Key rotation.
  • Usage and audit logs.
  • Published security and compliance documentation.
  • Controls for response storage.

The QwenCloud Trust Center lists security certifications and attestation reports including ISO 27001 and SOC reports.

However, the public QwenCloud Customer Agreement also contains a provision treating User Content as non-confidential under the standard agreement. Zero-retention architecture and contractual confidentiality are not the same assurance.

For real trade secrets, require a separately negotiated agreement, DPA, confidentiality provision, or other written enterprise commitment approved by counsel.

QwenCloud Retention and store=false

QwenCloud’s current safety documentation states that normal API inputs and outputs are processed in memory during the request and are not stored in persistent storage after the response. Metadata such as token counts, timestamps, and request IDs may be logged for billing and rate limiting.

There is an important exception: the Responses API currently uses store=true by default and can store conversation data for 30 days. Set store=false when the application does not require stored response state.

import os
from openai import OpenAI

client = OpenAI(
    api_key=os.environ["DASHSCOPE_API_KEY"],
    base_url="https://dashscope-intl.aliyuncs.com/compatible-mode/v1",
)

response = client.responses.create(
    model="qwen3.7-plus",
    input="Summarize this already-redacted internal policy.",
    store=False,
)

print(response.output_text)

store=false is not a complete confidentiality control. It does not:

  • Create an NDA.
  • Redact sensitive data automatically.
  • Control logs created by your application or proxy.
  • Control third-party observability platforms.
  • Apply automatically to Batch API files, datasets, fine-tuning jobs, or other stored resources.
  • Protect against an exposed API key.

QwenCloud’s request-level audit logs currently retain operational data for 14 days. Review exactly what your own application, SDK, reverse proxy, APM platform, and debugging tools log as well.

QwenCloud Security Controls and Contractual Limits

ControlWhat it helps protectWhat it does not solve
TLSData moving between the client and APIUnsafe prompts, excessive permissions, or contractual gaps
Workspace API keysSeparating teams and environmentsKeys hardcoded in source code or shared between users
store=falseResponses API conversation retentionOther product storage or external logs
Audit logsUsage review and anomaly investigationWhether business content was authorized for disclosure
Content moderationProhibited or harmful contentTrade-secret classification or customer confidentiality
Compliance reportsVendor assurance and due diligenceYour organization’s own compliance responsibility

Do not use a QwenCloud personal account as a substitute for an organization-managed workspace with centralized key control, access termination, monitoring, and procurement approval.

Is Alibaba Cloud Model Studio Safe for Confidential Data?

It can be appropriate for approved enterprise workloads, but it is not automatically cleared for every category of confidential information.

Alibaba Cloud’s current Model Studio documentation and product terms provide several relevant commitments:

  • Customer data is not used for model training under the published service position.
  • Product terms state that Member Content is not used to develop or improve Model Studio models without separate consent.
  • Inputs and outputs are processed for the customer and on the customer’s behalf.
  • Workspace permissions can isolate data between business units.
  • Private network access is available in supported regions.
  • Monitoring and audit controls are available.

The Model Studio customer remains responsible for obtaining necessary rights and consents, complying with data-protection requirements, choosing the correct region, and configuring appropriate security controls.

Model Studio terms also explain that Member Content may be transferred, stored, and processed in countries where Alibaba Cloud, its affiliates, or subcontractors maintain facilities for the service. Cross-border processing must therefore be included in your review.

Model Studio Training, Encryption, Workspaces, and PrivateLink

ControlPublished Model Studio capabilityRecommended action
Model trainingMember Content is not used to improve models without separate consentRecord the applicable contract and do not grant optional consent without review.
EncryptionModel Studio documents AES-256 protection for transmitted application and training dataConfirm encryption scope and key-management requirements during vendor review.
Workspace isolationData can be isolated through separate workspaces and RAM permissionsCreate separate workspaces for production, development, and business units.
Private networkPrivateLink can route supported Model Studio API traffic over Alibaba Cloud’s internal networkUse a private endpoint where available and validate DNS, TLS, and security-group rules.
API keysKeys can be separated by account, user, workspace, and environmentUse least privilege, rotation, and a secret manager.
Knowledge basesKnowledge-base data is private to its workspace and not used to answer other usersRestrict membership and review uploaded documents.

PrivateLink currently supports private Model Studio access in Singapore and China (Beijing), while the official documentation states that US (Virginia) private access is not currently supported. Check the current regional page before designing the architecture.

Be Careful with Inference and Monitoring Logs

Logging can improve troubleshooting while quietly becoming a second copy of the confidential data.

Model Studio’s advanced monitoring can record the complete input and output of supported model calls after inference logging is enabled. That means prompts and responses may be visible to users with the required workspace and monitoring permissions.

  • Do not enable full prompt logging by default for sensitive workloads.
  • Restrict who can enable and view inference logs.
  • Redact logs before exporting them to SIEM or support systems.
  • Set a documented retention period.
  • Separate operational metadata from prompt content.
  • Test whether APM agents capture request bodies.
  • Do not copy full confidential prompts into tickets or public issues.

Turning off one provider-side log does not disable logs created by your application, load balancer, reverse proxy, SDK, browser extension, or observability vendor.

Is Qwen Code Safe for Proprietary Source Code?

Qwen Code can be used safely only when the model provider, permissions, tools, and local configuration are approved for that repository.

Official Qwen Code documentation states that Qwen Code itself does not use prompts, code, or responses for model training. Optional usage statistics can collect anonymous commands, performance metrics, feature usage, and crash information, but the configured AI provider still receives the model requests.

Authentication determines the applicable policy:

  • Qwen account authentication follows Qwen’s consumer terms and privacy policy.
  • Alibaba Cloud Coding Plan follows Alibaba Cloud terms.
  • A third-party API key follows that provider’s terms.
  • A self-hosted provider follows your own deployment controls.

Qwen Code also introduces risks beyond the model request:

  • File-reading tools can include repository content in the model context.
  • Shell tools can access local files, environment variables, and network resources.
  • MCP servers can send data to other services.
  • Extensions can add prompts, tools, and commands.
  • Subagents can use a different provider from the main session.
  • Tool-use summaries can send truncated arguments and results to a fast model.
  • OAuth tokens for MCP can be stored unencrypted unless encrypted file storage is enabled.

For confidential repositories:

  • Disable optional telemetry.
  • Use an approved enterprise or self-hosted provider.
  • Exclude secrets, credentials, production dumps, and private keys from model access.
  • Use sandboxing and explicit approvals.
  • Avoid YOLO-style automatic approval.
  • Allowlist MCP servers and individual tools.
  • Enable encrypted credential storage.
  • Review every generated change as untrusted code.

See Qwen Code Privacy and Telemetry for the configuration details.

Is a Self-Hosted Qwen Model Private?

A self-hosted model can keep prompts inside your environment, but “local” is not the same as “secure.”

Official Qwen weights can be deployed with frameworks such as Transformers, vLLM, SGLang, llama.cpp, Ollama, or LM Studio. When inference runs completely inside your controlled infrastructure, prompts do not need to be sent to Qwen Studio or an external model API.

However, data can still leave the environment through:

  • Telemetry from the runtime or surrounding application.
  • Web search, code execution, or external tools.
  • MCP servers.
  • Remote monitoring and crash reporting.
  • Cloud-hosted vector databases.
  • Automated model downloads and update checks.
  • Backups and centralized logs.
  • Employees with excessive file-system or administrator access.

A confidential self-hosted deployment should include:

  • Official model source and verified hashes.
  • Pinned model and dependency versions.
  • Network egress restrictions.
  • Authentication and role-based access.
  • Encryption at rest and in transit.
  • Secure prompt and output logs.
  • Vulnerability scanning.
  • Container or process isolation.
  • Patch, rollback, and incident-response procedures.
  • Human review of outputs and generated code.

See Qwen Cloud vs Local Privacy and the local Qwen deployment guides.

Third-Party Qwen Providers

A Qwen model served by another company follows that company’s policies and infrastructure.

Before sending confidential data through a third-party provider, verify:

  • The exact legal entity receiving prompts.
  • Whether it stores prompts or outputs.
  • Whether data is used for training or abuse review.
  • Data-processing locations.
  • Subprocessors.
  • Enterprise and consumer policy differences.
  • Security certifications.
  • Deletion and incident-notification terms.
  • Whether the provider logs request bodies.
  • Whether your selected plan includes a no-training commitment.

A Qwen logo does not prove that the request goes directly to Alibaba or Qwen.

Risks Beyond Model Training

A no-training promise addresses only one risk. Confidential data can still be exposed or misused through other paths.

Prompt injection

An uploaded document, web page, issue, or email can contain instructions designed to make the model reveal data or misuse tools. Treat external content as untrusted input.

Excessive tool access

An agent with file-system, database, shell, browser, email, or cloud permissions can expose more information than the prompt itself.

Application logs

Debug logs, traces, analytics, screenshots, support tickets, and APM tools can retain full prompts even when the model provider does not.

Hallucinated or unsafe output

A private model response can still be wrong. Confidentiality does not make an output legally, medically, financially, or technically reliable.

Human error

Employees may paste raw documents, expose API keys, use the wrong provider, enable logging, or share a conversation link without understanding the consequences.

Data Classification Matrix

Data classExamplesQwen StudioEnterprise APISelf-hosted
PublicPublished pages, public documentation, press releasesGenerally acceptableAcceptableAcceptable
Internal, low sensitivityGeneric internal templates, non-sensitive proceduresUse only after approval and sanitizationUsually appropriate under approved configurationAppropriate
ConfidentialClient contracts, private code, financial projectionsDo not submit unredactedOnly under enterprise contract and controlsPreferred when properly secured
Restricted or regulatedHealth records, credentials, biometrics, government secretsDo not useOnly if formally approved for that exact data categoryUse only in a specifically certified and governed environment

Your organization’s classification policy overrides this general matrix.

Use-Case Decision Table

TaskRecommended approachDo not include
Rewrite a public blog postQwen Studio or APIUnpublished campaign data
Summarize a client contractApproved enterprise API or self-hosted model after legal reviewNames and terms not required for the task
Generate code from a public exampleQwen Studio, Qwen Code, or APIPrivate keys and production credentials
Review a proprietary repositoryApproved Qwen Code provider or self-hosted model.env, secrets, customer dumps, production tokens
Analyze employee feedbackPseudonymized enterprise environmentNames, emails, IDs, and unnecessary free-text identifiers
Analyze patient recordsOnly an explicitly approved regulated environmentAny data outside the approved legal and technical scope
Draft merger strategySecure self-hosted or specially contracted environmentRaw party identities and undisclosed deal terms unless approved
Troubleshoot a production incidentUse sanitized logs in an approved environmentPasswords, session tokens, customer payloads, private URLs

A Safe Workflow for Confidential Work

  1. Classify the data. Public, internal, confidential, or restricted.
  2. Confirm authorization. Ensure you have permission to send the data to the selected service.
  3. Choose the correct access method. Avoid Qwen Studio for raw confidential data.
  4. Apply data minimization. Send only the information required for the task.
  5. Redact identities and secrets.
  6. Confirm the contract and region.
  7. Configure retention. Use store=false where applicable.
  8. Review logging. Provider logs, application logs, proxies, tools, and observability.
  9. Restrict access. Workspaces, least privilege, unique API keys, and key rotation.
  10. Disable unnecessary tools and connectors.
  11. Validate the output. Human review remains required.
  12. Delete temporary data. Remove files, stored responses, and logs according to policy.
  13. Record the decision. Model, provider, version, data class, and approval.
Safe Qwen Confidential Data Workflow

How to Redact Data Before Using Qwen

Replace real identifiers with consistent placeholders:

Before:
Customer: Acme Medical Ltd
Contact: [email protected]
Account ID: C-908821
Contract value: $840,000
Issue: Production API key sk-live-...

After:
Customer: [CLIENT_A]
Contact: [CONTACT_1]
Account ID: [ACCOUNT_ID]
Contract value: [VALUE_RANGE]
Issue: Production credential [REMOVED]

Redaction must remove information from the actual file or prompt. Covering text with a black shape inside a PDF may leave the underlying text extractable.

Qwen Confidential Data Redaction Guide

After receiving the output, restore identifiers only inside an approved internal system. Do not ask the model to map placeholders back to identities.

Enterprise Security Checklist

  • Approved vendor-risk assessment.
  • Signed enterprise agreement, confidentiality terms, and DPA.
  • Documented data-processing region.
  • Subprocessor review.
  • No-training commitment for the selected product and plan.
  • Defined retention and deletion behavior.
  • Workspace isolation and least-privilege roles.
  • Separate development and production API keys.
  • Secrets manager and regular key rotation.
  • Private network access where available.
  • Approved logging and redaction configuration.
  • Tool, plugin, MCP, and connector allowlist.
  • Prompt-injection testing.
  • Output validation and human approval.
  • Incident-response and data-deletion procedure.
  • Employee policy and training.
  • Periodic review when Qwen terms or models change.

Guidance for Legal, Healthcare, Finance, HR, and Software Teams

Legal teams

Do not upload privileged or client-confidential material to Qwen Studio. Assess confidentiality, privilege, client engagement terms, data location, retention, and vendor agreements before using an enterprise API.

Healthcare teams

Do not send identifiable patient information unless the complete service, contract, region, and workflow have been formally approved for that health-data regime. De-identification should be verified rather than assumed.

Finance teams

Exclude account numbers, payment credentials, material non-public information, fraud-investigation details, and customer-identifying transaction records unless the environment is expressly approved.

Human resources teams

Remove names and identifiers from performance reviews, complaints, compensation records, medical leave information, and candidate materials. Consider whether free-text comments can re-identify an employee.

Software teams

Use secret scanning before sending code. Exclude .env files, private keys, certificates, tokens, customer data, infrastructure credentials, and non-public vulnerability details. Treat generated code as untrusted until reviewed and tested.

What to Do After Accidental Disclosure

  1. Stop sending additional information.
  2. Identify exactly what was disclosed.
  3. Delete the conversation, file, stored response, or dataset where controls permit.
  4. Revoke and rotate any exposed credential immediately.
  5. Preserve necessary audit evidence without copying the sensitive content unnecessarily.
  6. Notify the organization’s security, privacy, or legal team.
  7. Assess contractual, regulatory, and client-notification duties.
  8. Contact the provider through a private support route when deletion or investigation is required.
  9. Document the cause and update controls to prevent recurrence.

Deleting a visible chat does not prove that every copy in backups, logs, feedback systems, or external observability tools has been deleted.


Frequently Asked Questions

Is Qwen safe for confidential company data?

Qwen Studio should not be used for unredacted confidential company data under its standard consumer terms. An approved QwenCloud, Alibaba Cloud Model Studio, or self-hosted deployment may be suitable after security, legal, retention, and access-control review.

Can I upload client documents to Qwen Studio?

Do not upload raw client-confidential documents. Use public or properly sanitized content, or move the workload to an enterprise environment governed by an approved contract and data-processing arrangement.

Does Qwen treat my prompts as confidential?

The standard Qwen Terms state that User Content is considered non-confidential and that no confidentiality obligation applies unless a separate direct agreement says otherwise.

Does Qwen use prompts to train its models?

Qwen Studio’s Privacy Policy describes using de-identified User Content and Feedback to improve services, including AI models. Alibaba Cloud Model Studio states that customer content is not used to develop or improve its models without separate consent. The answer therefore depends on the product.

Is QwenCloud safer than Qwen Studio?

QwenCloud provides API-specific security, workspace, retention, and audit controls that are more suitable for governed business use. It still requires contractual review, secure configuration, data minimization, and access control.

Does QwenCloud store API prompts?

Current QwenCloud documentation says normal inputs and outputs are processed in memory and are not persistently stored after the response. The Responses API is an exception when store=true; it currently stores conversation data for 30 days. Set store=false when storage is not required.

Does store=false make QwenCloud confidential?

No. It controls one response-storage behavior. It does not create confidentiality terms, remove sensitive data, secure your API key, disable external logs, or govern batch files and other stored product features.

Is Alibaba Cloud Model Studio suitable for sensitive data?

It may be suitable for approved enterprise workloads because it offers no-training commitments, workspaces, permissions, encryption, monitoring, and private-network access in supported regions. Your organization must still review contracts, region, cross-border processing, logging, and applicable regulations.

Can I paste proprietary source code into Qwen Code?

Only when Qwen Code uses an approved model provider and the repository, tools, permissions, telemetry, MCP servers, logs, and secrets have been reviewed. Do not expose credentials, private keys, production data, or restricted vulnerability information.

Does Qwen Code train on my code?

Qwen Code’s official documentation says Qwen Code itself does not use prompts, code, or responses for model training. The configured AI provider’s policy still governs the model request.

Is a local Qwen model completely private?

Not automatically. Local inference can keep prompts off a hosted API, but the runtime, external tools, telemetry, vector database, logs, backups, and network access can still expose data. A secure local deployment requires deliberate no-egress and access controls.

Can I use Qwen for legal documents?

Use only public or sanitized legal material in Qwen Studio. Privileged, client-confidential, or litigation material requires legal approval and an appropriately contracted and secured environment.

Can I use Qwen for patient or employee data?

Not through the consumer service with identifiable data. A regulated use requires a formally approved service, contract, region, access model, retention policy, and documented legal basis.

What information should never be sent to Qwen?

Never send passwords, API keys, private keys, authentication tokens, recovery codes, or other active credentials. Restricted government, health, financial, legal, or trade-secret data should be processed only in an explicitly approved environment.

Official Sources and Verification

Verification status: Qwen Studio’s confidentiality language, User Content practices, and processing locations were checked against its current Terms and Privacy Policy. QwenCloud retention, encryption, workspace, audit, and certification claims were checked against current QwenCloud documentation and its Trust Center. Model Studio’s training, processing, workspace, PrivateLink, and logging terms were checked against current Alibaba Cloud documentation and product terms. Qwen Code provider dependence, telemetry, tool access, and MCP credential controls were checked against current official Qwen Code documentation. The risk ratings and deployment recommendations are independent editorial analysis.

Last verified: August 22, 2026.

2 Comments

Leave a Reply

Your email address will not be published. Required fields are marked *