Can AI Feedback Include System-Added Prompts And Hidden Context?
Yes. Depending on the product and permissions, AI feedback can include prompt rewrites, chat history, files, hidden context, model settings, and diagnostic logs.
title: "Can AI Feedback Include System-Added Prompts And Hidden Context?" slug: "can-ai-feedback-include-system-prompts-hidden-context" excerpt: "Yes. Depending on the product and permissions, AI feedback can include prompt rewrites, chat history, files, hidden context, model settings, and diagnostic logs." meta_title: "Can AI Feedback Include Hidden Prompts And Context?" meta_description: "AI feedback may include prompt rewrites, chat history, files, system-added context, model settings, and logs. See what to check before you submit." tags: - AI feedback privacy - hidden prompt context - Microsoft Copilot feedback - Claude feedback data status: published published_url: "https://openveil.app/blog/can-ai-feedback-include-system-prompts-hidden-context" published_at: "2026-08-03" post_id: "88841430-112f-4785-babc-886a9ff42c1d"
Yes. An AI feedback submission can include much more than the one answer you rated. Depending on the product, account type, administrator policy, and choices in the feedback form, the bundle may include your original prompt, system-made prompt changes, the actual prompt sent to the model, earlier chat turns, files or retrieved content, model settings, and diagnostic logs.
That does not mean every thumbs-up or thumbs-down automatically sends every hidden instruction. The important privacy question is not simply, "Did I rate this answer?" It is: What data will this product attach when I finish and submit the feedback report?
Who This Guide Is For
This guide is for people who:
- use Microsoft 365 Copilot, Claude, ChatGPT, or another hosted AI assistant
- rate AI answers that contain client, business, personal, or research context
- work with files, projects, connectors, custom instructions, memory, or search
- administer feedback policies for a company or school
- turned off routine model training and assume that choice also covers feedback
- want a privacy-focused AI chat workflow with clearer history boundaries
The short lesson is simple: a rating icon is an interface element, not a complete data-flow description. Read the submission screen and the product's current documentation before treating feedback as a one-bit signal.
What Is Confirmed
Microsoft and Anthropic both document feedback paths that can include context beyond the visible answer.
Microsoft's current Copilot feedback documentation says that, with permission, a submission may collect:
- the prompt the user entered
- modifications Copilot made to that prompt
- the actual prompt sent to the large language model, including Microsoft proprietary content
- chat history
- files or other content used to formulate the answer, including content not shown or referenced in the final response
- intermediate responses, prompt suggestions, and citations
- additional logs that may contain file contents, names, email addresses, IP addresses, or other personal data
Microsoft also says the extra data is not collected until the user submits the report. Work and school administrators can control whether content samples are available, and Microsoft tries to provide preview links when possible. The same page says an organization's administrator can view submitted feedback and collected content samples except for Microsoft proprietary content.
Anthropic's current model-training and feedback notice says thumbs feedback stores the entire related conversation, including content, custom styles, conversation preferences, and model settings, for up to five years. It says raw content from connectors, including remote and local MCP servers, is excluded unless that material was copied directly into the Claude conversation. Anthropic may use the feedback for research, service analysis, and model training as permitted by law.
These are product-specific disclosures. They prove that some feedback systems can carry hidden or surrounding context. They do not prove that every AI product sends the same fields.
What Is Still Unclear
Several questions remain product-, version-, and submission-specific:
- A feedback form may say that it includes content samples without listing every field in the current bundle.
- A system may collect a transformed prompt without exposing the full proprietary instruction text in the preview.
- A product can change its feedback interface, default policies, or retention terms after this article is published.
- Organization administrators may disable some collection paths while allowing a basic rating or written comment.
- Connector content may be excluded by one provider but included by another, or copied into a chat before the feedback event.
- The term "system prompt" is used loosely. A final model request can contain policy instructions, product instructions, tool definitions, retrieved documents, conversation history, and other context that are not all one field.
For those reasons, the defensible answer is not "every feedback button sends the secret system prompt." It is: feedback can include system-added and non-visible context, and the exact payload must be checked for the specific service and submission.
The Seven Layers That May Sit Behind One Rated Answer
Use this seven-layer map before submitting feedback about a sensitive interaction.
| Layer | What it can contain | Why it matters |
|---|---|---|
| 1. Visible response | The answer you rated, citations, intermediate messages | This is the part most users expect to share |
| 2. Visible user prompt | The text or voice-transcribed request you entered | It may contain names, identifiers, or confidential facts |
| 3. Prompt modifications | Rewrites, metadata, prompt-template references, or system expansions | The model may have received a different representation from the text you saw |
| 4. Product instructions | System messages, safety rules, tool definitions, or proprietary instructions | These can explain the answer even though the user did not type them |
| 5. Conversation context | Earlier turns, summaries, memory, profile instructions, project instructions, or style preferences | A harmless-looking current turn may depend on older sensitive details |
| 6. Retrieved content | Files, emails, web results, connector data, or document excerpts | Relevant evidence may never appear verbatim in the final answer |
| 7. Logs and metadata | Errors, app state, device details, names, addresses, IP data, or file fragments | Diagnostic material can reveal data outside the visible conversation |
This framework also explains why a feedback report can be useful to engineers. If an answer was wrong because the assistant retrieved the wrong file, rewrote the prompt badly, or failed inside a tool, the visible response alone may not reveal the cause. The same context that makes debugging possible can also increase the privacy scope of the submission.
Microsoft Copilot: The Clearest Hidden-Context Example
Microsoft's documentation is unusually explicit about the gap between the prompt a user sees and the context a feedback report may include.
The Copilot feedback page distinguishes the original user prompt from modifications made by the Copilot system and from the actual prompt sent to the model. It separately lists chat history and files or content used to formulate the answer, including material that was not shown or cited in the final response.
That distinction matters in a work account. Imagine asking Copilot to summarize a project risk in one sentence. The visible answer may contain no customer name. The model may still have used earlier conversation turns, a spreadsheet, a presentation, a retrieved email, or an internal document passage. If the feedback bundle includes relevant content samples, the rated sentence is not the only sensitive object in scope.
Microsoft's broader feedback overview says content samples can include portions of customer documents or AI interactions, while logs may include a user's name or file contents. It also states that users choose whether screenshots, attachments, content samples, and logs are submitted when the corresponding policies allow them.
For organizations, the feedback policy controls separate the ability to submit feedback from the ability to include screenshots, attachments, log files, and relevant content samples. That is the right administrative model: do not treat "feedback enabled" as one indivisible switch.
There is also a material exception. Microsoft's current documentation says U.S. government Microsoft 365 environments do not collect diagnostic logs, prompts, responses, screenshots, attachments, or user files through this feedback configuration. The payload therefore depends on the environment, not only the product name.
Claude: The Whole Related Conversation Can Matter
Claude's disclosure creates a different but equally important lesson.
Anthropic says a thumbs feedback report can store the entire related conversation, including custom styles, conversation preferences, and model settings. Its personalization guide explains that account-wide instructions, project instructions, and styles can shape responses in different scopes.
That means the answer you rate can be influenced by context that is easy to forget:
- account-wide instructions applied to every conversation
- project instructions that apply only inside one project
- a custom style built from uploaded writing samples
- model or conversation settings selected earlier
- prior turns that make a short current prompt understandable
Anthropic's connector exclusion is a useful boundary, but it should be read precisely. The company says raw connector content is not part of feedback data. It also says connector material can be included when it was copied directly into the conversation. A connector exclusion is therefore not a guarantee that no connected-source information appears anywhere in the submitted chat.
Team and Enterprise owners can use Anthropic's Rate chats setting to disable thumbs feedback for the organization. That is separate from ordinary retention, connector access, and other data controls.
Is Feedback The Same As Routine Model Training?
No. Training defaults and feedback exceptions are separate controls.
Microsoft says it does not use Microsoft 365 Copilot feedback to train the foundation models used by Copilot with Microsoft 365 apps. It still uses the feedback to improve Copilot, debug issues, and prioritize product changes.
Anthropic says feedback may be used for research and model training, even where other commercial-data defaults differ. OpenAI's current model-improvement policy similarly says business and API inputs are not used for training by default, while API customers can explicitly opt in to share data through mechanisms such as Playground feedback.
The practical rule is the same one explained in Can Submitting AI Feedback Override Your Training Opt-Out?: a routine training setting does not automatically describe a voluntary feedback path.
Also keep deletion separate. Removing the original chat may not remove a feedback copy already created under a different retention rule. See Does Deleting An AI Chat Delete A Submitted Feedback Copy? for that cleanup boundary.
A Safer Feedback Checklist
Before submitting feedback about a sensitive AI interaction, run this checklist.
1. Pause After The Rating
Some products record the initial rating separately from the later report. Microsoft says no additional data beyond the initial thumbs choice is collected until the user submits the feedback. Do not click through the final step automatically.
2. Read The Payload Description
Look for references to:
- conversation or chat history
- content samples
- actual or transformed prompts
- files, attachments, or screenshots
- logs or diagnostics
- model settings, styles, preferences, or instructions
- connector or tool data
If the interface offers a preview, inspect it. If it says some data cannot be previewed, treat that as an unresolved scope, not as proof that the hidden portion is harmless.
3. Check Earlier Turns
The rated answer may be safe while the conversation contains a secret, client name, medical detail, source code, financial number, or personal identifier several turns earlier. A whole-conversation feedback rule makes those older turns relevant.
4. Check Files And Retrieved Sources
Ask what the assistant used, not only what it quoted. A source can influence an answer without appearing in the final response. If the product permits content samples, a file passage may enter the diagnostic bundle.
5. Separate Product Controls
Check feedback, model improvement, chat history, memory, connector access, and deletion independently. Turning one off does not establish the state of the others.
6. Use A Minimal Reproduction When Possible
If the issue can be reproduced without real customer data, create a clean test conversation with synthetic names and values. Submit that report instead of attaching the original sensitive thread.
7. Use Administrator Policies
Organizations should decide whether users may submit:
- basic ratings
- written comments
- screenshots and attachments
- prompts and responses
- content samples
- diagnostic logs
The safest useful setting may be different for a marketing team, a legal department, a medical organization, and a software-development group.
What This Does Not Mean
This article does not prove that:
- every AI rating sends an entire conversation
- every provider exposes or stores its full proprietary system prompt
- Microsoft 365 Copilot feedback trains Copilot's foundation models
- all connector contents are included in Claude feedback
- diagnostic logs always contain sensitive data
- disabling feedback prevents normal active-request processing
- a privacy-focused chat product makes it safe to paste any secret into any prompt
It also does not mean feedback is inherently bad. High-quality reports help providers find errors, accessibility problems, safety failures, and broken retrieval paths. The goal is informed submission: share enough to explain the problem without unknowingly sharing a much larger sensitive context.
Where OpenVeil Fits
OpenVeil is a paid, privacy-focused hosted AI chat workspace with browser-local chat history and no server-side chat-history record for normal private chat sessions. That can reduce the normal long-lived account-history footprint for users who want a narrower alternative to mainstream assistants.
The boundary still matters. Active requests may be processed by OpenVeil and necessary AI, search, upload-processing, hosting, routing, security, billing, and infrastructure providers. OpenVeil is not fully offline, does not promise zero logs, and is not a shield against every feedback, file, connector, or diagnostic-data risk in other products.
If your priority is avoiding a normal server-stored transcript while keeping hosted web search, uploads, voice, and image tools, review the OpenVeil privacy policy and compare that model with the feedback and retention controls of the assistant you use today.
FAQ
Does A Thumbs-Down Send Only The Response I Rated?
Not necessarily. Microsoft documents optional collection of prompt changes, actual model prompts, chat history, files or content used for the answer, and logs. Anthropic says thumbs feedback stores the entire related conversation plus styles, preferences, and model settings. Check the specific product's submission screen and policy.
Can AI Feedback Include A System Prompt?
It can include system-added prompt material. Microsoft says Copilot feedback may collect prompt modifications and the actual prompt sent to the model, including Microsoft proprietary content. That does not establish that every provider sends or exposes its complete proprietary system prompt in every feedback report.
Can Feedback Include A File That Was Not Cited In The Answer?
Yes, in some products. Microsoft says relevant content samples may include files or other content used to formulate the response even when that material was not shown or referenced in the final answer.
Can AI Feedback Include Earlier Chat Messages?
Yes. Microsoft lists chat history as a possible relevant content sample. Anthropic says it stores the entire related conversation when thumbs feedback is submitted.
Does Turning Off AI Training Disable Feedback Collection?
Do not assume it does. Feedback is commonly governed by a separate control and can follow separate use and retention rules. Check both settings.
Can My Employer See Feedback I Submit From A Work Account?
It depends on the service. Microsoft says organization administrators can view Microsoft 365 feedback, including user identity and collected content samples that do not contain Microsoft proprietary content. Administrators can also configure or disable feedback data paths.
What Is The Safest Way To Report A Sensitive AI Bug?
Reproduce it in a new conversation with synthetic data, inspect the feedback payload, remove unnecessary attachments, and submit only the minimum context needed to demonstrate the problem. If you cannot determine the payload, use a separate support channel approved by your organization.
Bottom Line
AI feedback can include hidden and surrounding context, not just the answer under the rating icon. The clearest documented examples include prompt rewrites, actual model prompts, chat history, files not shown in the response, entire related conversations, styles, preferences, model settings, and diagnostic logs.
Treat feedback as a deliberate data-sharing event. Preview what you can, minimize sensitive context, separate feedback controls from training and deletion settings, and use a clean synthetic reproduction whenever the original conversation contains information you would not knowingly submit for review.