HubSpot, Breeze and customer information

Research date: 4 October 2026
Edition: First HubSpot baseline report
Method: Review of HubSpot's public documentation. No signed-in business account was inspected and no controls were tested in a live account.

Summary

HubSpot documents several AI access settings as on by default. Its AI can operate through staff assistance, customer conversations and workflows.

  • By default: Generative AI, Breeze Assistant, CRM access and conversation access are documented as on. Files access is off. Eligible customer-data model training is also on, except for accounts with Sensitive Data enabled.
  • Beyond the default: File access, Customer Agent, custom agents, selected actions and automated workflow execution.
  • Outside HubSpot: Custom agents can use external connections. Separately authorised external AI services can access HubSpot information. Enrichment uses public sources, other providers and HubSpot’s commercial dataset; website tracking can contribute through another data-sharing route.
  • Business exposure and learning: CRM access can include contacts, deals, tickets and notes; conversation access includes emails, chats and call material. Agents can have separate read and edit permissions. Turning training off stops future eligible training use, but does not remove previous learning or disable enrichment and tracking.

The main exposure: Several information-access and learning settings begin enabled, while external connectors, enrichment and tracking remain separate choices.

Business finding

A business can disable generative AI, restrict information access and opt out of HubSpot's model training. These are separate choices. Enrichment, customer agents, automated processes and external connections also need their own checks. This review did not establish one switch that stops every form of AI processing throughout HubSpot. [1][2][3]

HubSpot is a customer relationship management service, often shortened to CRM. For a business, the information involved can include customer details, sales opportunities, emails, support requests and records of conversations. The assessment therefore concerns both how staff use AI and what AI can do with information about other people.

Where is AI operating?

Everyday assistance: Breeze Assistant and embedded tools help draft content and summarise information. AI can appear within marketing, sales and support work rather than only in a separate chatbot. [4]

Customer service: Customer Agent answers customer questions using selected business content. It can also be configured to perform actions. Its published availability includes qualifying Professional and Enterprise subscriptions and requires HubSpot Credits for deployment. [5]

Automated work: Custom agents can analyse information, generate outputs and take selected actions. They can run through workflows, so an employee need not open an AI conversation each time they operate. [6]

Less visible functions: HubSpot identifies AI models behind duplicate-record detection, search, business-card scanning, sales forecasts and predictions about sales opportunities. Turning off generated text should not be treated as proof that these functions stop. [2]

Enrichment: HubSpot can add or refresh contact and company information using its commercial dataset, other providers and public sources. This is a separate data-use route, whether or not staff use Breeze Assistant. [3]

Who controls it?

HubSpot requires Super Admin permissions to manage the account's AI settings. This means a person with the highest administrative access, rather than any employee who can use the CRM. [1]

User permissions also govern access to individual features. Some agents have separate settings controlling who can edit or run them. The business should identify the person responsible for each deployed agent and each connection to another service. [4][6]

Record the subscription, accounts, authorised administrators and operational owner. If an outside agency manages HubSpot, establish who in the business can require a change and who can actually make it. An instruction to stop is useful only if someone has the necessary access.

What can the business switch off?

Account-level generative AI

As a Super Admin, open Settings → Account management → AI → Access.

  • Set Give users access to generative AI tools and features to Off.
  • Review Give users access to Breeze Assistant separately.
  • Review the CRM data, Customer conversation data and Files data switches.

HubSpot documents generative AI, Breeze Assistant, CRM access and conversation access as on by default; files access is off by default. Check the actual saved settings rather than assuming an existing account matches those defaults. [1]

Customer Agent

To stop new assignments, HubSpot documents Account & Billing → Usage & Limits → Credit Agent usage, where the agent switch can be turned off. It says the agent continues existing threads until they are resolved. [7]

To remove a channel assignment, use Service → Customer Agent → Deploy → Channels, then Remove for the relevant channel. Check chatflow fallback settings too: some assignments are controlled there. [7]

Enrichment and other automation

Review Settings → Data Management → Data Enrichment → Settings. Disable the automatic and continuous enrichment options the business does not want. Separately remove users' Data enrichment access permission. [8]

HubSpot says Super Admins can still enrich records manually. Stopping enrichment completely therefore also requires them to stop doing so. Previously added information remains in the CRM. [3]

Inspect workflows and agents individually. A business should not assume disabling an employee's assistant access stops processes already configured to run automatically.

What information and actions can the business restrict?

Information or capability Relevant restriction
CRM records Account data controls cover information such as contacts, companies, deals, tickets and notes. [4]
Customer conversations A separate category covers emails, chats, call recordings and transcripts. [4]
Files and documents Review files access and material supplied directly as agent knowledge. [4][6]
Customer Agent record access Its permissions can distinguish viewing a contact property from editing it. [9]
Custom-agent actions Select the actions and knowledge available to each agent, including CRM reading, CRM writing and external connections. [6]

For Customer Agent, use Service → Customer Agent → Define → Permissions. Review each selected property and its View property and Edit property settings. HubSpot documents separate identity checks: matching an email address or sending a verification link. The business should choose and test the appropriate check before allowing customer information to be disclosed or changed. [9]

For custom agents, inspect the action list as well as the instructions. An instruction saying “only summarise” should not be treated as evidence that writing access has been removed. This is a proposed business check, not a claim that an instruction will necessarily be ignored.

External AI connectors can give other services access to HubSpot information. Review these connections separately; this research did not establish that HubSpot's internal AI switches disable every independently authorised connector. [4]

Human support

Customer Agent's handoff settings can transfer a customer immediately, arrange later follow-up or keep the AI assigned without transferring to anyone. Review Service → Customer Agent → Train → Human handoff. [10]

Test that requests for a person reach someone able to help, including outside business hours. A configured transfer is not evidence that an employee is available or that the complaint has been resolved.

Can the business refuse use of its information for training?

Yes. A Super Admin can turn AI Model Training off under Settings → Account management → AI → Access. HubSpot says this covers eligible customer data in that account, stops future training use and does not remove access to AI features. The default is on; accounts with Sensitive Data enabled are automatically excluded and cannot opt in. [2]

HubSpot also says previously used information cannot be removed from trained models. The opt-out applies going forward. Configure it separately for each account. [1][2]

HubSpot's own model training differs from processing by its AI service providers. HubSpot says those providers cannot train their models on customer data and that it seeks zero retention wherever possible. “Wherever possible” should not be read as a guarantee that every provider retains nothing. [11]

Enrichment remains a separate choice. HubSpot's training guidance expressly says turning training off does not turn enrichment off, or vice versa. To stop both activities, address both sets of controls. [2][3]

Website tracking needs another check. HubSpot's terms identify tracking-code information as a source for its commercial dataset, and distinguish Intent data sharing from enrichment. Review that preference separately; a current universal menu path was not established in this review. Switching off Breeze should not be treated as switching off website tracking. [13]

Individuals can also request removal of their professional information from HubSpot's enrichment dataset. That request does not delete an existing contact or previously enriched information from the business's own CRM. The business still needs to decide how to handle that information and any associated request. [12]

How can the business check that its choices worked?

The following are proposed business checks, rather than claims of testing completed for this report:

  1. Record the accounts, subscriptions, switches, administrator and date of each change.
  2. Reopen settings and check the saved state. HubSpot says training-toggle changes are logged in audit logs. [1]
  3. Test relevant employee accounts with harmless records. Check both feature access and whether enabled tools can retrieve restricted information.
  4. Inspect each agent's permitted actions, knowledge and workflow triggers. Test whether it can still change a test record after writing access is removed.
  5. For Customer Agent, check new enquiries and existing threads separately after switching it off. Verify that human handoff reaches the intended person. [7][10]
  6. Review enrichment activity under Data Enrichment → Activity and investigate new changes after disabling automatic enrichment. Check workflow enrichment too: its overwrite behaviour can differ from general mapping rules. [8]
  7. Review external connections and the information they can still retrieve.

A setting or missing button provides evidence about access controls. It does not independently prove the complete absence of background processing. This review found no public business-account test establishing that all HubSpot AI processing has stopped.

What does the business lose, retain or need to replace?

Disabling generative assistance means staff may need to draft, summarise and review material themselves. Removing customer-agent assignments requires sufficient people and working processes to handle incoming enquiries. Restricting agent actions reduces automation but can retain assistance within the permissions left available. [5][6]

Stopping enrichment leaves the business responsible for collecting and updating missing contact information. Existing enriched values remain, so disabling the feature does not restore records to their earlier state. [3]

Opting out of model training is different: HubSpot's terms say the business can continue using AI features. Businesses therefore need not assume training participation is the price of retaining Breeze assistance. [13]

Possible working alternatives include approved templates, manual record updates and staff handling support requests. Measure the time saved by any retained AI against checking effort, corrections and customer outcomes. For paid agents, also review credit use. These are proposed business measures; this report did not independently establish savings or return on investment.

Control assessment

Requirement Finding
Disable generative AI and Breeze Assistant Documented account controls requiring Super Admin access.
Restrict customer information access Category controls plus feature-specific knowledge and permissions.
Separate viewing from changing records Documented Customer Agent property controls and custom-agent action choices.
Stop Customer Agent immediately everywhere Assignment switch stops new threads; existing threads can continue.
Refuse future HubSpot model training Documented account-level opt-out; previous training effects remain.
Stop enrichment Separate controls and permissions; manual Super Admin use also matters.
Stop external AI access Requires separate connection review; universal coverage not established.
Verify complete absence of AI processing Not established from published information reviewed.

Sources and scope

All sources below are official HubSpot documentation checked on 4 October 2026. This report covers relevant CRM, Breeze, customer-agent, training and enrichment controls. It is not a full audit of every HubSpot feature, marketplace app or external AI provider. Published capability is distinguished from availability in a particular account. Provider statements are not independent verification of implementation.

  1. Manage AI settings
  2. Understand HubSpot's AI model training
  3. Get started with data enrichment
  4. Set up a HubSpot account to adopt AI features
  5. Set up the customer agent
  6. Create and customise agents in the agent builder
  7. Deploy the customer agent to channels
  8. Manage data enrichment settings
  9. Allow the customer agent to access and update CRM data
  10. Set up the customer agent's handoff process
  11. HubSpot AI Cloud Infrastructure: frequently asked questions
  12. Understand opt-out notices for HubSpot's enrichment dataset
  13. Customer Terms of Service — customer data and tracking-code provisions

Unresolved: account-specific availability; effects on every existing automated process; each external connector's permissions and retention; complete independent verification of background processing and provider compliance.

Changes since previous HubSpot report: None. This establishes the first HubSpot baseline for subsequent monthly research.