Reference · Privacy and retention

Privacy and retention

Code stays local. What travels to the hosted account is a receipt, a case, a sanitized package or a session's outcome; a transcript travels only under a grant a person gave, and a package never carries one. This page says what leaves, what stays, and what deletes.

What leaves the machine

  • Receipts and cases. A source's observation, bounded and redacted, with the rule version that classified it and the source's health at the moment of the sighting. The gateway validates the allowed fields and applies redaction before storage; a page whose redaction failed stores nothing and is retried.
  • Decisions and lessons. The case's status moves, findings, verification checks, cost receipts and the lesson state, each as an event with its actor and time.
  • Prevention packages. The sanitized package: cause, explanation, scope, prerequisites, exceptions, and pointers to its reproducer, guards and evidence. Restricted evidence is a pointer the reader resolves through its own authorization.
  • Outcome receipts. That a session retrieved, acknowledged or used a package, that a guard ran with one of six outcomes, and a device's acknowledgment of what it installed. A receipt names the session and the device, never the session's content.

The full private brain and a raw transcript are never committed to a repository and never carried inside a package. A curated pull request carries the package's text and checks, by the same id, version and hash the sync channel uses.

Transcript grants

A transcript is readable on the hosted side only through a grant: requested by a reader, granted or denied by the person who owns the session, for one incident, with an expiry. A grant may be withdrawn by its requester or revoked by its granter; revoked and expired grants are purged from the mirror. A package that references a transcript through a grant stays intact when the grant is revoked; the reference reads as unauthorized, nothing else changes. Reading a grant's transcript is recorded as a read.

Redaction and bounding

Every receipt is bounded before it is stored: titles and notes to a fixed length, lists to a fixed count, control characters stripped, and the words of a source reaching only the summary. A source-supplied session reference is reported context until independently verified. A cost event is not a provider billing receipt.

How long each kind of data is kept

Every window below is a ceiling. You, your team or an operator can pick a shorter one; a longer one, including the old "keep forever" transcript choice, runs at the ceiling and the receipt says it was clamped. Where a store already expired sooner, its shorter window stays.

DataKept forWhat stays after
Raw connector debug payloads7 daysNothing stores one today. A dead letter keeps its reason and a digest, never the record.
Connector payloads staged for re-processing (hosted, opt-in, encrypted)30 daysThe memories already made from them. The daily sweep removes older payloads for every user, including one who stopped syncing.
Retained transcript bodies (prompts, responses, tool inputs and outputs)30 days, or 7 or 14 if you chooseThe session and its cost. The trace reads "expired", not "not captured".
Prompt and reply text on local session records (what the Prompts tab searches)30 days, or 7 or 14 if you choose, on the same settingThe session, its tokens and its cost. The Prompts tab says how many older prompts expired and through which day, and a search says how many it could not look inside.
Detailed session and request telemetry14 days for the local telemetry partition and 30 for the event outbox, then archived; 30 days hostedCompact session records and priced totals. A hosted session past its window still lists with its cost and outcome, and its step detail reads "Expired" with the date. With cloud sync on, an outbox day the cloud has not received stays until it does, up to 512 MB, and counts as held.
Hosted audit rows (who did what, and the action trail)13 monthsNothing older, except an account's deletion request, which the purge job needs. A tab visit is stored as an audit row but records usage, so it goes at 30 days.
Hosted commit and pull request rows13 monthsNothing older. The Inbound triage page reads 180 days back, well inside the window.
Hosted brain rows (edits, decisions, lessons, claims, causal links)The life of the brainThe telemetry window does not sweep them. They go when the account is deleted, or under an organization's own retention rule.
Daemon debug logs7 days, capped in bytesThe newest five crash reports.
Dead letters and cron run history30 daysThe reason a record failed, never its body.
Hosted daily rollups and retention receipts13 monthsNothing older.
Archived day files on your machine (session records, the event outbox and the telemetry partition, compressed by month) and the daily rollups the desktop app builds from them13 monthsNothing older, except the records of a session a case evidence hold names. When the holds cannot be read, the nightly sweep removes nothing from the archive that night.
Cases, findings, lessons and costsThe life of the case or teamPrevention records keep 365 days and transcript grants 14.
The forgetting sweep's monthly archives of brain recordsFrozenNo bulk deletion; an export or purge needs its own migration.

Case evidence holds

A case under investigation can keep a session's transcript body past its window. In the desktop app, open Settings, Data retention, and place a hold with the case, the session ids, an owner and an end date no more than a year out. A hold with no owner or no end is refused, so nothing is kept forever by accident. The nightly sweep skips held sessions and counts them as held; when the hold ends or is released, the next sweep removes the body. A hold keeps the session's prompt and reply text the same way, and its records in the archived day files past their 13 months.

A team owner or admin can place the same kind of hold on the hosted Settings page. It keeps the stored transcripts of the sessions it names past the 30-day window, and the daily sweep counts them as held on your team's receipt. A hosted hold does not extend a developer's transcript grant, which ends when the developer said it would.

A managed repository's evidence keeps the window its owner set in a policy each developer accepted. A hold keeps it longer only where that policy says so: the owner sets a hold allowance when publishing (30 days past the window by default, never more than 365 days in all), the developer reads that clause in Settings before accepting, and a hold then reaches only evidence uploaded under a policy version that carries it, and only for an open case. Evidence from an installation that accepted an earlier version keeps its window until that installation accepts the new one. Placing and releasing such a hold is written to the repository's audit trail, and the person placing it is told how many snapshots it keeps and how many it could not reach.

A session whose managed evidence upload the receiver has not verified is kept the same way, so unsynced evidence is never removed before it is acknowledged. RepoOps never deletes the coding tools' own transcript files that managed evidence is read from.

Sweep receipts

Every sweep writes a receipt per store: how many records it looked at, expired, held and failed, and the bytes it removed. A store with no sweep shows "not swept" and why, never a zero. The first run under a new policy is marked, because that run removes everything that had built up past the window. The desktop app shows the receipts in Settings, Data retention (GET /api/retention); the hosted Settings page shows your team's own counts (GET /api/team/retention) and never another team's.

The hosted events sweep writes one receipt for each kind of row: usage and telemetry, audit, commits and pull requests, and brain. Brain rows are counted as held, never expired, because that sweep keeps them on purpose. Connector staging has its own receipt.

A store that starts being swept after the policy began marks its own first sweep on its row. The prompt text on local session records is one: the first night removes text older than the window that built up before. The archived day files and the daily rollups are two more: their first night removes everything older than 13 months.

No store waits on a decision any more. The last one, the local daily rollup caches, was decided on 2026-10-05 along with the archive they are built from.

Who can delete

A team's rows on the hosted side are deleted by an organization's retention window, and attaching a team to an organization gives that window the power to delete the team's events; only the team's owner may attach, and only the owner may take the exit. An export carries the retention label it was taken under. On the local machine, the brain's own records are archived by the forgetting sweep (the newest four hundred pull request records and the last thirty days stay in place; the rest is compressed by month and indexed, and can be restored by number), and every deletion the desktop app performs on its own store is its own.

A lapsed subscription or trial stops new hosted compute. It does not delete evidence, remove an active safeguard, or stop a revocation from reaching a device; those are never behind a bill.

What this page does not say

An organization's own retention window can shorten the hosted windows above and cannot lengthen them; it is also the one rule that removes a member team's hosted brain rows by age. Where a retention question is a contract question, the answer is in the agreement, not here. How a source's health is reported, and what a quiet source means, is on No data is not no incidents.

Last updated