What we store, for how long, and how deletion works.
| Data | Stored | Default retention | Configurable |
|---|---|---|---|
| Indexed content (chunks, embeddings, metadata) | Yes, in the workspace region | While the source is connected | Remove source or document at any time |
| Original files from connectors | Not stored; fetched on sync and discarded after extraction (except API-uploaded files, which are stored) | — | Delete document |
| Queries, answers, citations | Yes | 12 months | 30 days – 7 years |
| Run traces | Yes | 90 days | 30 days – 7 years |
| Audit log | Yes | 12 months | Up to 7 years |
| Connector credentials | Vault | While connected | Revoke at any time |
| Backups | Encrypted, EU | 35 days rolling | — |
Deleting a document, source, knowledge base or workspace removes data from live systems within minutes and from backups as they rotate (35 days). Deletion requests for individuals' data are honoured within 30 days; see the Privacy Policy.
All processing and storage happen in the EU. Sub-processors outside the EU are listed in the DPA with transfer mechanisms.
Customer content, queries and traces are never used to train models — ours or third parties'. Aggregated, de-identified usage metrics are used to operate and improve the service.
Support staff access to workspace data requires a customer-initiated support case, is time-limited, and is recorded in the customer's audit log.