Privacy, storage, retention, and deletion
Understand the Desktop boundary, centralized storage, telemetry prohibition, lapse, and physical expiry.
Desktop boundary
Raw video, screenshots, and audio remain on the employee device and are never uploaded in v1. The local Screenpipe ring is bounded by policy to 0–7 days. Only policy-approved structured events enter the encrypted local outbox and centralized ingestion path.
Local filtering excludes password managers, private/incognito browsing, payment or authentication secrets, configured applications/domains/windows, and content that fails redaction. Policy separately controls accessibility text, OCR text, window titles, and whether browser URLs are omitted, reduced to origin, or include the path. Query strings, fragments, embedded credentials, non-HTTP URLs, and sensitive authentication/payment paths are never preserved.
Central retention defaults
| Data | Default |
|---|---|
| Structured Desktop context | 30 days |
| SaaS current tables | While the Source remains connected |
| Supported SaaS change tables | 90 days |
| DuckLake rollback snapshots | 7 days |
| Upload staging | 3 days |
| Quarantine | 14 days |
| Audit and query receipts | 90 days |
| Detailed operational logs | 14 days |
Effective Account policy can differ and is displayed in Settings. Query results are transient.
Storage boundaries
The control database holds Accounts, identities, grants, Source state, catalogue metadata, receipts, and Activity. Queryable records live in the lake behind service-only credentials. Provider secrets live in the managed secret boundary. Sandboxed connector work receives a run-scoped capability, not project infrastructure credentials.
Customer context is prohibited from Sentry, PostHog, operational logs, support chat, and product analytics. The observability vendor may change; the content prohibition does not.
Source deletion
Deletion first revokes grants, schedules, claims, endpoint uploads, and secrets. A durable job then drops active lake relations, expires snapshots, cleans referenced/staging objects, removes database roles and the managed secret, verifies Source inventory, and records a content-free proof.
Logical and managed backups age out under their published retention window. Combined does not claim instantaneous removal from historical backups.
Account lapse
When a trial or subscription lapses, structured data remains recoverable only for the Account's configured lapsed-retention window (14 days by default) before durable deletion becomes eligible. The Settings page displays the effective value.
Support and diagnostics
Support access is visible, role-bound, and audited. Error reports should contain correlation IDs, states, counts, and timing—not copied customer rows or secrets. See Diagnostics for a safe support bundle.