Account and authentication records
Account email, password hashes, verification/reset records, sessions, API-key metadata, plan state, and usage counters are retained while needed to operate the account, prevent abuse, provide support, and meet billing or legal obligations. Expired one-time verification/reset tokens are not intended to remain usable.
Memory and request data
Memory payloads and queries sent to the hosted API are retained in the configured Vault backend until the customer or operator deletes them, the applicable plan/contract says otherwise, or the service lifecycle requires removal. The current public API does not expose a general self-service memory-delete route. Request deletion or export assistance at [email protected]; ownership and scope must be verified.
Do not infer automatic deletion: backups, replicas, audit records, and billing records may persist for a bounded operational or legal period after a primary record is removed. A signed order or data-processing agreement controls where it provides a more specific schedule.
Billing and legal records
Stripe and Perseus may retain transaction, subscription, tax, fraud-prevention, and accounting records for the period required by the applicable provider, contract, or law. Payment-card details are handled by Stripe rather than stored as raw card data by the Cloud application.
Operational telemetry
Client-error telemetry is bounded and routed to an operator-controlled relay when configured. Its fields and limits are described in Telemetry. Operational logs may be retained long enough to investigate failures and security events; do not place secrets or memory payloads in log messages.
Local and self-hosted Vault
For local or self-hosted Vault, the operator controls the database, backups, encryption key, retention settings, and deletion process. See the Vault documentation for that deployment rather than applying this hosted-service schedule.
Deletion requests
Include the account email, workspace or entity identifiers, requested scope, and any required legal/contractual basis. Never email passwords, API keys, encryption keys, or customer payloads. We will confirm the request, apply the verified scope, and identify any records that must be retained.