Your data controls
Available controls
- Export: download a JSON export of your account identity, preferences, memberships, consent records, active session metadata, and owned workspace records without passwords, tokens, or IP hashes.
- Consent: view current policy versions and withdraw recorded privacy or terms consent.
- Sessions: list and revoke your active sessions from the signed-in product.
- Account deletion: request account anonymization. Access is revoked, credentials and tokens are invalidated, preferences are removed, and immutable operational history retains only a pseudonymous actor reference where required for integrity.
Administrator controls
Workspace administrators can view redacted Logs, Errors, Audit, and Security records for their tenant. They cannot use those views to obtain password hashes, session tokens, CSRF secrets, or another tenant’s records.
Retention and limitations
The administrator retention job purges local transient data according to the published schedule: token safety window, 30-day sessions/exports/shares/jobs, 72-hour temporal snapshots, and 90-day logs/errors. Immutable audit, security, and operations history is retained pending qualified legal/deployment policy. Workspace deletion, backup purge, provider mailbox retention, and jurisdiction-specific rights remain deployment-owner and qualified legal-review decisions.