← All legal documentsLegal

Data Retention

This page explains what we keep, for how long, and why — from the moment work runs on the platform, through a deletion request, to the point where erasure is complete and only a small set of content-free records remains.

This page reflects our ratified data-retention classification and is subject to the published launch contract.

Deletion, in two steps

Acceptance and completion are not the same thing.

Deletion Request Acceptance

Your deletion request and your billing-shutdown intent are made durable, and the platform's authority over the account is suspended. This is not an assertion that remote billing or erasure has completed — only that the request has been recorded and authority has stopped.

Deletion Completion

Every subscription is deletion-terminal, any retained reconciliation authority has been spent, and erasure has completed. The only records that remain are those that satisfy the four content-free classes described below.

After completion

What we retain — exactly four content-free classes.

After Deletion Completion, the retained security and financial records carry no organisation id, user id, GitHub install or repo id, repository name, pull-request or head reference, model or provider content, IP address, free-form text, or personal data. Each row carries only a random 128-bit retention subject plus closed event, amount, and time fields — the sole exception being the one-way trial aliases.

ClassWhat it isRetention periodPurpose
Security audit eventsContent-free security audit events — minimized, subject-scoped security facts.The remainder of 365 days after the event.Detect, investigate, and prove security-relevant actions and abuse.
Seat financial recordsContent-free seat financial records.10 years after the record is created.Accounting and tax records, invoice substantiation, and billing-dispute defense.
Trial anti-abuse ledgerA one-way, irreversible trial anti-abuse ledger and versioned aliases that hold no personal identity fields.Indefinite.Prevent repeated free-trial abuse without retaining identity fields.
Legal-hold recordsRecords preserved under an explicit legal hold.The duration of the identified legal or regulatory obligation. A hold may extend the security-audit and financial-record periods above, but never creates a hold over prohibited material.Preserve only otherwise-retainable security or financial records for an identified legal or regulatory obligation.
Legal hold

A legal hold has strict limits.

A legal hold may extend the retention of the security-audit and financial-record classes above. It must never retain Provider Credentials, GitHub credentials, repository content, prompts, model responses or findings, personal identity fields, or secret-bearing support attachments.

Before a deletion request

Retention during normal operation.

These are the retention periods that apply while an account is active. Each of them is overridden at Deletion Request Acceptance.

DataRetention
Repository input images, scratch space, raw harness diagnostics, and raw prompt and model outputDestroyed at attempt teardown; never retained in ordinary operation.
Validated Common Findings and review-history display30 days after the attempt completes.
Bounded, content-free operational attempt metadata90 days after the attempt completes.
Content-free security audit events365 days after the event — becomes a retained security-audit record after Deletion Completion.
Content-free seat financial records10 years after the record is created — becomes a retained financial record after Deletion Completion.
Trial anti-abuse ledger and one-way aliasesIndefinite.
Backup, restore, and discovery

There is no general index after completion.

The live mapping between an organisation and its retention subject is erasable, and it is deleted at Deletion Completion. After completion, financial or legal discovery requires an external case-entry reference — the retention subject itself — or an in-horizon receipt proof. There is no general organisation or user index once completion has occurred.

Content-free restore-control artifacts — such as witness receipts, checkpoint references, key-manifest version references, degraded and alarm watermarks, quarantine and suppression marks, and restore attestation markers — are not a further class of customer data.