Where data is held
What we store, and what leaves.
Your content
Everything a connector brings in is stored in the managed instance's database: content, search indexes, memories, users, settings and audit records.
What leaves
Indexing: nothing. The embedding model runs inside the service, so your content is never sent to a third party to be made searchable.
Chat and tagging: only if you configure a provider, and then only to the provider you chose, using your key.
Connectors: reach out to your systems to read from them.
Access
Your content is scoped to your organization and never crosses to another.
Our operations staff have infrastructure access — the same access anyone running a database has. We do not read customer content, and access is logged.
Deletion
Ask, and we will delete your organization and its content. Backups age out on their normal schedule afterwards.
If this is not enough
For requirements that rule out a third party holding content at all — regulatory, contractual, or policy — self-hosting is the answer, and it is the same product. Plenty of instances run that way.