Data handling and retention
This article explains where your data lives, how it is kept apart from other customers, what you control about retention, and how to get your data out.
One organization, one boundary
Every row of data in Records Labs is tagged with the organization it belongs to, and the database enforces that tag with row-level security. When you use the app, requests run as you, with your own sign-in token, so the database only ever returns rows your organization and your role can see. There is no shared index across customers: each organization's vector index lives in its own namespace keyed to the organization's ID.
Inside an organization, each item's company access, customer exposure, and sensitivity decide who it can be used for. Trust only changes how heavily answers lean on it. See Access, sensitivity, and trust.
Where data lives
Database, sign-in, and file storage: Supabase (Postgres) on AWS in the US West region. Uploaded originals, chat attachments, knowledge images, and Creations are stored in Supabase Storage buckets.
Search index: TurboPuffer, in AWS US West, one namespace per organization.
Application servers: Railway (API and ingestion workers) and Vercel (web app), both in US West.
Database backups are taken daily and encrypted. AI processing, such as answer models and document extraction, can run with vendors in other regions. The full list of vendors is in Subprocessors.
Retention settings you control
Open Settings → Security, then the Data tab. Only Owners and Admins (or a custom role with organization settings access) see this page and can change these settings.
Trash retention — how long trashed knowledge, chats, Creations, and projects stay restorable: 7 to 365 days, 30 by default. Trashed items are already excluded from AI answers; after the window they are permanently deleted, together with the original uploaded files. A trashed Creation that still has a published page is kept until the page is unpublished.
Recording & upload retention — Keep meeting recordings (the organization default for the notetaker, off unless you turn it on; transcripts and summaries are always kept), Let members choose for their own meetings (on by default), and Keep uploaded audio & video originals (off by default). This pre-selects Keep the original audio & video files when someone adds audio or video; they can still change it for that upload. When an original is not kept, only the transcript is stored.
PII scrubbing — see PII scrubbing.
Data use — Improve our own experience (on by default) keeps your organization's citation clicks and answer feedback as private, per-organization ranking signals, never shared across organizations. Help improve the platform (off by default, Owners only) additionally shares query text and document excerpts from a small sample of searches.
Browser capture policy — the widest visibility a browser-extension capture can have, and how captures are reviewed.
Email Learnings — whether learnings from connected mailboxes need review before they are shared, and how many must agree before a draft note is written.
What is kept, and for how long
Chats and Help Desk conversations are kept until someone deletes or archives them. There is no automatic deletion by age. A deleted chat goes to Trash and is purged after the trash window. Archived chat widget conversations in the Help Desk are purged after the same window.
Private chat conversations are not saved to chat history. The usage record for each answer is still kept, with placeholders in place of the question and answer text.
Knowledge stays until it is trashed, then follows the trash window.
Notifications are removed after 90 days.
Audit log entries are kept and can be exported.
Export archives are deleted 7 days after they are ready.
Exporting your data
Owners and Admins can request a full archive from Settings → Security → Data → Export organization data.
Click Request export.
Wait for the archive to build. The button shows Preparing… while it checks; if checking pauses, click Check status.
Click Download once it is ready. The archive stays available for 7 days, and each click makes a fresh download link. After 7 days the archive is securely deleted and you can Request again.
The archive contains knowledge articles (Markdown plus JSON metadata), FAQs, a sources index, customers (accounts and contacts), and Help Desk conversations as JSONL transcripts. Chat sessions and Creations are not yet included.
Other exports:
Settings → Audit Log → Export CSV.
Analytics → Export (CSV).
Any Library document → Download original; any Creation → Download.
Help Desk → Customers, open a company or contact, then Data & privacy → Export data or Delete data, for one end customer's information. Owners and Admins only.
The REST API, for conversations, documents, and Creations.
Cancelling your plan
Billing changes, including cancellation, happen in the Stripe billing portal via Settings → Plan & Usage → Manage billing. A cancelled plan runs to the end of the period.
Cancelling does not delete your data. Nothing is removed automatically when a plan ends; your knowledge, chats, and settings stay in place so you can export them or come back. If you want your organization's data deleted, contact support and we will delete it as described in our Privacy Policy.
When you contact support
Chat with support in the Help and support menu tells the support team who you are: your name, email, organization, plan, and role. Support also sees what you type or attach, and may see which page of the app you opened the chat from. When you open the chat from an alert, such as a blocked website, support also sees what the alert was about. Opening a chat or request does not give support access to your organization's knowledge.
The support chat keeps its conversation in your browser while you are signed in. Signing out clears it, along with any widget preview conversations, and a different person or organization on the same browser starts a fresh chat.