Source: docs/integration/privacy-and-retention.md

Privacy and retention policy for the integration MVP

This policy describes the minimum handling of data sent through Forgium. The

host application remains responsible for its own user notice, lawful basis,

access controls, and deletion obligations.

Data classes

ClassStored by ForgiumPurposeDefault retention
Message textConversation and message recordsGenerate and audit a reply30 days
Host-interaction correlationForgium interaction ID, account/conversation/subject scope, operation name, interaction type, status, expiry, and timestampsAccept an optional terminal report without retaining host references90 days
Capability and service auditIDs, SHA-256 hashes, timing, HTTP status, stable error codes, unresolved-request and failure categoriesSecurity and operations90 days
AI usage ledgerOpaque account/user/correlation IDs, model, bounded parameters, token counts when reported, versioned rates, costs, and lifecycle statusInternal AI cost attribution and future account costingNo public retention period announced in this version
CredentialsAES-GCM ciphertext onlyAuthenticate an endpointUntil revoked, then 30 days for deletion evidence
Signing materialPrivate key in the Worker secret store onlySign outbound contextManaged by key-rotation policy; never stored in D1

Bodies, bearer tokens, complete JWS values, capability arguments, previews,

operation_ref, selection_ref, and option_ref are not written to capability

audit or host-interaction records. Staging fixtures use synthetic data only.

AI usage records never contain prompts, responses, message text, attachments,

schemas, tool definitions, raw provider payloads, credentials, or JWS values.

Chat user_id values are opaque external identifiers and remain optional during

client migration. Prompt Integrations are account-only for usage attribution.

Capability-audit retention enforcement

agent_run_events are deleted daily by the dedicated retention Worker after

90 days. They include sanitized capability decisions and service-audit events;

they never duplicate message text. Unresolved-request categories are bounded

operational signals, not authorization decisions or verified explanations of

user intent. The worker has only a D1 binding, no public route, and deletes in

bounded idempotent batches. Platform On-call owns execution monitoring and

escalates failures to the Platform owner.

Accounts may choose whether their account-scoped capability-gap diagnostic

endpoint returns message text with PUT /v1/diagnostics/settings. The safe

default is diagnostic_message_mode: "metadata"; "text" is opt-in. This

setting controls diagnostic projection. "disabled" makes the account-facing

report empty. Neither setting changes the separate conversation message-storage

policy or internal audit retention. Text remains subject to the message

retention period and is never copied into agent_run_events.

An active legal hold or incident hold excludes the specific event from deletion

until Operations/Security releases it under the incident process. Holds do not

pause retention for other records. Retention-worker logs carry only a cutoff,

deleted count, and batch count.

Access, deletion, and support

Access is limited to the authenticated host backend, the Forgium runtime for

execution, and authorized Operations/Security personnel for incident response.

Support access is time-limited, logged, and must use redacted identifiers.

The host application can request deletion of conversations, messages,

host-interaction correlation records, credentials, and related audit records

through the operational owner.

Deletion requests are acknowledged with scope, timestamp, requester, and

completion evidence. Legal holds or active incident investigations may delay

deletions; the requester receives the reason and expected review date.

Incidents

For suspected disclosure, the host application must revoke the endpoint token

and Forgium access bundle, preserve redacted evidence, and contact the

platform incident owner. Forgium Operations rotates affected credentials or

signing keys, reviews security events, and communicates impact and recovery

steps. Never include secrets or raw message bodies in an incident ticket.

This MVP policy requires Product, Legal, and Security approval before a

production access bundle is issued. Changes to retention, data classes, or

support access require a documented review.