This summary is limited to behavior observed in the current code. It is not a claim of legal compliance or complete processor inventory.
What we hold
Your sign-in and account record use WorkOS and D1. Content you choose to save—conversation messages, memories, and genealogy—lives in your account-named Durable Object. Uploaded files can live in R2, and genealogy search can create Vectorize embeddings. The account-memory page inventories selected Durable Object tables; it is not a complete export.
Why
We use this data to run the service, answer your requests, process billing, secure and debug the product, and measure product use. AI providers receive the conversation or media needed for a request. Analytics and monitoring services can receive identifiers, events, and error context.
Who can see it
Subscriber-agent routes compare the requested Durable Object name with the signed-in subscriber and reject other-account targets. Authorized operators and the service providers named in the draft policy may process scoped data needed for support or operation. This page does not prove what a provider has retained.
How to delete it
Settings can start the account-deletion flow. Current deletion depends on the enabled production mode and spans more than one store. We do not promise that R2 objects, Vectorize embeddings, backups, or processor copies are erased until an end-to-end deletion receipt proves each one. For a deletion or export request, contact hello@voice-catalyst.com.