Data handling and privacy
What AutoData stores, for how long, how secrets are protected, when data may reach a language model, and what shared links expose.
This page describes what AutoData keeps when you run a dataset, for how long, and what may leave the server. The retention periods are the service defaults; a self-hosted installation can change them.
What is stored, and for how long
| Data | Kept |
|---|---|
| Your uploaded input file | Deleted when the run ends, whether it completes, fails or is cancelled |
| Output files (stage outputs, model-ready export, reports) | 7 days |
| What a session needs for inference and retraining (fitted transforms, schema, quality report) | 1 year |
| Images and audio uploaded with a run | 1 year |
| Run history: file name, row and column counts, settings, status, amount charged | Kept with your account |
| Saved connections, schedules, listeners, triggers, webhooks, shares | Until you delete them |
| Sign-in session | 24 hours, extended while you use the app |
Download the outputs you need within 7 days. After that the session stays in your history and still supports inference and retraining.
Secrets
- Connector credentials are encrypted at rest and are never returned. Lists show only non-secret hints such as bucket, host or region.
- API keys, SFTP passwords and account passwords are kept only as one-way hashes. Keys and SFTP passwords are shown once, when created.
- Webhook signing secrets are never returned. They are used to sign each delivery.
- Connection-test error messages are cleaned of secrets before they are saved.
Language models
A few optional features use a large language model (LLM). Depending on the installation, it is either hosted by a provider or runs on the server itself. Nothing else in the pipeline sends your data anywhere.
| Feature | On by default? | What it may send |
|---|---|---|
| Anomaly Detection | No | Column names, a small sample of values, text cells being repaired, and any descriptions you gave |
| Data Completion and Verification | No | The cells being completed or checked |
| Parameter tuning from a project description | Only if you write one | The description, row and column counts and task type; no cell values |
| Semantic profiling (Enterprise) | Enterprise runs | Column names and a few short sample values |
Controls
llm_enabled(defaulttrue): set it tofalseto block every LLM call for a run. Features that can work without an LLM carry on; Data Completion and Verification is skipped.strict_llm(defaultfalse): set it totrueto fail the run instead of continuing without a model that couldn't be reached.- Both go in
advanced_paramsof/api/v1/processand the SDK, and in the pipeline configuration of automations (llmEnabledandstrictLlmare accepted too). - Self-hosted installations can switch LLMs off for everyone, or use a local model.
{"advanced_params": {"llm_enabled": false}}
The dashboard upload form has no LLM switch. To keep a dashboard run on the server, leave Anomaly Detection and Data Completion off and the project description empty.
Every run records whether a model was used. The record gives the host it went to (never the key) and the result for each stage. It is returned as llm by GET /api/v1/result/<session_id>, and it follows the 7-day output retention.
Sharing
| Permission | Can |
|---|---|
| read | View the session summary and download the files you shared |
| comment | Read, and comment |
| edit | Comment, and rename, reuse the configuration, replay and access all output files |
- A public link can be opened without signing in. It shows:
- the session name, original file name, status, date, and row and column counts;
- your name, your note and the permission;
- the files you chose to share.
- By default no files can be downloaded through a link.
- Set an expiry date to make a share lapse; an expired link returns 410. Revoking a link also removes everyone who joined through it.
Sign-in
- The sign-in cookie lasts 24 hours.
- It is HTTP-only and same-site, and it is sent only over HTTPS on the hosted service.
- Sign-in attempts are limited to 10 per 5 minutes per IP address.
Closing an account
Self-service deletion is not available yet; contact support. An account can be:
- Deactivated: sign-in is blocked and everything is kept. This can be undone.
- Deleted: permanent. It removes the account, its API keys, history, settings, saved connections, automations and the shares it created. Output files already on disk are removed on the normal retention schedule.