Browse documentation
2026-09-28AutoDataOpen in dashboard

Data handling and privacy

What AutoData stores, for how long, how secrets are protected, when data may reach a language model, and what shared links expose.

This page describes what AutoData keeps when you run a dataset, for how long, and what may leave the server. The retention periods are the service defaults; a self-hosted installation can change them.

What is stored, and for how long

DataKept
Your uploaded input fileDeleted when the run ends, whether it completes, fails or is cancelled
Output files (stage outputs, model-ready export, reports)7 days
What a session needs for inference and retraining (fitted transforms, schema, quality report)1 year
Images and audio uploaded with a run1 year
Run history: file name, row and column counts, settings, status, amount chargedKept with your account
Saved connections, schedules, listeners, triggers, webhooks, sharesUntil you delete them
Sign-in session24 hours, extended while you use the app

Download the outputs you need within 7 days. After that the session stays in your history and still supports inference and retraining.

Secrets

  • Connector credentials are encrypted at rest and are never returned. Lists show only non-secret hints such as bucket, host or region.
  • API keys, SFTP passwords and account passwords are kept only as one-way hashes. Keys and SFTP passwords are shown once, when created.
  • Webhook signing secrets are never returned. They are used to sign each delivery.
  • Connection-test error messages are cleaned of secrets before they are saved.

Language models

A few optional features use a large language model (LLM). Depending on the installation, it is either hosted by a provider or runs on the server itself. Nothing else in the pipeline sends your data anywhere.

FeatureOn by default?What it may send
Anomaly DetectionNoColumn names, a small sample of values, text cells being repaired, and any descriptions you gave
Data Completion and VerificationNoThe cells being completed or checked
Parameter tuning from a project descriptionOnly if you write oneThe description, row and column counts and task type; no cell values
Semantic profiling (Enterprise)Enterprise runsColumn names and a few short sample values

Controls

  • llm_enabled (default true): set it to false to block every LLM call for a run. Features that can work without an LLM carry on; Data Completion and Verification is skipped.
  • strict_llm (default false): set it to true to fail the run instead of continuing without a model that couldn't be reached.
  • Both go in advanced_params of /api/v1/process and the SDK, and in the pipeline configuration of automations (llmEnabled and strictLlm are accepted too).
  • Self-hosted installations can switch LLMs off for everyone, or use a local model.
{"advanced_params": {"llm_enabled": false}}

The dashboard upload form has no LLM switch. To keep a dashboard run on the server, leave Anomaly Detection and Data Completion off and the project description empty.

Every run records whether a model was used. The record gives the host it went to (never the key) and the result for each stage. It is returned as llm by GET /api/v1/result/<session_id>, and it follows the 7-day output retention.

Sharing

PermissionCan
readView the session summary and download the files you shared
commentRead, and comment
editComment, and rename, reuse the configuration, replay and access all output files
  • A public link can be opened without signing in. It shows:
    • the session name, original file name, status, date, and row and column counts;
    • your name, your note and the permission;
    • the files you chose to share.
  • By default no files can be downloaded through a link.
  • Set an expiry date to make a share lapse; an expired link returns 410. Revoking a link also removes everyone who joined through it.

Sign-in

  • The sign-in cookie lasts 24 hours.
  • It is HTTP-only and same-site, and it is sent only over HTTPS on the hosted service.
  • Sign-in attempts are limited to 10 per 5 minutes per IP address.

Closing an account

Self-service deletion is not available yet; contact support. An account can be:

  • Deactivated: sign-in is blocked and everything is kept. This can be undone.
  • Deleted: permanent. It removes the account, its API keys, history, settings, saved connections, automations and the shares it created. Output files already on disk are removed on the normal retention schedule.