# Data and privacy

How long conversations are kept, what gets redacted, what is shared with model providers, and who gets emailed.

Source: https://docs.omazy.ai/workspace/data-and-privacy/

Three settings decide what happens to customer data in this app, and they are
worth a deliberate decision rather than a default.

## Retention

**Retain messages for** sets how many days conversations are kept before they
are removed.

Longer retention gives you better analytics and a longer memory for returning
customers. Shorter retention reduces what is exposed if anything ever goes
wrong. There is no correct answer, only a choice that should match the sensitivity
of what people tell you.

Pick the number your privacy policy already promises. If those two disagree, the
policy is the one customers can read.

## Redacting personal data

**Redact PII** strips personally identifying information from stored messages.

This is the setting people enable after an incident rather than before one. Turn
it on when conversations routinely carry card numbers, health details, or
government identifiers, which is more often than most teams assume. Customers
paste whatever is in front of them.

Redaction applies to what is stored. It does not stop a customer from typing
something, so it reduces exposure rather than eliminating it.

## Sharing with model providers

**Share data with provider** controls whether conversation content may be used by
the model provider beyond answering the immediate request.

Off is the conservative default and the right one for most businesses. Turning it
on is a decision for whoever owns your data protection position, not for whoever
happens to be in the settings screen.

If you have your own provider account connected through the
[LLM Gateway](/reference/llm-gateway/), your provider's terms apply as well as
this setting. Both have to be right.

## Notifications

Three email toggles decide when the platform contacts your team.

| Setting | Sends email when |
|---|---|
| **New conversation** | A conversation starts |
| **New assignment** | A conversation is assigned to someone |
| **Daily summary** | Once a day, with the numbers |

New-conversation email is the one to be careful with. It is genuinely useful at
five conversations a day and actively harmful at five hundred, because the
moment an alert is always firing it stops being an alert. If your agent resolves
most conversations alone, assignment email is the better signal: it fires only
when a human is actually needed.

The daily summary is the low-cost option. It is the one to keep when you turn the
others off.

## Where the record lives

Changes to these settings are audited like any other. If retention shortens and
nobody remembers agreeing to it, the audit log knows who and when. See
[Roles and permissions](/workspace/roles/).

## Taking your data with you

Everything covered above can also be downloaded: catalog, customers,
conversations, messages, bookings and agent configuration, as CSV. Exports are
recorded here alongside these settings, their download links expire, and
erasing a workspace removes its exports with it.

See [Exporting your data](/workspace/exporting-data/).
