> ## Documentation Index
> Fetch the complete documentation index at: https://help.casaconect.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy and your data

> What Casa Conect records about how you use the product, how customer content is kept out of analytics, and how to delete your account, your organization and your data.

This page covers how Casa Conect treats data in the product itself. It complements, and does not replace, the [privacy policy](https://casaconect.ai/privacy) and your data processing agreement.

## Roles

For the documents, correspondence and client data you put into Casa Conect, **you are the controller and Casa Conect is your processor**. We process that content to provide the service to you. For account and billing information, Casa Conect is a controller.

## Keeping content out of analytics

We measure how the product is used so that we can improve it. We have built the measurement so that it **cannot** see your content.

<AccordionGroup>
  <Accordion title="Usage events are scrubbed on the server" icon="list-filter">
    Before any usage event is recorded, fields that could carry content or secrets are **removed whatever the code that sent them intended**. This covers text, body, content, HTML, Markdown, email, name, phone, address, prompt, question, answer, feedback, note, message, subject, URL, password, token and secret, among others. Remaining text values are cut to 200 characters and lists to 50 items.
  </Accordion>

  <Accordion title="Session replay masks everything by default" icon="scan-eye">
    Session replay helps us understand where people get stuck. In Casa Conect, **every piece of text is replaced with asterisks** unless we have explicitly marked it as our own interface copy, such as a menu label. All form inputs are masked. Element attributes are masked. Network request headers and bodies are **not recorded**. Embedded frames from other origins are not recorded.
  </Accordion>

  <Accordion title="Content areas are blocked, not just masked" icon="ban">
    The parts of the screen that show your material are excluded from replay altogether: editor bodies, document viewers, email bodies, conversations with the agent, matter descriptions, summary values and share pages. Our engineering rules forbid unmasking anything that renders customer content.
  </Accordion>

  <Accordion title="Profiles only for signed-in users" icon="user">
    Analytics profiles are created only for identified, signed-in users. Analytics data is hosted in the EU.
  </Accordion>

  <Accordion title="Error reports carry shapes, not values" icon="bug">
    When a server error is reported, the request's inputs are reduced to their types and field names. The values are never attached.
  </Accordion>
</AccordionGroup>

## Deleting data

| What                      | How                                                                             | Effect                                                                                                  |
| :------------------------ | :------------------------------------------------------------------------------ | :------------------------------------------------------------------------------------------------------ |
| **A document or file**    | Delete it from the vault                                                        | Removed, together with its search index                                                                 |
| **A conversation**        | Delete the conversation                                                         | Its messages and everything remembered from it are purged, and its cloud session is closed              |
| **A matter or project**   | Delete it                                                                       | The same purge, for every agent thread it contained                                                     |
| **An inbox conversation** | An admin deletes it                                                             | The email conversation and the agent's work sessions for it are deleted                                 |
| **Your account**          | **Settings → Account → Delete account**, then type `DELETE`                     | Your identity is deleted at the identity provider first, then in Casa Conect. It cannot be undone.      |
| **Your organization**     | **Settings → Organization → Delete**, for admins. Type the organization's name. | All members lose access immediately, and data tied to the organization is removed. It cannot be undone. |

Deletion is ordered so that it cannot be silently reversed. The identity is removed first, then the local record, and a marker prevents a late message from the identity provider from recreating what was just deleted.

<Note>
  **Backups.** Deleted data remains in encrypted backups until those backups expire, which takes a matter of weeks for daily backups and longer for monthly ones. Backups are used only for disaster recovery. Previous versions of files are removed on a fixed schedule.
</Note>

## What is not yet available

We would rather you know than assume.

* **Self-service data export.** There is no one-click export of an account or organization. Individual documents can be downloaded at any time. For a bulk export, [contact us](mailto:support@casaconect.ai).
* **A single erasure request across every system.** Deletion works per item, per account and per organization, as described above. For a formal data-subject request, [contact us](mailto:support@casaconect.ai) and we will carry it out and confirm.
* **Configurable retention periods.** Data is kept until you delete it.

## Emails we send you

Casa Conect sends transactional email only: sign-in codes, invitations to organizations and Shared Spaces, share links, billing notices and replies to access requests.
