Administration

Privacy and data

On this page

Open Privacy & data to review the Workspace's managed AI retention requirement and send an account privacy request. A provider-routing requirement and a request to delete data are different controls.

Choose the managed AI requirement

Open Settings, then Privacy & data, and check the Workspace named under Managed AI data retention. A Workspace owner can change Require zero data retention and choose Save. Other members can see the requirement and the permission explanation without an editing control.

Zero data retention, or ZDR, governs provider-side routing for AI requests sent with Task Machine-managed credentials. These requests go through OpenRouter and a selected downstream provider. Model eligibility depends on current provider-reported endpoint evidence.

When ZDR is required, managed model choices are restricted to qualifying models. Missing evidence or an unavailable qualifying endpoint blocks the request rather than relaxing the requirement. A fixed-model choice that becomes unavailable must be replaced explicitly. It is not silently changed to Auto.

When the requirement is off, Task Machine prefers known compatible ZDR endpoints but permits fallback to other providers for the model. Missing ZDR evidence alone does not block the request. The Workspace requirement is off by default.

Product-side features such as coaching also send content to OpenRouter. Those calls always require ZDR for each request, independently of the Workspace switch and Agent execution.

Privacy & data with the saved Workspace ZDR requirement and the support-email fallback for privacy requests

Review connected services separately

The managed AI setting does not cover Local Workers, your own provider accounts, Connectors, tools, or web search. Review the terms and controls of each service before sending sensitive information to it.

A Connector can send a query, URL, tool input, or other work context to an external service. Marketplace availability does not establish its retention period, processing region, or non-training terms.

Requiring ZDR does not mean data never leaves Task Machine, all processing stays in one region, or every downstream service has the same contractual terms. Read the Privacy Policy and Subprocessor Schedule for the broader relationships.

Distinguish provider retention from work history

The ZDR switch does not delete Tasks, Chats, transcripts, Library documents, results, Cloud files, backups, or logs. Run history can include instructions, supplied context, tool inputs and outputs, model responses, and the result you review.

Ordinary product records have no general automatic expiry. They normally remain while the account or Workspace is active, and afterward only as needed for operation, security, disputes, legal obligations, or an agreed instruction. Archiving preserves history rather than erasing it.

Understand temporary Cloud files

Cloud work files have a separate deletion lifecycle. Normal retention extends to 60 days after each managed Run, and later Runs extend that deadline. Closing or archiving the owning work can schedule earlier deletion.

Deleting those files does not delete the Task or Chat, transcripts, comments, receipts, or separately saved results. See Billing for retention timing and storage charges. Local working files remain on your machine and are outside Task Machine's deletion control.

Other stores have their own rules. Vault credentials in trash remain recoverable for 30 days before permanent purge. Logs, analytics, provider records, and backups follow their applicable settings and legal obligations. Archiving or changing ZDR does not clear all those copies.

Send a personal-data request

The Privacy requests form concerns your signed-in account. It remains available without a Workspace or active subscription. A selected Workspace supplies authorized context, not automatic authority to delete all of its data.

Choose access, correction, deletion, restriction, objection, a portable copy, or consent withdrawal. Use Details to identify the records and scope, without passwords, API keys, or unnecessary sensitive information. Then choose Send privacy request.

If the form is unavailable, use the support email shown on the page or in the Privacy Policy.

Know what happens after submission

Submission starts a Human-handled request, not an instant export or deletion. An authorized person checks your identity, authority, scope, and legal retention obligations before acting.

The response target is one calendar month. If a complex request needs an extension, you are notified within the first month. This is not a promise that every copy in every provider backup will be erased by that date.

For data controlled by your organization, Task Machine may need to work with the Workspace customer. The Data Processing Addendum explains that relationship. The Cookie Policy covers browser analytics choices.