How an organization manages its data
The three settings an owner controls for an organization, what each one stores, who can read it, and the limits of the strongest setting. Content logging, product telemetry, and retention, in one place.
An organization has three settings that decide what is kept and who can read it. They live on the Data page of the organization in your dashboard, and only the owner can change them. Everyone else who can see the page reads them as they are, with the line "You can see these settings but not change them. Only an owner can."
Content logging
What is written to your audit records about each request. Three settings:
| Setting | What it records |
|---|---|
| None | Only that a request happened. No prompts, no responses. |
| Metadata | Model, token counts, timing and cost. No content. The default. |
| Full content | Prompts and responses are retained and readable by your administrators. Marked Sensitive. |
Full content is the strongest setting, and it is worth being exact about what it covers, because it is narrower than the name suggests.
What it records. Member conversations: what the member sent and what the model replied, tagged with the surface it came from. A conversation in chat and a session in the CLI land in the same record, told apart by that tag alone, so a review does not have to know where to look first.
Who is recorded. Everyone in the organization, the owner and the administrators included. There is no exemption for the people who set the policy.
Who can read it. The owner, the security role, and auditors. Not administrators, deliberately, so that the person who onboards staff is not the person who can read what they wrote. See Read and export the conversation archive.
What it never records. Images, uploaded files, memory, or the request records described in What is recorded about every request. It is your organization's own record, held under your policy, and Dropstone staff have no route into it.
Turning it on requires a second confirmation, and members must be told. See Turn on content logging.
Product telemetry
Whether anonymised usage signals from the organization may be used to improve Dropstone. Off by default for every organization, and the setting is enforced when data is collected rather than in the client, so an off organization contributes nothing even if an individual member has left their own preference on.
The page states the consequence in full: with it off, "Nothing from this organization is collected, and no code or conversation from it is ever used for training."
Data retention
How long conversations, telemetry and usage records are kept before deletion. Choose 30 days, 90 days, 1 year, a custom number of days, or no limit.
Audit events are exempt from this window, and the page says why: they are the record of what happened, and are kept for the life of the contract. A retention setting shortens what the organization holds; it does not shorten the record of who changed what.
What is never covered, at any setting
- Uploaded files and images. No setting stores them for review. See What happens to the files you upload in a chat.
- Memory. What members have taught Dropstone is governed separately, by its own sharing ladder. See Who can see and change your memory.
- Usage records. The usage page shows counts and cost, never the contents of anyone's work, whatever the logging setting is.
- A view for Dropstone. Nothing on this page gives Dropstone a way to read your organization's data.
Every change is recorded
Changing any of these three settings writes an entry to your audit log, naming the setting and the person who changed it. The Data page says so under each control, and the audit log cannot be edited or deleted from, by anyone. The log has its own page: The organization audit log.
What all of this adds up to over a year of use is the subject of How Dropstone compounds in an organization.
Related articles
- Turn on content loggingHow an owner turns on full content logging for an organization, what the confirmation means, how to tell members, and how to turn it off again.
- Read and export the conversation archiveWho can read an organization's recorded conversations, how to search and filter them, what the archive never holds, and how to export it as JSONL.
- Is your data used to train models?On an organization account, never. On a personal account, only if you leave the setting on. What is collected, what is never collected, and what deletion can and cannot undo.
- Who can see and change your memoryWhat Dropstone remembers belongs to your account. You can read all of it and delete any of it, the agent records and never forgets on its own, and nobody at Dropstone can read it.
- Dropstone for teams and organizationsAn organization gives a company one Dropstone account structure, centralized billing, members and teams, shared memory, and enterprise sign-in. What an organization is, roles, and how to set one up.
- Shared memory across a teamHow organization admins oversee shared memory in Dropstone. Reviewing what has been shared, removing entries, setting a retention window, and how secrets are kept out.