Dropstone Support

How an organization manages its data

The three settings an owner controls for an organization, what each one stores, who can read it, and the limits of the strongest setting. Content logging, product telemetry, and retention, in one place.

Available onFreeProMaxEnterpriseOrganizations are on the Enterprise plan.

An organization has three settings that decide what is kept and who can read it. They live on the Data page of the organization in your dashboard, and only the owner can change them. Everyone else who can see the page reads them as they are, with the line "You can see these settings but not change them. Only an owner can."


Content logging

What is written to your audit records about each request. Three settings:

SettingWhat it records
NoneOnly that a request happened. No prompts, no responses.
MetadataModel, token counts, timing and cost. No content. The default.
Full contentPrompts and responses are retained and readable by your administrators. Marked Sensitive.

Full content is the strongest setting, and it is worth being exact about what it covers, because it is narrower than the name suggests.

What it records. Member conversations: what the member sent and what the model replied, tagged with the surface it came from. A conversation in chat and a session in the CLI land in the same record, told apart by that tag alone, so a review does not have to know where to look first.

Who is recorded. Everyone in the organization, the owner and the administrators included. There is no exemption for the people who set the policy.

Who can read it. The owner, the security role, and auditors. Not administrators, deliberately, so that the person who onboards staff is not the person who can read what they wrote. See Read and export the conversation archive.

What it never records. Images, uploaded files, memory, or the request records described in What is recorded about every request. It is your organization's own record, held under your policy, and Dropstone staff have no route into it.

Turning it on requires a second confirmation, and members must be told. See Turn on content logging.


Product telemetry

Whether anonymised usage signals from the organization may be used to improve Dropstone. Off by default for every organization, and the setting is enforced when data is collected rather than in the client, so an off organization contributes nothing even if an individual member has left their own preference on.

The page states the consequence in full: with it off, "Nothing from this organization is collected, and no code or conversation from it is ever used for training."


Data retention

How long conversations, telemetry and usage records are kept before deletion. Choose 30 days, 90 days, 1 year, a custom number of days, or no limit.

Audit events are exempt from this window, and the page says why: they are the record of what happened, and are kept for the life of the contract. A retention setting shortens what the organization holds; it does not shorten the record of who changed what.


What is never covered, at any setting

  • Uploaded files and images. No setting stores them for review. See What happens to the files you upload in a chat.
  • Memory. What members have taught Dropstone is governed separately, by its own sharing ladder. See Who can see and change your memory.
  • Usage records. The usage page shows counts and cost, never the contents of anyone's work, whatever the logging setting is.
  • A view for Dropstone. Nothing on this page gives Dropstone a way to read your organization's data.

Every change is recorded

Changing any of these three settings writes an entry to your audit log, naming the setting and the person who changed it. The Data page says so under each control, and the audit log cannot be edited or deleted from, by anyone. The log has its own page: The organization audit log.

What all of this adds up to over a year of use is the subject of How Dropstone compounds in an organization.


Related articles

Ctrl+I