Privacy
How the current DialogArc pilot minimizes, retains and protects workspace data.
Data used by the service
DialogArc processes workspace membership, configured automation, Instagram connection metadata, comment-derived text and delivery evidence needed to operate the private-first workflow. Provider credentials, ciphertext and raw provider response bodies are not returned to the browser.
Default retention
- Raw webhook data: 7 days.
- Normalized comment or source text: 30 days.
- Failed-job diagnostics: 14 days.
- Delivery metadata and provider identifiers: 180 days.
- Security audit records: 365 days, subject to legal hold.
- Non-identifying aggregates may be retained indefinitely.
A legal hold must be explicit, narrowly scoped, auditable and time-bounded where possible.
Workspace controls
An Owner may request a workspace export or workspace deletion. Owners and Administrators may remove a connection. These privileged operations require a current membership and recent verified authentication.