Data retention, exports, and usage accounting.
Data retention and usage
With enforcement disabled, organizations retain the existing 90-day default and 30–365-day setting. With billing enforcement enabled, plan limits below apply. The platform worker starts at most one cleanup batch per organization per hour and removes up to 25 eligible completed runs. It skips unfinished runs, queued or leased work, and runs referenced by active recovery jobs. The polling fallback can remain during rollout; cleanup does not require customer polling once the platform worker is running. This is a bounded sweep, not a precise deletion deadline.
Deleting a run also removes its steps, attempts, encrypted durable input, encrypted idempotent result, and idempotency lookup. After deletion, duplicate keys for that run no longer deduplicate, and replay is unavailable. Export needed history before it expires. Audit events, operational incidents, published contracts, accounts, keys, and aggregate monthly usage remain. Incident links to expired runs may no longer resolve. Changing retention to a shorter period takes effect at the next sweep and is irreversible after deletion. No unfinished work is removed by retention.
Monthly usage is kept separately from run history, in UTC calendar months. Units are runs (accepted non-synthetic agent executions), steps (accepted non-synthetic logical tool calls, including calls blocked by a circuit), attempts (actual non-synthetic invocations), and synthetic runs (test executions). A retry or reclaimed lease adds an attempt; a deduplicated request adds nothing. Counts are incremented in the same transaction as the related record. The migration backfills counts for existing rows. Attempts enforce the monthly allowance when billing enforcement is enabled; see plans and billing.
The Settings page shows the most recent 12 months. GET /api/console/data-lifecycle returns the same organization-scoped data; owners and admins can PUT {"retentionDays":90} with a same-origin session. The sweep audit record stores only the number of runs purged, with no payload data.
Plan-aware retention
With billing enforcement enabled, Free retains completed history for 7 days, Basic for 30, and Pro for 30–365 (default 90). The platform maintenance worker advances bounded cleanup independently of customer polls. Downgrades protect history and allow exports for 14 days; Settings → Billing shows the exact UTC date. See billing and platform maintenance. Existing queued work is never deleted to enforce usage quotas.