Privacy by Default
Velatir starts from Never: the raw prompt and response are not stored. You still get a generalized description of the interaction, the agent outcome, and a full audit trail. An organisation admin can keep raw content when it is needed — always, or only when an agent flags the interaction — and choose how long records live.What Happens to an Interaction
It is captured
When someone uses an AI service Velatir monitors, the interaction is sent to Velatir so your agents can review it. Velatir does not collect browsing history, cookies, credentials, or local files.
Agents review it in memory
Your agents assess the prompt in flight — in memory — and allow, flag, or block it. The raw wording is not written to storage for that review.
What is kept depends on you
A generalized description is always stored. Raw prompts and responses are written to storage only if you choose When flagged or Always. See Data storage & encryption for how that stored data is protected.
Under Never, the default, the raw prompt never hits disk. It is processed in memory and discarded after review. When flagged and Always are the opt-ins that persist it.
Session Content
Store trace data in sessions controls when raw prompts and responses are kept. The default is Never.Generalized Summaries
Every interaction gets a short, generalized Description, even when raw content is not stored. That is what you see in the session list and on the Summary tab. The description says what kind of request it was, not the actual words. Names, companies, numbers, identifiers, URLs, and verbatim excerpts are replaced with generic terms — for example, “The user is asking the assistant to draft an email to a colleague.”What the summary is for
What the summary is for
It keeps the session list useful under Never, and it is the record of the interaction when you choose not to keep the raw prompt.
What it does not include
What it does not include
It is written to drop specifics. It is not a copy of the prompt, and it is not covered by a customer-held encryption key — those keys protect stored Context, not the Description.
How Long Data Is Kept
Data retention period controls how long session records live — the description, assessments, and any raw content you chose to keep. The default is Always.
Changing from Always to a bounded period starts a seven-day grace period, so a misclick does not wipe history immediately. Settings shows the next deletion date; change the period before that date to prevent it.
Storage mode and retention are independent: one decides whether raw content exists, the other decides how long the record lives.
Configure It
Open organisation settings
Go to Settings → General and find the Data & privacy section.
Choose when to store raw content
Set Store trace data in sessions to Never, When flagged, or Always.
Choose how long to keep records
Set Data retention period to Always, or to 6, 12, 24, or 36 months.
What Is Recorded
Velatir keeps an internal record of account activity so there is a trail for reviews and support. That includes member invitations and role changes, organisation and workspace settings updates, agent configuration and instruction changes, and who was notified of a high-criticality finding. This record is not a dashboard you can browse today. What you work from day to day is Sessions, Assessments, and data exports. Channel notifications do not have an approve/decline workflow — see Escalations.Support Access
Velatir’s team has no access to your account by default. No one at Velatir can view your data, traces, or settings unless you grant access under Settings → Support, and revoking it takes effect immediately.EU-Based Infrastructure
Velatir runs entirely on EU-based infrastructure. Your data stays within the European Union, which supports data residency and sovereignty requirements and aligns with GDPR. There are no data transfers to non-EU jurisdictions.Data storage & encryption
What is stored, and how it is protected.
Roles & permissions
Control who can see and change what.
Redaction
Strip sensitive content from pasted text, on the device, before it is sent.