Appearance
Files, retention, and deletion
The proposed pilot supports bounded UTF-8 text and JSON files, up to 10 MiB decoded. Upload requests use the contract's base64 JSON envelope. Files stay quarantined until validation and scanning finish. Only available files can enter a run.
Downloads are authenticated and proxied; there are no public signed file URLs. The owning tenant/environment/workspace is checked at access time. Never turn an arbitrary model-generated path into a download URL.
Retention defaults
| Data | Proposed retention |
|---|---|
| Conversation content and files | 30 days; configurable to 7, 30, or 90 |
| Safety journals and audit | 90 days |
| Billing metadata | 13 months |
| Backups | 30 days |
Environment storage is bounded to 1 GiB initially. Explicit agent-scoped memory and managed connector OAuth are future additions, not implicit cross-user memory.
Delete with a receipt
Deletion immediately denies access, cancels pending work, and revokes affected approvals/connections. A deletion job records progress; live data purge targets 24 hours. Backup expiry is disclosed separately. Restored cells replay the deletion journal before serving traffic.
Deleting Mystro data does not delete customer-owned downstream records. Your app remains responsible for its own data and for any actions already committed in its tools.