Guides
Data handling
Who can read a Spec conversation, how long it is kept, how to delete it, and what leaves Parcel.
A conversation belongs to its creator
A Spec conversation is visible to the member who created it. Not to their colleagues, not to a workspace admin, not to Parcel support through a product path.
There is no administrator screen that shows conversation content. This is not a permission that is switched off; there is no route that returns it.
What an administrator CAN see is that work happened: how many runs, what they cost, which tools ran, and whether an action was approved or denied. What an administrator CAN do is delete, including deleting on behalf of a member who has left. Delete without read is the whole shape of the admin power here.
Deleting
| You want to | Where |
|---|---|
| Delete one conversation | the conversation menu in the sidebar |
| Delete all of your conversations | the same menu, Delete all |
| Delete a Personal skill | the Skills page |
| Remove a member and their content | Members settings |
Deletion cascades. Deleting a conversation deletes its messages, its context snapshots, its tool execution records, its approvals, and its compactions.
Three things survive on purpose:
- Usage and billing records. What a run cost is a financial record, and it is kept without the content that produced it.
- Audit records. That an action was approved and executed is kept, again without content.
- A skill version a past conversation used. Deleting a skill removes it from the Skills page and from every list, search, and load at once, and its editable draft goes immediately. The published version a past conversation loaded is kept while that conversation exists, because that conversation’s record of what it ran points at it. Nothing reads it again: the version is removed with the last conversation that used it. Delete that conversation and the skill is gone entirely.
Deleting is a job, not an instant erase: it is queued and drained on a schedule, and it retries until it finishes. Your conversation disappears from your view immediately.
Delete all, and an administrator’s delete on behalf of a member, cover the conversations that exist at the moment the request is made. A chat started after that request is not part of it, and stays until you delete it or retention reaches it.
The same window applies to the rest of an administrator’s purge of a member who is still in the workspace: it takes the Personal skills and the member’s own connections that existed when the request was made. Anything added after that stays until the next purge, or until the member is removed from the workspace, which covers everything they have.
Retention
By default a workspace keeps Spec conversations until someone deletes them.
A workspace can instead choose an automatic retention window of 30, 90, or 365 days. Conversations older than the window are deleted by a scheduled sweep, in bounded batches, fairly across workspaces so a large workspace cannot starve a small one.
One exception, and it is deliberate: a conversation whose run still has an approval waiting on a person, or one being carried out, is not swept while that approval is live, because the approval is that run’s record of a decision that has not been made yet. Once the approval is decided or its window lapses, the next sweep takes the conversation like any other. An action interrupted midway does not hold a conversation forever: a scheduled sweep marks an approval whose execution has gone quiet for 15 minutes as failed, and the next retention pass takes that conversation like any other.
When someone leaves
Removing a member does several things in one transaction:
- Their in-flight runs are settled, so credits are not left reserved.
- Their Personal skills are purged.
- Workspace skills they created SURVIVE, because they belong to the workspace. Maintainership can be transferred.
- Their authoring sessions are cleaned up.
- Their conversations are queued for deletion.
What leaves Parcel
Three destinations, and what each one receives:
| Destination | Receives | Never receives |
|---|---|---|
| The model provider, through Parcel’s AI gateway | the conversation content needed to answer | anything Parcel retains a copy of at the gateway: payload logging is off and responses are not cached across members |
| Product analytics | counts, durations, outcome codes, opaque identifiers | messages, tool arguments, tool results, connection payloads, skill bodies |
| Stripe | the amount charged and an opaque reference | anything about what the credits were spent on |
Error reports carry a code, never the text that produced the error. An error that cannot be described without content is described by its code alone.
Secrets in what you send
Spec refuses a message that contains something shaped like a credential, before it is stored and before any model sees it. The refusal names the kind of secret and nothing else, so the refusal itself does not become a place a secret is written down. See Connections and security.
The scan covers what you SEND, not what a connected system sends BACK. A credential returned inside a tool result is not removed. This limitation is published rather than hidden, and closing it is future work.
Data you can export
Usage and billing history is available in Billing and Usage settings. Conversation content is yours to read in the product; it is not exposed through the admin surface to anyone else.