Memory, privacy, retention, and deletion
Availability: The AutoMCP production service is not yet deployed. This page and its examples describe the committed v1 contract for integration planning; requests to the API URL will not succeed until the runtime is released.
Memory is scoped to one app and customer user and can cross that user’s sessions. It may contain user-stated preferences and facts, but never credentials, payment or health data, system instructions, or tool-response bodies. Memory is context, not authorization.
Users can list, update, delete individual items, clear all memory, or disable memory. Disabled memory is neither read nor written. If bounded extraction fails, the Run result remains valid, a memory_warning is reported, and nothing from that turn is stored.
Deleting a session deletes memory and summaries derived from it. An item with multiple source sessions is removed as a whole when any source session is deleted. Deletion fences prevent pending extraction or retry work from recreating deleted data. App/customer-user deletion and workspace archive immediately block access, cancel work where possible, revoke tokens/keys, disable webhooks, and schedule cleanup.
Conversation, memory, Run, and tool payloads are encrypted at rest; original voice audio is not stored. Retention and cleanup are finite environment settings with no production default selected here. Minimal audit and settlement evidence follows its separately configured retention period.