Data Retention Policy
Last updated: 21 September 2026
Prisma Connect is a pass-through layer between accounts you connect and an AI assistant you choose. We retain the account and connection records needed to operate the service, but do not keep connected source content in durable storage.
Live account record
While your account is active, our database stores:
- Identity: email address and account creation time.
- Workspace structure: company or group names and connector-account names.
- Connection secrets: provider OAuth refresh tokens and connector API credentials, encrypted at rest with AES-256-GCM.
- Preferences: enabled connectors and tools, settings, and privacy choices.
- Service state: random MCP credentials, plan and connector entitlements, and Stripe customer and subscription identifiers. Full payment-card details are not stored by Prisma Connect.
These records remain for the life of your account. Encrypted connection secrets in a database copy cannot be read without the separate encryption key.
Connected source content
- Never stored durably: emails, documents, files, analytics reports, advertising data, calendar events, commerce records, and other provider responses are fetched for the request, returned to your agent, and discarded rather than written to our database, backups, or application logs.
- Google is always live: Google API results are not cached by Prisma Connect, even if an older account record contains a previous cache preference.
- Other connectors: an optional cache, off by default, can hold a tool result in non-persistent Redis memory for 15 minutes or one hour. It expires automatically and is also wiped when its MCP session ends.
- Pseudonymization maps: token-to-value mappings exist only in session memory and are destroyed with the session. Stability comes from a derived per-account key, not a stored lookup table.
- Prompts and AI responses: Prisma Connect does not store them.
Encrypted backups
We create encrypted database backups for disaster recovery. They contain the live account record described above at the time of backup, but not connected source content. The backup process refuses to retain or upload an unencrypted copy. Local and configured off-site copies are automatically rotated after approximately 14 days and are used only to recover the service after data loss or corruption.
Logs
Application logs contain operational metadata only: method, request path with secret URL tokens redacted, status, latency, connector and tool name, and error class. They never contain request or response bodies. Container logs rotate and are size-capped at about 30 MB per service. Our reverse proxy does not enable web access logging. Infrastructure and edge-security providers can separately process ordinary network metadata, such as IP address, user agent, request headers, and network-error reports, under their own retention terms.
Session cookie
The strictly necessary signed cookie that keeps you logged in expires after 30 days. Signing out or deleting your account clears it in your browser. MCP sessions close after inactivity and their in-memory pseudonymization maps and temporary caches are wiped.
Deleting your account
From Connect → Delete account, you can permanently remove the live account. Prisma Connect attempts to revoke each Google token, closes live MCP sessions, wipes their temporary caches, removes the database record and its companies, connector accounts, settings, billing identifiers, and encrypted credentials, and clears the browser session. A recovery backup may retain the deleted account record for up to approximately 14 days before rotation; it contains no connected source content.