Skip to main content
Security, Privacy & Data

Usage Data Retention

StackJack attempts to create a usage and audit record for each tool call your AI assistants make (see Where to See Your Usage). A normal successful-call record contains metadata such as the tool,…

Written By Christopher Scaminaci

Last updated 3 days ago

StackJack attempts to create a usage and audit record for each tool call your AI assistants make (see Where to See Your Usage). A normal successful-call record contains metadata such as the tool, connector, client or user, duration, timestamp, routing method, and outcome. The usage record does not contain the tool's request body, and does not contain the response body of a successful call.

A failed call additionally carries a free-text error detail, bounded at 2,000 characters. That detail is either text produced locally — a gate refusal (an allowance or plan gate, a tool not enabled for the client), a timeout, a temporary connector block, a network fault, malformed input — or, when an upstream API rejected the call, StackJack's own summary line followed by the provider's error message, so support can diagnose the failure without asking you to reproduce it. Redaction is scoped to that provider response, the only part of the detail that came from outside StackJack: recognized credential material is replaced with a redaction marker before the text is stored.

StackJack still does not store the call's request parameters or the body a tool returned. What it stores on a failure is a diagnostic message, and a vendor writes its own. A provider's message can name a record, quote a field, or repeat a value it was given, so an error detail can contain customer or personal information even though the payload itself was never recorded. The redaction marker targets credential patterns; it is not a general removal of personal data. See What usage records contain.

Audit rows also identify tenant activity, tools, clients, and attributed members, so treat audit-log access and exports as sensitive.

How long records are kept

StackJack keeps usage records for as long as your organization is active. They are removed when the organization is deleted.

If you have a specific compliance or data-retention requirement (a guaranteed window, or an export), contact StackJack support.

How reliably records are written

Usage records are written in the background, and a record can occasionally be missing. Do not use usage views as the only evidence for a requirement that demands complete capture.