Help Center

Docs

AI Assistant Data Privacy

How Laureo scopes, protects, and retains Assistant data

Your current access is the boundary

The Assistant acts as you, inside your organization.

Laureo checks your organization, membership, seat, role, plan, feature access, and record scope before a capability runs. It checks them again immediately before an irreversible effect. If authorization data cannot be read safely, the action does not run.

Conversations and drafts are private to your account. Record and file references remain subject to their source permissions, so a revoked or deleted item cannot be recovered through an old chat.

Context is snapshotted per command

Removing a chip changes future messages, not history or source data.

Add context can reference an uploaded file, an existing CRM file, or a record such as a person, deal, quote, campaign, or product. Laureo snapshots the active references when the server accepts each command. Removing a chip later does not change that snapshot and never deletes the source CRM file or record.

  • Up to 10 references per command.
  • Up to about 16 pages of text per reference, and about 53 pages across one command.
  • Your plan's file size, storage, and usage limits still apply.

Uploads are quarantined and scanned

Unsafe or unsupported bytes never enter an Assistant prompt.

New uploads enter private quarantine. Laureo verifies the signed-in user and organization, plan and quota, declared and observed file type, archive expansion limits, and an antivirus result. Scanner outages fail closed. Only the server-side scanner may promote an immutable file hash and verdict; authenticated clients cannot write directly to promoted storage.

Text extraction currently supports UTF-8 text, Markdown, CSV, JSON, XLSX, DOCX, PPTX, and a strict standard-text PDF subset. Encrypted files, unsafe archives, active content, image-only PDFs, PDFs with unsupported embedded or custom-font text, and unsupported Office layouts produce an actionable error and are not sent to the model.

On the Business plan and above, PNG, JPEG, WebP, and GIF images are read as images. They pass the same quarantine, type check, and antivirus scan as every other upload first, and they travel only on a route certified under the retention-restricted policy, so they are never used to train shared models and are not kept by the model. Other image formats, and every image on a plan that does not carry the capability, are refused before anything is stored.

Before every run and tool hop, Laureo rechecks tenant, role, plan, record scope, deletion or revocation status, and the immutable file hash. Extracted text is always treated as untrusted input, and that caution remains attached through later tool calls and approvals.

Inference routes are restricted

Requests fail closed when no eligible route is available.

A model receives your command plus only the CRM and attachment context needed for that request. Laureo uses routes certified under its retention-restricted policy and does not use your content to train shared models. If no eligible route is available for the requested capability, Laureo returns a recoverable error instead of silently using a less restrictive route.

Requests count against your organization's AI budget. Usage reservations, settlements, and receipts are recorded separately so a missing receipt cannot turn a partially completed run into free or duplicated work.

A request carrying an image is routed only to models that were separately confirmed to accept image input on a retention-restricted route, so it is never quietly handed to a text-only model that could not read the picture. That confirmation is rechecked automatically, and the capability closes rather than degrades if it stops holding.

Private model reasoning is never exposed or retained

You see useful progress labels, not hidden provider traces.

Laureo records deterministic activity such as "Checking catalog," "Preparing quote," and "Waiting for approval." Raw model reasoning is excluded from conversation storage, event streams, realtime updates, logs, exports, and the page itself.

Tool arguments, approval parameters, provider receipts, secrets, database errors, and internal identifiers are also removed from browser-facing events. Artifact and effect cards use a safe public projection instead.

History, retention, and deletion

Deleting a conversation fences active work before removing it.

Conversation history, approvals, receipts, attachment references, and run events are stored in Laureo so work can survive a disconnected browser and remain auditable. Quarantined uploads are cleaned up by a server-owned retention job according to the configured policy.

When you delete a conversation, Laureo first stops and fences active work and invalidates pending proposals. If an external provider already accepted an effect, the minimal audit record remains until reconciliation reaches an honest terminal state; then the conversation can be purged without leaving an approvable orphan.

Saved preferences remain private to your account and affect future requests only. See AI Preferences to review or remove them.