Documentation
Data Retention and Sharing
Retention is part of the product boundary: expired results stop being available, and every Share Link is limited by the result it exposes.
Current retention windows
| Feature | Availability |
|---|---|
| Guest result | 24 hours from Guest Scan creation |
| Free Workspace result | 30 days after completion |
| Share Link | Until the retained result expires or the link is revoked |
A Guest result is available only through its browser-bound access capability. Creating an account before expiry can claim that result into the new Free Workspace without recalculating it.
Bounded evidence retention
Semantic evidence retains only the minimum copied excerpts needed to explain an artifact or finding: at most 240 characters per excerpt, three references per item, and 12,000 aggregate excerpt characters per Page Scan after deduplication. Higher-severity and score-affecting evidence is kept first when the aggregate cap is reached, and omitted evidence is disclosed.
Copied excerpts expire after 90 days or earlier when the Page Scan or Workspace is deleted. Rubric output and source-field/location metadata remain with the retained scan so a finding stays explainable after an excerpt expires. The report discloses that expiry rather than reconstructing the page.
Full raw HTML, full normalized page text, unrestricted prompts, raw provider or model responses, credentials, /llms.txt file bodies, linked-resource bodies, screenshots, traces, and unbounded diagnostics are prohibited retained data.
Origin-level llms.txt evidence
The bounded /llms.txt outcome, fetch timestamp, resolved URL, site identity, and linked-resource resolvability can be cached for 24 hours and reused across scans of the same origin. A requested recheck bypasses that cache. Missing, invalid, unusable, materially stale, or misleading files receive one shared maximum deduction; subsection failures do not stack.
Saved results remain versioned
Every saved result retains its Evaluation Version and original assessment output. A newer rubric does not silently alter an older result. Rescanning creates a new result that can be compared with the latest earlier retained scan of the same page.
Only exact same-version results are comparable. Score ranges are an improvement only when the newer range lies entirely above the older range; overlap is inconclusive, and different evaluation generations are not comparable.
When a Free result reaches its retention boundary, its report and dependent Share Links are no longer available. The Website grouping remains only while it still has retained Page Scans.
Read-only Share Links
What recipients can do
Anyone with an active link can open the immutable assessment result without joining the Workspace. The link does not grant Workspace membership or editing access.
What managers control
Owners and Admins can create multiple isolated links and revoke each one independently. Members can read retained reports but do not see Share Link management.
- The raw Share Link token is shown only when a link is created.
- A stored digest, rather than the raw bearer token, identifies the link.
- Revocation takes effect independently for each link.
- Every link stops working when its underlying result expires.
Workspace data export
The active Workspace Owner can download one private ZIP archive from Account Settings. The archive captures one consistent snapshot of the Workspace's retained Page Scans and Websites, including URLs, scan state and timing, scores, findings, recommendations, and the Evaluation Version manifest needed to interpret every result.
- The archive contains versioned JSON and CSV files plus a schema identifier, generation timestamp, and Evaluation Version manifest.
- Partial Results do not receive a Page Optimization Score in the export.
- Expired results, deleted records, other Workspaces, credentials, provider payloads, raw HTML, and operational diagnostics are not included.
- The download is generated on request, is not stored at a public URL, and is available only to the active Workspace Owner.
Permanent Workspace deletion
The active Workspace Owner can permanently delete that Workspace from Account Settings. FutureContent offers the private ZIP export first, then requires an explicit choice to continue, the exact current Workspace name, and a live authentication session created within the previous 15 minutes.
- Deletion removes memberships, invitations, Websites, Page Scans, results and evidence, findings, recommendations, Share Links, usage history, and Workspace configuration in one transaction.
- Queued and running work loses its Workspace boundary and cannot publish late results after deletion. Existing Share Links stop working when deletion commits.
- User accounts, profiles, Auth sessions, other Workspaces, and their retained data are preserved. Affected users move to their sole remaining Workspace or return to Workspace selection.
- The deletion is irreversible and cannot restore expired data.
Personal data and account retention
Result windows are not the complete privacy policy. Account, Workspace, security, provider, and legal records have purpose-specific handling. Read the Privacy Policy for those details.
Account Settings provides permanent self-service Account deletion after recent authentication and exact Account-ID confirmation. An Account that still owns a Workspace cannot be deleted; delete that Workspace or transfer its ownership first. Successful deletion ends the User's sessions and removes their personal access and associations without deleting another User's shared Workspace or linking retained aggregate metrics back to the deleted Account.