Feature
Keep sessions private by default, encrypt raw session details on Paid and Enterprise, review sensitive content, choose where data lives, and export or delete it on your terms.
Control layer
Captured sessions belong to your account first. Nothing is shared, sold, or used for training unless you explicitly choose to do that later.
RCLM flags credentials, tokens, passwords, connection strings, and other risky content so you can review sessions before sharing, exporting, or using them in team workflows.
You can apply redaction rules so sensitive material is handled consistently instead of relying on one-off manual cleanup.
Paid users and Enterprise organizations can encrypt full session blobs while metadata remains available for search, stats, summaries, and filters.
Your history is portable. Export what you want, delete what you want, and avoid lock-in if your needs change.
Core controls
AI sessions often contain the exact material people would never deliberately publish: internal code, credentials, infrastructure details, and personal information.
The product stance here is simple: capture can be powerful without being reckless, and privacy controls should be part of the default workflow rather than a cleanup step after the fact.
When session encryption is enabled, the detailed session blob is encrypted. Derived metadata stays unencrypted so search, stats, summaries, filters, and dashboards can keep working without opening every full transcript.
Why it matters
The problem is not only storage. It is that AI sessions often contain code, schemas, credentials, or personal details that should not be treated like disposable chat logs.
If sessions may eventually be exported, shared internally, or used as team context, privacy controls cannot be an afterthought. They have to sit in the product before distribution.
Saying users own their data is incomplete unless they can decide where it lives, how it is protected, and when it leaves the system.
Raw transcripts need stronger storage protection, but metadata still needs to power search, summaries, stats, and governance views without decrypting every full session.
Lifecycle
01
Sessions are ingested from the proxy, hooks, or browser extension.
02
Potentially sensitive content is identified so risky sessions stand out for review.
03
You decide whether to keep private, encrypt raw session storage, redact, export, delete, or share later.
04
Enterprise deployments can add org-wide encryption, decrypt-access policy, residency controls, and on-prem boundaries.
Outcomes
Privacy and control are not side features. They are what make durable session storage viable for serious work.
That applies equally to individual users protecting their own workflows and to organizations that need clearer rules around what AI tools can retain and expose.
Capture useful work, review sensitive sessions, and decide what stays private, what gets shared, and what gets deleted.