> ## Documentation Index
> Fetch the complete documentation index at: https://docs.daoco.org/llms.txt
> Use this file to discover all available pages before exploring further.

# Privacy and data deletion

> Choose whether daoco may learn from your workspace, and delete a brand, a workspace, or your account with a durable receipt.

daoco keeps two kinds of records about a workspace: the content you create (brand context, drafts, posts, assets, chat transcripts) and the agent's own working record (which runtime handled a request, which tools ran, how the run ended, how you rated it). Both are yours. This page covers the controls over each.

## Help improve daoco

Open **Settings**, then the **Teams** tab. The **Privacy** card holds one switch, **Help improve daoco**. Only a workspace owner or admin on the Growth plan can see the Teams tab, so this switch is a Growth control. On Starter it stays at its default of on.

| Setting      | What daoco keeps                                                                                                                        | What deletion does                                                                         |
| ------------ | --------------------------------------------------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------ |
| On (default) | Prompts, outputs, and agent activity may be used to improve the product.                                                                | A deletion form preselects keeping an anonymized copy of the agent's working record.       |
| Off          | Diagnostics store only ids, timings, token counts, decisions, and error classes. They do not store prompts, outputs, or tool arguments. | A deletion form preselects removing the agent's working record along with everything else. |

The switch sets the starting point for each deletion form, not the outcome. You choose again at the moment you delete.

Errors are still recorded either way so support can help you. With the switch off they carry no content, only the error class, the runtime it happened in, and timing.

This switch has no effect on how model requests are routed. That is unconditional: OpenRouter requests always require a zero-data-retention endpoint and always deny routing to providers that may collect request data.

## Delete a brand

Only the brand's owner sees this control. A workspace admin who does not own the brand cannot delete it.

1. Open **Settings**, then **Brands**, and pick the brand.
2. Under **Delete brand**, type the brand's exact name. Capitalization must match.
3. Under **After deletion**, choose **Delete all agent data** or **Help improve daoco**. The preselected option follows the workspace's **Help improve daoco** setting.
4. Confirm.

daoco records a deletion receipt and removes the brand's content, assets, connected-account records, active storage, and search indexes in the background. Access to the brand is blocked from the moment you confirm. While cleanup runs, the brand stays in the **Brands** list as a disabled row marked **Deleting** and drops out of navigation, defaults, and your brand count right away. Deleting a brand never touches the workspace's billing account.

If you choose **Help improve daoco**, daoco keeps two things under a random key that is not linked to the brand, the workspace, or a person:

* **How the agent worked.** The working record is rewritten with every approval title, note, and artifact reference cleared. What remains is the shape of the work: runtimes, tool order, outcomes, and ratings.
* **A redacted copy of the conversation.** Before the thread is deleted, daoco takes a copy of its messages and runs a redaction pass over the text. The pass strips the brand and product names, the names and emails of everyone on the workspace, connected-account handles, and anything that looks like an email, link, @handle, phone number, IP address, long number, or credential. Tool inputs and outputs are dropped; only tool names are kept. If a thread cannot be read and redacted, it is deleted without a copy.

Redaction is deterministic and versioned. Each retained record says which rules produced it, and the receipt reports how many conversations were kept. A very long thread is copied up to its first 2,000 messages.

A brand that is the only brand in the workspace cannot be deleted from the dashboard. Create another brand first, or use workspace deletion below.

## Switching from Growth to Starter

Starter holds two brands. If your workspace has more, the downgrade dialog asks you to pick the brand to keep and then permanently deletes the brands above the Starter limit.

That deletion always keeps the anonymized agent data described above. It does not offer the **After deletion** choice, and the workspace's **Help improve daoco** setting does not change it. Delete a brand yourself first if you want the other outcome.

## Delete a workspace or your account

Go to [daoco.org/data-deletion](https://daoco.org/data-deletion) while signed in.

* **Workspace**: the owner types the workspace's exact name, with no extra spaces and matching capitalization. Only an owner can do this; an admin cannot. daoco deletes every brand in it, then the workspace's assistant configuration, channels, memories, memberships, billing customer, and WorkOS organization.
* **Account**: type your email address. daoco deletes your memberships and personal preferences, your WorkOS login, and your product-analytics profile (if the analytics provider's deletion API is unavailable, the receipt lists it as an exception and daoco completes it by hand). Workspaces owned by someone else keep their content. If you own any workspace, you must tick **Also permanently delete my owned workspaces** to continue; you cannot delete your account and leave a workspace you own behind.

Both forms carry a **Keep anonymized agent data** checkbox that does the same thing as the brand choice. On the account form it appears only after you tick the owned-workspaces box, and it starts ticked only when every workspace you own has **Help improve daoco** on.

If a deletion fails and you start it again, retype the confirmation. A request that is still running keeps the anonymized-data choice you confirmed the first time; only a failed request takes a new one.

## Reading the receipt

Workspace and account deletions show a receipt with the current stage, rows deleted, rows anonymized, conversations kept, and any retained-data exceptions. Exceptions name records daoco cannot erase immediately: provider backups that age out on their own schedule, billing and security records kept where required by law, and third-party cleanups that need a retry. The receipt is the record of what daoco did, not a claim that every third party has already purged its copy.

Because deleting your account ends your session, the account receipt stays readable from the same browser for 7 days. Brand deletion does not have a receipt page; it confirms with a short receipt id when the deletion starts. Keep that id if you need to ask us about it.
