Data Handling
What Trappr stores, where it's stored, how long we keep it, and how you can control or delete it.
What Trappr stores
| Data type | What is stored | Retention |
|---|---|---|
| Gateway logs | Model, token count, latency, timestamp, execution ID. Message content is not stored by default. | 30 days (standard), 1 year (Enterprise) |
| DLP events | Pattern category, match count, timestamp. Matched values are not stored. | 90 days |
| Incidents | Incident type, execution ID, timestamp, severity. No message content. | 1 year |
| Execution records | Start/end time, status, token count, event list, metadata you provide. | 90 days (standard), 1 year (Enterprise) |
| Provider keys | AES-256-GCM encrypted ciphertext only. | Until you delete them |
Where data is processed
Trappr processes and stores data in the United States. For Enterprise customers requiring EU data residency or other specific regions, contact us at hello@trappr.io.
Data isolation
All data is isolated per workspace. No data from one workspace is accessible to another, even within the same organization. Workspace isolation is enforced at the database level, not just via application logic.
Deleting your data
You can delete data at any time:
- Individual incidents — delete from Dashboard → Incidents
- Gateway logs — bulk delete by date range from Dashboard → Gateway → Logs
- Your entire account — email hello@trappr.io to request full account deletion
Account deletion permanently removes all data within 30 days.
Third-party subprocessors
Trappr uses a minimal set of infrastructure subprocessors for hosting and delivery. We do not share your data with third parties for advertising or analytics purposes. For the full subprocessor list, see our Security overview.