Skip to content
indraft
Start free

Documentation

What we store

Indraft holds personal data about people who have no relationship with us: your customers never chose us, and most will never hear of us. That makes deletion and export legal obligations rather than features, and it makes what we DO NOT accept as important as what we do.

What Indraft never stores

There is no path into Indraft for any of these. They are not filtered out; there is no field to put them in.

  • Email bodies. Not the text, not the HTML, not a copy.
  • Call transcripts and recordings. Neither the audio nor the text.
  • Attachments and files of any kind.
  • Arbitrary blobs. There is no free-form document store.

An interaction is a SUMMARY that you or your agent write, up to 4000 characters, optionally with a bounded evidence snippet of up to 2000 characters. Indraft does not connect to your inbox and does not ingest mail.

What Indraft does store

  • The CRM records you and your agents create: companies, contacts, opportunities, tasks.
  • Interaction summaries with their actor, their assertion kind, and their source where one was given.
  • The full change ledger: who changed what, when, from which surface, and the previous value. This is append-only and is what makes provenance and undo possible.
  • Control-plane data outside your workspace: the mapping to your organization, credential hashes, the billing snapshot, webhook receipts, and usage counters. No CRM record lives there.

Where it lives

Each workspace has its own database. That is a hard boundary rather than a filtered view of a shared one: a request that resolved to the wrong workspace would reach a different database entirely, so it cannot read another customer's rows even by accident.

Deletion

Deleting a workspace destroys the records, the ledger, and the search index, including the index's own residue. That last part is easy to miss: a full-text index keeps deleted terms in its storage until it is compacted, so an erased contact's email can remain readable in the index long after the record is gone. Indraft compacts on deletion for exactly that reason.

Deletion is scheduled rather than immediate, with a cancellation window, because an accidental deletion that runs instantly is not recoverable by anyone.

Retention, and what the window measures from

The free plan keeps interactions for 90 days and change history for 90 days. Every paid plan keeps both for as long as you keep the workspace, so nothing on a paid plan ages out on a schedule.

Where a window applies, it runs from when the record LANDED in Indraft, not from the date of the thing it describes. An agent writing up a call from three months ago starts that interaction's clock today.

The distinction is not academic. Measured the other way, backfilling a year of customer history onto a plan that keeps interactions for ninety days would delete three quarters of it in the first sweep after it arrived, which is the opposite of what anybody backfilling wants. Nothing is ever removed without the window having actually elapsed in Indraft, and the application shows what is due to age out before it does.

Change history is separate from interactions and is never trimmed as a response to capacity pressure. Losing the explanation for an older value would break the claim the product is built on.