Privacy and retention
Understand local evidence, operational telemetry, organization exports, and API submissions.
Local security analysis, organization governance, and hosted API scans use different data paths.
Local runtime evidence
Section titled “Local runtime evidence”The desktop app stores traces, audits, and historical runtime evidence locally. In Settings → Privacy, use Runtime Evidence Retention to choose 1, 3, 7, 30, or 90 days, or Always.
Shortening retention can delete existing evidence immediately after confirmation. If the app displays a Retention Enforcement Warning, follow it; selecting a shorter period does not confirm cleanup.
This setting controls local runtime history. It does not change the retention of data already exported to another system.
Operational telemetry
Section titled “Operational telemetry”The Operational Telemetry control in Privacy manages runtime-health and setup telemetry. This is separate from traffic inspection and from organization governance exports.
Organization data
Section titled “Organization data”Enrolled devices provide governance evidence for organization inventory, findings, and policy reporting. Security findings use minimized classifications and evidence references. Local traces and exported records have their own contents and data-handling requirements.
Review evidence and exports before storing or sharing exported data.
Hosted scans
Section titled “Hosted scans”Text or files explicitly submitted to the hosted API are sent to the Patronus service for analysis. Local desktop retention does not apply to those submissions.
Local ARK analysis also does not stop the AI application itself from sending prompts to its configured model provider. See local inference for that boundary.