01
Deletion controls
Memory export, reset, and delete controls should remain available from Memory Vault. Other deletion requests should be handled through privacy settings or support paths.
02
Confirmation
Destructive data actions should use clear confirmation and, where enabled, recent MFA requirements.
03
Current status
This is a product placeholder for launch planning. It describes intended controls and user-facing expectations, not final legal advice.
04
Private by default
Obrasken private workspace data should remain private unless the user intentionally chooses a secure sharing or export workflow.
05
Security boundary
Provider keys, service-role credentials, payment data, and other secrets must remain server-side and must not be exposed in browser code or logs.