Data Catalog

Last updated: June 8, 2026

This catalog sets out the retention specification for the customer data that VATES (operated by STANDOUT Inc.) processes. VATES selects retention periods by referring to the strictest standard among the regulations of every jurisdiction where your data may be relevant (EU, UK, Japan, California, China, Brazil, Korea, Singapore, Canada, Australia, and others). Your data is governed by the most protective baseline regardless of your location. This specification is generated from the canonical source that drives our code, so it never drifts from actual behavior.

1. Account & Organization

Customer account state

The lifecycle state of your account as a whole (active, suspended, and so on).

Instance state

The lifecycle state of each instance you create.

User accounts (including personal data)

User account information, including personal data such as login ID, display name, and credentials.

User–instance access links

The link between a user and the instances they may use. Deleted together with the account.

API keys

Issued API keys. Stored only as an irreversible hash; the plaintext is never retained.

Revoked sessions

Revoked login sessions, kept briefly so they cannot be reused.

2. Usage Logs

Conversation logs

End-user conversation history. Retention follows the plan you choose (Standard = 30 days / Zero retention = not retained).

Usage records (per-event)

Per-event usage records, used to calculate your charges.

Usage aggregates (billing basis)

Aggregated usage totals that form the basis of billing. Subject to statutory retention.

3. Balance & Billing (legally retained)

Customer balance

Your prepaid balance — the settled record of payment. Retained for the statutory period and not pseudonymized.

Balance history (transactions)

The change history of your balance. Transaction amount, currency, and rate are retained for the statutory period (only the operator name is pseudonymized).

4. Audit Logs

Instance audit log

Your instance audit log: a tamper-evident record of security-relevant events.

5. Your Knowledge Assets & Settings

ES-IFM knowledge assets

Your ES-IFM knowledge assets — your intellectual property. When you delete your account, these assets follow the standard deletion lifecycle and are physically deleted after the retention period.

Instance settings

Instance settings such as branding, limits, and prompts.

Shell settings

Shell settings that reference the central master configuration.

Client-wide settings

Your client-wide default settings.

This specification is generated from the canonical data catalog. The complete technical specification for each data type (physical location, deletion function, legal basis) is also available in the "Data lifecycle" screen of the console.