Logging and retention
What Kiste logs, what it never logs, who can read logs and how long everything is kept.
Last updated: 6 October 2026
What is logged
Every component writes structured log lines with the time, the component, the event, an error code where there is one, and a request id. The CLI sends one request id per command, and it is carried from the CLI through kiste.run to the compute server. When you report a problem, that id lets us find exactly your request and nothing else.
Logs identify your account by a random account id, never by your e-mail address, and name a Kiste by its name.
Never logged: passwords, tokens, API keys, cookies, Authorization headers, payment secrets
and e-mail addresses. Redaction removes values under secret-looking keys and masks Kiste token
formats and e-mail addresses inside free text. Kiste does not log the contents of your Kisten,
your SSH sessions, your terminal or your desktop stream.
Your own audit trail
Security-relevant actions on your account (sign-ins, sign-outs, revoked sessions and computers, CLI approvals) are recorded as audit events. They let you and us reconstruct what happened to an account.
Who can read logs
Only the operator. Edge logs live in Cloudflare's logging for the kiste.run workers. Logs of the compute server stay on that server and can only be queried read-only, through an access-controlled path. Nothing about logs is exposed on the Internet.
Retention
| Data | Kept for |
|---|---|
| Edge logs (kiste.run) | 7 days |
| Compute server logs | 30 days (or 10 GiB, whichever comes first) |
| Audit events of your account | 12 months |
| Browser sessions | 7 days from sign-in, or until you sign out |
| CLI tokens | valid 30 days, deleted 30 days after expiry or revocation |
| Revoked or expired API keys | deleted 30 days later |
Command history (metadata of commands run with kiste exec) | 30 days after the command finished |
| Events and alerts of Kisten | 90 days |
| Webhook deliveries | 14 days |
| Payment event ids (de-duplication only) | 90 days |
| Disks and memory snapshots of Kisten | until you delete the Kiste |
| Off-site checkpoints | every checkpoint of the last hour, the newest per hour for 24 hours and the newest per day for 14 days; named snapshots until you delete them |
| Account data | until you delete the account |
| Payment records after account deletion | the statutory retention period for accounting records, without your e-mail address |
Every period above is enforced by an automatic job, not by hand. When a store is added or a period changes, this table and the privacy policy change with it.