> Documentation index: https://docs.kiste.run/llms.txt, a list of every page in this documentation.

# Logging and retention

> What Kiste logs, what it never logs, who can read logs and how long everything is kept.

## What is logged

Every component writes structured log lines with the time, the component, the event, an error
code where there is one, and a request id. The CLI sends one request id per command, and it is
carried from the CLI through kiste.run to the compute server. When you report a problem, that id
lets us find exactly your request and nothing else.

Logs identify your account by a **random account id**, never by your e-mail address, and name a
Kiste by its name.

**Never logged:** passwords, tokens, API keys, cookies, `Authorization` headers, payment secrets
and e-mail addresses. Redaction removes values under secret-looking keys and masks Kiste token
formats and e-mail addresses inside free text. Kiste does not log the contents of your Kisten,
your SSH sessions, your terminal or your desktop stream.

## Your own audit trail

Security-relevant actions on your account (sign-ins, sign-outs, revoked sessions and computers,
CLI approvals) are recorded as audit events. They let you and us reconstruct what happened to an
account.

## Who can read logs

Only the operator. Edge logs live in Cloudflare's logging for the kiste.run workers. Logs of the
compute server stay on that server and can only be queried read-only, through an access-controlled
path. Nothing about logs is exposed on the Internet.

## Retention

| Data | Kept for |
| --- | --- |
| Edge logs (kiste.run) | 7 days |
| Compute server logs | 30 days (or 10 GiB, whichever comes first) |
| Audit events of your account | 12 months |
| Browser sessions | 7 days from sign-in, or until you sign out |
| CLI tokens | valid 30 days, deleted 30 days after expiry or revocation |
| Revoked or expired API keys | deleted 30 days later |
| Command history (metadata of commands run with `kiste exec`) | 30 days after the command finished |
| Events and alerts of Kisten | 90 days |
| Webhook deliveries | 14 days |
| Payment event ids (de-duplication only) | 90 days |
| Disks and memory snapshots of Kisten | until you delete the Kiste |
| Off-site checkpoints | every checkpoint of the last hour, the newest per hour for 24 hours and the newest per day for 14 days; named snapshots until you delete them |
| Account data | until you delete the account |
| Payment records after account deletion | the statutory retention period for accounting records, without your e-mail address |

Every period above is enforced by an automatic job, not by hand. When a store is added or a
period changes, this table and the privacy policy change with it.

## Related topics

- [Security and trust](https://docs.kiste.run/security.md)
- [Isolation](https://docs.kiste.run/security/isolation.md)
- [Network](https://docs.kiste.run/security/network.md)
- [Encryption](https://docs.kiste.run/security/encryption.md)
- [Supply chain and updates](https://docs.kiste.run/security/supply-chain.md)
- [Data location](https://docs.kiste.run/security/data-location.md)
- [Subprocessors](https://docs.kiste.run/security/subprocessors.md)
- [Export and deletion](https://docs.kiste.run/security/account-data.md)
- [Incidents and status](https://docs.kiste.run/security/incidents-status.md)
- [Vulnerability disclosure](https://docs.kiste.run/security/disclosure.md)
- [Compliance](https://docs.kiste.run/security/compliance.md)
- Previous: [Subprocessors](https://docs.kiste.run/security/subprocessors.md)
- Next: [Export and deletion](https://docs.kiste.run/security/account-data.md)
