Security

Privacy, exports, retention, and leaving

Understand what belongs to the workspace and how to move or remove it safely.

Applies to V1.2+ · Checked July 2026

Before you start

  • Workspace owner access for organization-wide actions

Know who owns each layer

The tenant owns its business records, configuration, templates, connected profiles, and selected storage destinations. Individual members own personal presentation preferences and may own personal provider profiles subject to workspace policy. Cygnetree owns platform runtime configuration and code-defined capability contracts.

Clients and vendors see only their permitted project slices. They never receive workspace observation state about content they sent to the business.

Export before making a destructive decision

Export people, projects, pipeline history, invoices/payments, expenses, files, and migration reconciliation before cancellation or deletion. Open representative files and verify checksums, currency, dates, relationships, and archive state.

Exports intentionally exclude credentials, provider tokens, password/session material, temporary signed URLs, and private keys. A portable logical file identity remains stable even when storage is migrated.

Disconnect tenant providers

Review each Google, Microsoft, Zoom, Resend, SMTP, storage, webhook, API, AI, or payment profile. Move files and replace active bindings before disconnecting a storage destination. Repair or replace active scheduling and sending defaults before revoking their profiles.

Disconnecting a tenant profile removes its saved credential from Cygnetree and should be paired with revocation at the provider. It does not delete the tenant's independent provider account.

Handle retention honestly

Retention is not one number. Active records, messages, files, signed contracts, invoices, payment evidence, tax records, audit logs, support access, migration archives, deleted objects, and backups may require different periods.

Before commercial use, the workspace and Cygnetree operator need counsel-approved policies for the launch jurisdictions and data classes. A user-facing setting must not promise deletion earlier than backups, disputes, legal holds, or processor behavior can honor.

Delete an account or workspace

Removing a member is different from deleting a workspace. Transfer ownership and assigned work before removing an owner. Revoke sessions, personal profiles, device subscriptions, and delegated access.

Workspace deletion requires an export opportunity, explicit confirmation, a visible timeline, and clear exceptions. It never silently cancels a third-party provider subscription or deletes data stored in tenant-owned storage.

Preserve disputes and required evidence

Payment disputes, fraud/security investigations, tax obligations, contracts, litigation holds, or another lawful duty may require bounded preservation after an ordinary deletion request. Preserve only the required evidence, restrict access, record the reason and owner, and delete it when the hold ends.

This guide explains product behavior, not legal advice. Cygnetree's commercial retention, privacy, signature, and deletion promises remain subject to qualified review before launch.

Keep going

Did this guide get you unstuck?

If not, tell us — this opens a support conversation with the guide already attached, and a real person reads it. If the guide is wrong or missing something, we fix the guide.

Tell us what's missing