Read the current governance posture for retention, deletion, export, data boundaries, and audit evidence.
Retention is managed by the service today
The current MeGovernanceResponse reports retention.status=operator_managed and retention.available=false. Automated retention rules are not configurable per account; archive, forget, and clear actions require explicit account action. This page describes the implemented posture, not a promise of an automatic retention schedule.
{
"retention": {
"status": "operator_managed",
"available": false
},
"delete": {
"status": "self_service",
"available": true
}
}
Deletion and export have separate postures
Individual memory deletion is self-service. Account-level closure revokes access and queues a Personal purge workflow; the response contract says team-shared data remains with the Team. Export is either self-service download or request-only depending on the runtime configuration, and prepared artifacts expire automatically.
- delete — self-service individual memory deletion is available.
- export — status is self_service_download only when the runtime enables it; otherwise request_only.
- data_boundary — account-scoped; no cross-account access is permitted.
Governance actions leave audit evidence
The governance response reports audit.status=enabled and describes account actions as emitting audit events; audit-log access and self-service audit export remain managed by the service team. Memory deletion also records mode, reason presence, and target references in the memory audit outbox without retaining forgotten content in the public result.
{
"data_boundary": {
"status": "account_scoped",
"available": true
},
"audit": {
"status": "enabled",
"available": true
}
}
Check the effective posture before choosing a mode
Security mode and governance posture are separate controls. Cloud mode permits server-side processing; Keyguard uses customer key wrapping with audited temporary decrypt; Vault keeps memory bodies client-encrypted and normally requires local recall. Choose retention, deletion, and security handling based on the current response contracts rather than assuming one setting controls all three.
retention = operator_managed
delete = self_service
audit = enabled
security = resolve the effective Cloud, Keyguard, or Vault mode
Persona flows
ChatGPT user
Give ChatGPT durable access to your XMemo preferences, project facts, decisions, and TODOs without pasting bearer tokens into a chat.
Save a synthetic preference or project note, start a new chat, then ask ChatGPT to recall it through XMemo before continuing work.
Copilot / Codex developer
Carry repo decisions, coding conventions, bug-fix notes, and task history between IDE and CLI agents.
Record a codebase decision or bug fix, then ask the next IDE or CLI agent to recall the relevant XMemo context before editing.
Team / enterprise pilot owner
Evaluate shared memory with account controls, source attribution, export/delete workflows, and reviewer-safe setup evidence.
Have a pilot member save a synthetic team memory, confirm source attribution in XMemo, then review delete/export and support paths.