Security & trust · 5 min

Privacy and monitoring data

Understand the allowlisted report, what never leaves the server, and how long data remains.

Reviewed 5 September 2026

What the server reports

The allowlist includes server identity and time; OS, LSBS, and installed-package versions; capability status without local routes; redacted health findings and alerts; aggregate people, mailbox, and device counts; CPU, memory, root-disk, and load metrics; backup status; and the nearest certificate expiry.

What monitoring does not report

Monitoring does not send names, email addresses, LDAP records, mail or file contents, client IP addresses, passwords or hashes, private keys, arbitrary configuration, local action URLs, or backup archive names.

Optional managed Directory inventory

Installing the Premium Directory service enables a separate signed, read-only inventory for its private cloud workspace. It contains up to 50 people, groups, joined computers and shared folders, including names, email addresses and group memberships. It never includes passwords, password hashes, mail or file contents, arbitrary LDAP filters, local filesystem paths or private keys. Identity changes still open local WebAdmin.

Retention and deletion

  • Monitoring reports: 90 days
  • Alerts: one year
  • Support-bundle records: 30 days
  • Managed Directory: latest two completed snapshots

Older Directory snapshots are replaced as fresh inventories arrive. Deleting the account or server cascades through its portal data and revokes the stored public identity. The server’s private monitoring and managed-control keys are never held by the portal.