Skip to content

Sessions

A session is one conversation with an agent. It is kept on the user's device, not on the server.

On the device

Each session is an append-only transcript: the messages, the tool calls and their results, the approvals, and the outcome of each turn.

SDK Where Protection
.NET A folder in the user's local application data On Windows each entry is encrypted for the user with DPAPI. On other systems the files are readable by their owner only.
TypeScript, in a browser IndexedDB of the extension or page Only that extension or origin can read it. It is not encrypted beyond what the browser does for its profile.
TypeScript, elsewhere Memory, unless you give it a store Yours to decide

By default the newest 50 sessions are kept, none older than 90 days. A session can be continued later, in the tool mode it was left in. Both SDKs let you plug in your own store.

What the server sees

The SDK reports the agent's events to the server: which tools ran, how long they took, the outcomes and the approval decisions. These events carry no message content.

The model requests themselves pass through the server, like every request, and there the organisation's settings for personal data, usage records and audit apply. See Personal data.