> ## Documentation Index
> Fetch the complete documentation index at: https://docs.pup.run/llms.txt
> Use this file to discover all available pages before exploring further.

# Data and privacy

> Understand retained moderation records and transient logging data.

Moderation reasons and staff notes are stored in authoritative cases. Cases,
warnings and audit records are retained for the life of the installation;
transient message-log retention does not delete those operational records.

Only configured message-edit and message-deletion logging may temporarily stage
message text. Each before/after value is capped at 1,800 characters and expires
within 24 hours of the Discord event. Successful delivery erases the database
copy immediately. The Discord log copy has the same retention deadline;
retention failures are visible for authorized recovery.

Security incidents retain compact policy and recovery diagnostics rather than
the triggering message, private pattern, attachment name or surrounding chat.
Operational telemetry excludes moderation content and raw provider errors.
Optional analytics are disabled by default and require explicit configuration.

The public roadmap exposes approved capability descriptions and delivery
progress. It does not expose private issue descriptions, people, provider
payloads or operational evidence. Self-hosted deployments can use the bundled
catalog without a connection to a planning service.
