Frames are kept for as long as your organisation is
There is no expiry and no sweep. Nothing in the service deletes a frame, and that is structural rather than a policy anybody has to remember: a frame is stored with no expiry time at all, so no rule that compares a deadline can select one. This is what makes step by step replay possible. The frames a run saw are the run’s own record, and a record that disappears after three days is not a record you can be shown a month later when it matters.There is no API that reads a frame back today
The two endpoints that returned them,GET /v1/runs/{agentRunId}/frames and
GET /v1/receipts/{idempotencyKey}/frame, have been withdrawn. Nothing
consumed them, and an endpoint published on this site that the service cannot
serve is worse than an absent one.
The archive itself is unchanged: frames are still captured, still written, and
still kept for as long as your organisation is. What follows describes what is
stored, not something you can fetch. If you need a run’s frames, ask.
The store is private, and any read path would be a URL we mint
The store is private in its own right: an anonymous request, a request carrying the public API key, and a request from a signed in browser session are all refused, including the request that only asks whether an object exists. A read path returns a signed URL for one image rather than pixels, valid for the number of seconds the response names and never longer than five minutes. Treat such a URL as a password for that one image while it lasts: do not store it, log it, or paste it into a bug report. Before any URL is signed, the frame is looked up in the database under your organisation’s own row level policy, and the storage location is read out of that row. It is never constructed from the values in a request. That distinction is the authorisation: a location built from arguments would be a valid looking location for somebody else’s frame, and object storage has no idea which tenant asked.What we do not do to a frame
Frames are not encrypted at the application layer, and the reason is worth being straight about rather than implying more protection than exists. The protection is the private bucket, a credential whose reach is object storage and not the database, the organisation check above, and the short lived URL. There is no per organisation key, and per frame crypto shredding is not available today.Turning archiving off
An organisation can be taken out of frame archiving entirely, and can instead choose a finite retention window with a ceiling of 90 days. Both are set through the operational management path, not by you and not by an agent; ask if you want either. Two things about those settings:- Leaving the archive does not erase what is already in it. It stops new frames being written.
- A zero day window means the bytes are never written, not written and then cleaned up shortly after. At that setting the control plane records that a frame was captured and stores no image, so there is nothing waiting on a cleanup process to run on time.
Retention is decoupled from billing, permanently
Frame bytes do not participate in billing, usage or quota, and never have. The billing pipeline derives from the receipt ledger, which contains no frames. This is not a coincidence maintained by care. The two read and write completely disjoint paths, and that is checked directly: billing derived with frame data present and billing derived with it gone produce identical results. The consequence that matters to you: what happens to your frames can never cost you a billing record, so “we need it for billing” can never become an argument about images.What the control plane keeps besides the image
A frame’s identity is tracked separately from its bytes, and was long before the bytes were stored:- the frame id you can echo back as
observedFrame, - a per device sequence number,
- when it was registered, and the geometry it was captured at.
screenshot is not one of the actions
a receipt records, and the summaries that are recorded are deliberately thin: a
typed string is recorded as its length, never its content.