Skip to main content
Last reviewed: March 5, 2026 Owner: Security + Engineering Review cadence: Quarterly Status: Implemented This page defines the hosted default data scope, retention behavior, and what changes when you self-host.

Reviewer focus

  • Which data classes are stored in the hosted model
  • What the default retention and deletion behavior is
  • How ownership changes between hosted and self-hosted environments

Implementation status (March 5, 2026)

Tero limits retained data by default. The control plane stores only the metadata required to operate the product. Full raw telemetry stays in your observability platform.

Data lifecycle diagram (hosted default)

Data classes and handling model (hosted default)

Retention and deletion baseline

When a customer account or workspace is deleted, Tero removes data from active systems within 30 days. Backup copies age out under backup-retention windows.

Hosted vs self-hosted boundary

Evidence you can request

Exceptions and governance

Any exception to standard handling or retention behavior requires documented risk, Security and Engineering approval, compensating controls, and a time-bound remediation plan. Evidence requests: