- What we store
- Account profile (email, name, role), engagement metadata (project name, dates, members), files uploaded by you or your team, time entries you provide for monthly reporting, and audit logs of administrative actions.
- What we don’t store
- Salesforce passwords, Salesforce security tokens, session IDs, OAuth client secrets, payment card information, or any client data we have not been explicitly authorized to handle.
- Where it lives
- DynamoDB tables and S3 buckets in AWS us-east-1, each scoped to a single application and protected by IAM. There is no shared database across customers and no third-party data warehouse.
- How long
- Engagement files: retained for the life of the engagement plus a configurable retention period (default 90 days) — or until you ask us to delete. Logs: 30 days. Audit trail: 1 year. Account data: until you close the account.
- Who can see it
- Engagement files and time entries are visible only to engagement members and the blufyre.com owner. Cognito enforces this in every API call — there is no “admin view” that bypasses tenancy checks.