sacandaAgent workspace · Beta

Your agents. Your data.

This page describes how Sacanda’s agent workspace handles information. Updated September 24, 2026.

What Sacanda stores

Your username, password hash, recovery-code hash, agent configurations, knowledge documents, encrypted OpenAI API key, deployment settings, and recent run history are stored on the Sacanda server. A session cookie keeps you signed in for up to seven days. Passwords and recovery codes are hashed; model keys are encrypted with a separate server key. Agent content and run history are not individually encrypted by the application.

Google sign-in

If you sign in with Google, Sacanda stores your Google account identifier, email address, and display name to create or reopen your workspace. Google handles authentication; Sacanda does not receive your Google password. Sign-in requests basic profile and email information only. It does not grant access to Gmail, Drive, or other Google content. Google access tokens are not retained. Google workspaces use Google for account recovery; existing password workspaces keep their recovery-code flow.

When you leave for Google sign-in, a draft may be held in this tab’s session storage so it can be restored on return. The temporary copy is removed when you return and is ignored after ten minutes. It contains agent configuration and any attached knowledge, never your model API key.

When you run an agent

Sacanda sends the agent’s instructions and your task to OpenAI using your connected API key. Relevant document excerpts and tool results may be sent in subsequent model requests. Sacanda asks OpenAI not to store the Response object; OpenAI’s own API data handling and retention policies still apply. Usage is billed to the OpenAI account associated with the key. Do not submit information you do not have permission to process.

Deployments and access

Anyone with a deployment link can see its name, description, revision, and status. Running it requires its deployment access key or the signed-in owner’s session. A deployment key allows its holder to use your model quota and ask questions about the agent’s knowledge. Give keys only to trusted users and systems. Pause a deployment or rotate its key to prevent further use. Runs already in progress may finish.

History, export, and deletion

The workspace shows the latest 50 runs per agent. Sacanda retains at most 200 recent runs per workspace for up to 30 days. You can export agent configurations from the builder. Deleting an agent removes its documents, deployments, and run history from the active application database. Disconnecting OpenAI removes the saved key and pauses deployments. Operator backups, if present, may retain earlier data until those backups expire.

Recovery and support

Save your one-time recovery code in a password manager. It can reset your password and signs out existing sessions. There is no email reset flow. For account deletion or data questions, contact Nerdi and identify your Sacanda username. Never include your password, API key, or recovery code in a message.

Your original Ideas workspace

The Ideas workspace keeps using browser-local storage. Its venture plans are separate from server-stored agents. The color theme preference is also saved in your browser.

Back to the workspace →