Controller and processor model
Customers decide which public or authorized sources are processed; MediaHarvester processes requests according to API instructions.
customer_instructions
DPA readiness notes for customers who need processor/subprocessor, retention and security controls.
Customers decide which public or authorized sources are processed; MediaHarvester processes requests according to API instructions.
customer_instructions
Cache and generated asset retention are explicit controls; hosted production should expose organization-level deletion workflows.
DELETE /v1/compliance/data-retention/cache
Local development does not connect hosted billing, CDN, search or LLM providers unless credentials are configured.
local_only
A production DPA requires legal review, subprocessor inventory and customer agreement workflow.
This page documents technical readiness and does not claim a signed production DPA.