← Help

Business operations

Private business and personal exports

Product team · Reviewed

Keep a portable copy of your records

Open Settings → Private exports and choose Business records or My personal records. Review the listed datasets and exclusions, confirm the package will stay private, then select Prepare export. Refresh the list to see progress. A ready package downloads as a ZIP and expires seven days after its request.

Business and personal packages

A business package requires the current workspace owner. It includes the business profile, clients and contacts, projects, timelines and published coordination history, tasks, guests and households, seating and floor plans, budgets, invoices and ledger entries, expenses and payment records, proposal versions, agreements and signed snapshots, gallery metadata, private template records and versions, and an event index.

A personal package requires your current named full workspace membership. It includes your account profile, your own personal notes and navigation preferences in this workspace, and retained authentication events belonging to your account. It never grants access to a departed workspace. Other authors’ notes and private assistant runs are excluded from business packages, even for the owner. The interface also lists files and source-provider data that this format does not contain.

For example, an owner exporting September’s business records receives its invoices and immutable agreement evidence. Their teammate’s private note about preparing for a client meeting remains absent. That teammate can prepare a personal package containing their own note.

Inspect the archive

Start with manifest.json. It identifies format version, requested workspace, included datasets, row counts, capture timestamps, exclusions, and SHA-256 checksums. Structured records use UTF-8 NDJSON: one JSON object per line. IDs preserve relationships, dates are ISO strings, and money is integer cents unless its field explicitly says otherwise.

Each part is captured in a database transaction. Edits can happen between parts, so the manifest discloses that this is a portable record export rather than a transactionally consistent database backup. Records with creation timestamps are restricted to those created before the request; rows without those timestamps are read when their part is captured.

Signed agreements include immutable snapshots and their hashes, plus integrity-checked retained PDFs. If a retained PDF was not previously prepared, the existing deterministic signed-document renderer creates and retains it from the exact signed snapshot before packaging. A void or reissue preserves the original executed evidence. Export failure never rewrites the original agreement.

Gallery metadata identifies originals and checksums. Use the gallery’s separate original archive to export large professional media. This package does not duplicate gallery originals, mailbox attachments, or the entire private file library.

Resume, cancel and remove

Interrupted work retains committed data parts. Resume retries a failed, unexpired export from those parts. An uncertain browser response can be recovered with Check original request without creating another package. Cancel stops preparation; Remove package immediately stops new downloads of a completed export. Cleanup removes only the temporary package and captured parts, never its source records or original signed documents.

Permissions are checked again while preparing and downloading. Leaving the workspace, losing ownership of a business export, or changing membership authority prevents reuse of an older package. API keys cannot create or download exports. A file already downloaded to someone’s computer cannot be recalled.

The current format permits 500,000 records, 500 MB of structured captures, and a 1.9 GB ZIP. Oversized packages fail explicitly without silently dropping records. Private storage and background workers are activation requirements; a pending package is never presented as finished.

Authentication evidence

Personal packages contain only signature-verified Clerk session events actually retained after the webhook is activated. Session creation, ending, removal and revocation are distinguishable. The system keeps a hashed session identifier rather than a usable session token. It does not infer past logins from a current session or invent history from before capture was enabled.