• PII masking is set per knowledge base. It replaces personal data with placeholders such as [EMAIL].
  • Data retention is set per workspace. It controls how long conversations are kept.
Both are available on every plan.

Turn on PII masking

1

Open the setting

Open the knowledge base, click Settings, and find PII Masking. Switch on Enable PII masking.
2

Pick categories

Tick the categories to mask (see the table below).
3

Add your own patterns (optional)

Custom regex patterns, one per line, catch your own identifiers, such as \bORD-\d+\b for order numbers. Allow-list terms, one per line, are never masked, such as your support address.
4

Save and sync

Click Save changes, then sync your sources. Open a document under Sources to check the placeholders.
CategoryReplaced with
Email addresses[EMAIL]
Phone numbers[PHONE]
Credit card numbers (checked with the Luhn test)[CREDIT_CARD]
IBAN / bank account numbers[IBAN]
IP addresses (IPv4 and IPv6)[IP]
Full names, only after a title: Mr, Ms, Mrs, Dr or Prof[NAME]
Custom regex patterns[REDACTED]

What gets masked

  • Indexed content: every document body from every source type, before it is stored or embedded. Document titles are not masked.
  • Questions asked through the widget, the SDKs, the public chat API and Ask.
  • Not masked: questions from chat bots, the support form deflector, helpdesk automation, the helpdesk sidebar apps, MCP and the search API. These are stored and sent to the model as typed.
Turn masking on before the first sync of a source with personal data, such as tickets or Slack history. Changing the setting re-masks website pages and most sources on their next sync. Google Drive, OneDrive, S3, Jira, Jira Service Management, Salesforce Cases and GitHub issues, pull requests and discussions only re-read items that changed, so items indexed earlier keep their old text until they change. To re-mask those, remove the source and add it again.

Troubleshooting

  • A custom pattern masks nothing. Invalid patterns are skipped without an error. Check the syntax (Go regular expressions, the same as RE2).
  • An allow-list term is still masked. The term must match the whole masked value, for example the full email address. Case does not matter.
  • Names are not masked. Only names after a title such as Dr are detected. Add a custom pattern for others.

Set a conversation retention window

Go to Settings → Overview → Data Retention and choose:
OptionWhat happens
Keep forever (default)Nothing is deleted.
30 days, 90 days, 365 daysOnce a day, Kelu deletes conversations, messages, feedback, traces, widget-open events and coverage gap analyses older than the window.
Zero data retentionChats are answered but not stored. See below.
Only workspace owners and admins can change this.

Zero data retention

Every question is answered and then forgotten: in the widget, the SDKs, the public chat API, Ask, the support form deflector, the Slack and Teams bots and the helpdesk sidebar chat. No conversation, message, feedback or trace is stored. Searches, MCP calls and A2A calls record no trace either. Kelu keeps one thing: a count of questions per day, with no text. That is how your monthly question allowance is counted. What this changes:
  • The chat stream returns no message_id, so feedback cannot be recorded. Hide your rating buttons.
  • It returns no thread_id either, so each question starts fresh, with no memory of the one before.
  • The form deflector shows no rating buttons and no hand-off link. Its deflection rate is still counted.
  • Bots answer each message on its own. A follow-up in a thread does not see the earlier answer, and there are no rating buttons.
  • Conversations, Coverage Gaps, Analytics and Traces stay empty for those chats.