Data storage and retention changedoffice-agents/data-storage
Nearest release: v2.1.218, published 2 hours before upstream edited the page. Shown because the two are within 24 hours of each other. Nothing here says the release caused the edit.
Upstream edited this page at 22 Jul 2026 22:16 UTC, give or take a minute or two: the time comes from Anthropic’s own sitemap rather than from a commit. This site recorded the change at 28 Sep 2026 22:07 UTC.
Upstream edited
Recorded here
Lines+37added
Lines−37removed
From line
41
where the diff opens
First seen
14 Aug 2026
this site's first read of the page
Recorded edits2to this page, all time
The whole hunk
from line 41, old and new numbered
/
from line 41
4141The table below gives the result for each change users and administrators
4242actually make.
4343
44| Change | Result |
45| ------------------------------------------------------------------------------ | --------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
46| Uninstall and reinstall the same add-in | Data intact |
47| Move to a different store listing, or to one published with a new ID | Data intact. A new listing means a new add-in ID, not new storage |
48| Move from a sideloaded manifest to a store listing, or the reverse | Data intact |
44| Change | Result |
45| - | - |
46| Uninstall and reinstall the same add-in | Data intact |
47| Move to a different store listing, or to one published with a new ID | Data intact. A new listing means a new add-in ID, not new storage |
48| Move from a sideloaded manifest to a store listing, or the reverse | Data intact |
4949| Swap the standard manifest for the custom third-party manifest, or the reverse | Storage intact, but the history list changes, because the connection mode change is an identity change. See [what chat history is keyed to](#what-chat-history-is-keyed-to) |
50| Run a store install and a sideloaded manifest at the same time | Shared storage. Two entries in Office, one history. Remove one to avoid confusion |
51| Bump the manifest version, or issue a new ID to clear an Admin Center cache | Data intact |
52| Serve the add-in from a different host or port, or over `http` | A new empty store |
53| Rebuild, reimage, or wipe the profile on the device | Data destroyed. Export first |
50| Run a store install and a sideloaded manifest at the same time | Shared storage. Two entries in Office, one history. Remove one to avoid confusion |
51| Bump the manifest version, or issue a new ID to clear an Admin Center cache | Data intact |
52| Serve the add-in from a different host or port, or over `http` | A new empty store |
53| Rebuild, reimage, or wipe the profile on the device | Data destroyed. Export first |
5454
5555## What Claude for M365 stores
5656
from line 58
5858the signed-in user's operating system profile. The table below lists each one
5959and what it is scoped to.
6060
61| Store | Contents | Scoped to |
62| ------------------------------- | --------------------------------------------------------------------------------- | ------------------------------------------------ |
63| `claude-chat-history` | Conversation transcripts, titles, timestamps, and the contents of attached files | One user, one organization, one Office app |
64| `claude-local-skills` | Skills the user uploaded, including any templates bundled with them | The device profile, not the individual user |
65| `claude-mcp-gateways` | Client registrations for connectors the user has authorized | The connector's address, not the individual user |
66| `claude-mail-style` | Claude for Outlook only: learned writing style, draft preferences, and scratchpad | One user |
67| `claude-office-snipped-results` | Working scratch for long conversations, cleared at the start of every session | Nothing, transient |
68| Local storage | Settings, onboarding and terms flags, and the active sign-in profile | The browser profile |
61| Store | Contents | Scoped to |
62| - | - | - |
63| `claude-chat-history` | Conversation transcripts, titles, timestamps, and the contents of attached files | One user, one organization, one Office app |
64| `claude-local-skills` | Skills the user uploaded, including any templates bundled with them | The device profile, not the individual user |
65| `claude-mcp-gateways` | Client registrations for connectors the user has authorized | The connector's address, not the individual user |
66| `claude-mail-style` | Claude for Outlook only: learned writing style, draft preferences, and scratchpad | One user |
67| `claude-office-snipped-results` | Working scratch for long conversations, cleared at the start of every session | Nothing, transient |
68| Local storage | Settings, onboarding and terms flags, and the active sign-in profile | The browser profile |
6969
7070Conversations and the Outlook writing style guide are scoped to the
7171individual user. Uploaded skills and connector registrations are scoped to the
from line 151
151151
152152The table below gives the result for each case.
153153
154| Situation | Result |
155| --------------------------------------------------------------------------------------------------- | ---------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
156| A user signs out of Claude and signs back in | The same conversations. Signing out does not change the identity |
157| A different person signs in to Office on that device | They see their own conversations, not the previous user's. On Office builds that fall back to a per-installation identifier, both people resolve to the same identity and share one list |
158| The same person opens the add-in on a second device | No conversations. Storage is per device and does not sync |
159| A user's organization changes, such as joining or leaving a team plan | Earlier conversations stop appearing. They remain on disk under the previous organization |
160| A deployment moves between a Claude account sign-in and a third-party platform, in either direction | Earlier conversations stop appearing. They remain on disk under the previous identity, and the add-in has no path to reach them |
154| Situation | Result |
155| - | - |
156| A user signs out of Claude and signs back in | The same conversations. Signing out does not change the identity |
157| A different person signs in to Office on that device | They see their own conversations, not the previous user's. On Office builds that fall back to a per-installation identifier, both people resolve to the same identity and share one list |
158| The same person opens the add-in on a second device | No conversations. Storage is per device and does not sync |
159| A user's organization changes, such as joining or leaving a team plan | Earlier conversations stop appearing. They remain on disk under the previous organization |
160| A deployment moves between a Claude account sign-in and a third-party platform, in either direction | Earlier conversations stop appearing. They remain on disk under the previous identity, and the add-in has no path to reach them |
161161
162162Changing connection mode is not a data loss event, because nothing is deleted,
163163but it is an identity change and the history list follows the identity.
from line 172
172172Claude for M365 bounds local storage in two ways, and users can clear it
173173themselves at any time.
174174
175| Store | Retention |
176| ------------------------------- | -------------------------------------------------------------------------------------------------------------------------- |
177| `claude-chat-history` | The 50 most recent conversations per user, per organization, per Office app. Older conversations are deleted automatically |
178| Any store | When the browser profile runs out of storage quota, the oldest conversations are deleted to make room |
179| `claude-office-snipped-results` | Cleared at the start of every session |
180| Everything else | Kept until the user deletes it or the browser profile is wiped |
175| Store | Retention |
176| - | - |
177| `claude-chat-history` | The 50 most recent conversations per user, per organization, per Office app. Older conversations are deleted automatically |
178| Any store | When the browser profile runs out of storage quota, the oldest conversations are deleted to make room |
179| `claude-office-snipped-results` | Cleared at the start of every session |
180| Everything else | Kept until the user deletes it or the browser profile is wiped |
181181
182182Users clear their own conversations from the add-in's settings. Under "Chat
183183history", "Delete all" removes every saved conversation for that user in that
from line 194
194194The table below covers each category and its destination, so you can scope a
195195review to the paths that carry content off the endpoint.
196196
197| Data | Where it goes |
198| ------------------------------------------------------------------------------------------- | ------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------- |
199| Conversation text, attachments, and the document content Claude is asked to work with | The model endpoint your deployment is configured for. In third-party platform deployments that is your own Vertex AI, Bedrock, Azure, or gateway endpoint |
200| Chat history, uploaded skills, connector registrations, and the Outlook writing style guide | Nowhere. Local only, no sync, no server-side backup |
201| Sign-in credentials | Only to the identity provider they belong to |
202| Usage telemetry sent to Anthropic | Counts, durations, and error categories. Anthropic's collector is allowlist-filtered, so it excludes conversation text, document contents, file names, and the names of your connectors and their tools |
203| Telemetry sent to a custom OpenTelemetry collector you configure | The full audit trail, including prompt content and tool inputs and outputs. That path bypasses the allowlist filter by design. See [Audit and observability](/docs/office-agents/enterprise-readiness#audit-and-observability) |
197| Data | Where it goes |
198| - | - |
199| Conversation text, attachments, and the document content Claude is asked to work with | The model endpoint your deployment is configured for. In third-party platform deployments that is your own Vertex AI, Bedrock, Azure, or gateway endpoint |
200| Chat history, uploaded skills, connector registrations, and the Outlook writing style guide | Nowhere. Local only, no sync, no server-side backup |
201| Sign-in credentials | Only to the identity provider they belong to |
202| Usage telemetry sent to Anthropic | Counts, durations, and error categories. Anthropic's collector is allowlist-filtered, so it excludes conversation text, document contents, file names, and the names of your connectors and their tools |
203| Telemetry sent to a custom OpenTelemetry collector you configure | The full audit trail, including prompt content and tool inputs and outputs. That path bypasses the allowlist filter by design. See [Audit and observability](/docs/office-agents/enterprise-readiness#audit-and-observability) |
204204
205205## Export a user's data before a device is rebuilt
206206
No line in this hunk matches that.