# Data ## Ownership The service is the only SQLite writer. The agent durably spools events and submits them idempotently over the pod-local API; globally unique ids make retries safe. SQLite runs in a worker thread so health and SSE never block. ## Schema (v1) audit_events, chat_messages, tombstones, deployment_events, media, media_analyses, jobs, meta. Payloads are JSON validated by shared types; schema version lives in `PRAGMA user_version`. ## Compatibility rule Forward-only, bounded migrations. Release N must leave every value it can write readable by release N-1: schema, enum/JSON values, session file, event spool, archive index, media metadata, API cursors. Destructive cleanup waits until the previous revision stopped reading the shape. CI proves it by running previous -> candidate -> previous. ## Retention and archives Audit 90 days hot, chat one year hot; rows move exactly once into immutable monthly zstd JSONL segments with versioned sidecar indexes. A crash between publish and delete reconciles by segment membership. Timeline and recall merge hot and cold transparently. Tombstones filter archived chat forever. ## Maintenance Service-scheduled: hourly archive cycle + incremental vacuum + tmp reconcile, daily quick_check. Storage thresholds: warn under 20% free, stop under 10% (new model work and media pause; reads, queue, audit, recovery, and notification writes continue from reserved capacity).