Goal
Deprecate NEAR AI Cloud's confidential-data infrastructure for Private Chat/stateful APIs, so Cloud can focus on private inference without continuing to accept or serve new Conversation/File state that depends on CVM-only storage guarantees.
The end state is:
- No new confidential Conversation/File data is written through the stateful API surfaces.
- Existing raw Conversation data is protected before the database is moved out of CVM.
- Stateful Responses, Conversations, Files, and related Private Chat APIs are retired.
- Private Chat is shut down after users have had a read/export window.
Scope
Components involved:
- Database: keep tracking in
nearai/cloud-api.
- cloud-api: restrict stateful APIs in Stage I, then remove them.
- chat-api: update proxy/API behavior to match cloud-api deprecation and removal.
- private-chat frontend: disable write UX, add export/deprecation UX, then shut down the product surface.
Requirements
- During migration, do not expose raw confidential content to admins, operators, logs, or normal database access.
- Before moving the database out of CVM, encrypt existing raw Conversation content using a CVM-derived key from
S3_ENCRYPTION_KEY or S3_ENCRYPTION_KEY_FILE.
- After Stage I, no supported user flow should create or update Conversations, Files, shares, pins, archives, copies, or other Private Chat state. The existing Cloud resource DELETE endpoints are the explicit exception: they remain available so Chat's established account-deletion worker can complete cleanup.
- Read access is temporary and exists only to support export/migration until Stage III.
- For Responses API compatibility, retain only stateless/no-store behavior.
Stage I: Restrict confidential-data writes
Target date: Sep 14
Database
Current state: the database runs inside CVM so raw confidential data is not exposed through normal administrative access. The migration path is to move the database out of CVM only after raw Conversation content has been encrypted.
Action items:
- Add an admin API in
cloud-api that encrypts Conversation data with the CVM-derived key from S3_ENCRYPTION_KEY or S3_ENCRYPTION_KEY_FILE.
- Run the operational backfill to replace raw
conversations table content with encrypted content through that API.
cloud-api
Restrict stateful APIs to temporary retrieval views plus the existing resource DELETE compatibility exception.
Action items:
- Deprecate stateful Responses API behavior and keep only stateless Responses API behavior.
- Retain only temporary Conversation/File retrieval access needed by migration/export tooling.
- Retain
DELETE /v1/conversations/{conversation_id} and DELETE /v1/files/{file_id} so the existing Chat account-deletion worker can complete its normal Cloud cleanup.
- These DELETE operations remain the existing API-key/workspace-scoped endpoints; Stage I does not introduce an account-deletion-only token or internal path. They are therefore an intentional, limited public mutation exception.
- Disallow all other Conversation/File writes and conversation-related mutations such as copy, pin, archive, and similar operations.
chat-api
Update proxy endpoints to match the cloud-api restricted/deprecated behavior while preserving the existing account-deletion workflow.
Action items:
- Deprecate stateful Responses proxy behavior and keep only stateless Responses behavior.
- Disallow normal Conversations/File writes in proxy endpoints; keep only temporary read access.
- Disallow other conversation-related mutations such as share, copy, pin, archive, and similar operations.
- Preserve
DELETE /v1/users/me and its established asynchronous worker, which uses Cloud's retained resource DELETE endpoints.
private-chat frontend
Deprecate the Private Chat product surface while preserving a read/export path.
Action items:
- Disable creating new conversations, submitting new prompts, copying conversations, uploading files, and any other non-deletion write action against Conversations or Files.
- Add conversation export in the Private Chat settings dialog.
- Show a deprecation banner that Private Chat will be shut down before Stage III.
Stage II: Migrate database from CVM
Target date: Sep 9
Stage II intentionally remains lightweight for now. The initial tracker should cover moving the database out of CVM after Stage I encryption and write-disablement are complete. More detailed component/action issues can be added once the migration plan is finalized.
Stage III: Remove stateful APIs and shut down Private Chat
Target date: Nov 1
cloud-api
Remove stateful API surfaces after the migration/export window and account-deletion lifecycle are complete.
Action items:
- Remove Conversation APIs.
- Remove Files APIs.
- Remove other conversation-related APIs, including the retained resource DELETE endpoints once account deletion is retired or replaced by the final cleanup process.
chat-api
Remove proxy endpoints for retired stateful API surfaces.
Action items:
- Remove Conversation API proxy endpoints.
- Remove Files API proxy endpoints.
- Remove other conversation-related proxy endpoints.
private-chat frontend
Shut down the Private Chat frontend.
Action item:
- Remove Private Chat frontend serving in
chat-api.
Tracking
This epic is organized with GitHub sub-issues:
- Stage-level issues are linked directly under this epic.
- Component issues are linked under each stage.
- Component action items are linked under their component issue.
- Existing issues should be reused and linked rather than duplicated when they already cover the same work.
Goal
Deprecate NEAR AI Cloud's confidential-data infrastructure for Private Chat/stateful APIs, so Cloud can focus on private inference without continuing to accept or serve new Conversation/File state that depends on CVM-only storage guarantees.
The end state is:
Scope
Components involved:
nearai/cloud-api.Requirements
S3_ENCRYPTION_KEYorS3_ENCRYPTION_KEY_FILE.Stage I: Restrict confidential-data writes
Target date: Sep 14
Database
Current state: the database runs inside CVM so raw confidential data is not exposed through normal administrative access. The migration path is to move the database out of CVM only after raw Conversation content has been encrypted.
Action items:
cloud-apithat encrypts Conversation data with the CVM-derived key fromS3_ENCRYPTION_KEYorS3_ENCRYPTION_KEY_FILE.conversationstable content with encrypted content through that API.cloud-api
Restrict stateful APIs to temporary retrieval views plus the existing resource DELETE compatibility exception.
Action items:
DELETE /v1/conversations/{conversation_id}andDELETE /v1/files/{file_id}so the existing Chat account-deletion worker can complete its normal Cloud cleanup.chat-api
Update proxy endpoints to match the cloud-api restricted/deprecated behavior while preserving the existing account-deletion workflow.
Action items:
DELETE /v1/users/meand its established asynchronous worker, which uses Cloud's retained resource DELETE endpoints.private-chat frontend
Deprecate the Private Chat product surface while preserving a read/export path.
Action items:
Stage II: Migrate database from CVM
Target date: Sep 9
Stage II intentionally remains lightweight for now. The initial tracker should cover moving the database out of CVM after Stage I encryption and write-disablement are complete. More detailed component/action issues can be added once the migration plan is finalized.
Stage III: Remove stateful APIs and shut down Private Chat
Target date: Nov 1
cloud-api
Remove stateful API surfaces after the migration/export window and account-deletion lifecycle are complete.
Action items:
chat-api
Remove proxy endpoints for retired stateful API surfaces.
Action items:
private-chat frontend
Shut down the Private Chat frontend.
Action item:
chat-api.Tracking
This epic is organized with GitHub sub-issues: