Your comments

Both, public and private are required to meet my organisational compliance needs (a research university with projects which manage and process sensitive data - often we have specific ethics committee requirements as well). This is just like organisation email. From a project perspective it is also very useful to archive with the project at it's conclusion.


Why not make it a configuration (none, public, all) option chosen by the account owner, and then for users who sign up, or when the policy changes, inform the them of this by email and a nag banner notification (latter must be acknowledged to get rid of the banner).


Export data should be machine process-able and filterable and (e.g. JSON). I guess you can skip the binary attachments (images) and just put in a reference to the fact it existed, and the metadata associated with the upload.


Thanks!

+1 This is needed for compliance. Many organisations need to keep records for long periods of time.