Data Retention Policy
Draft pending qualified legal review. This policy has not yet been reviewed by qualified counsel and may change before launch.
Effective 1 September 2026
Most data is kept for minutes to 90 days and then deleted by automated jobs. Only payment records and the audit log are kept for years, because law and accountability require them. Traffic content is never stored.
5.1 Retention schedule
| Data | Kept for | What happens then |
|---|---|---|
| Request and response bodies, URLs, paths, query strings | Never stored | — |
| Sign-in one-time codes (hashed) | 10 minutes | Deleted |
| Key sign-in challenges | Minutes, until used or expired | Deleted |
| Idempotency keys | 24 hours | Deleted |
| Rate-limit hashes | 48 hours | Deleted |
| Offers not accepted | 30 minutes valid; then kept with payment history if paid, else deleted | Deleted |
| Free-plan names | Until 24 hours of inactivity | Released |
| Active sessions | 30 min idle, 12 h maximum; record kept 30 days | Deleted |
| Data exports | 7 days | Deleted |
| Edge request metadata (method, status, duration, bytes) | 30 days | Deleted |
| Usage byte counts, anomaly flags, webhook records | 90 days | Deleted |
| Notification content | Until delivered; metadata 90 days | Erased, then deleted |
| Abuse reports | Until closed, at most 180 days | Deleted |
| Support cases | 365 days | Deleted |
| Data-subject requests (access, deletion) | 1 year | Deleted |
| Account, email, keys, devices, recovery codes | Life of the account + 7-day cooling-off after a deletion request | Replaced by an identifier-only tombstone |
| Payment records, entitlements, wallet address, transaction hash | 5 years after the payment | Deleted; payment payloads are erased at finality |
| Audit log (hash-chained) | 7 years | Deleted in whole segments |
| Encrypted backups | 60 days | Overwritten |
5.2 Rules
- Automated deletion. Scheduled jobs enforce these periods. Periods may be shortened by configuration but not lengthened without updating this policy.
- Account deletion. A deletion request starts a 7-day cooling-off period; you can cancel during that time. After it ends, we delete your email, keys, devices, sessions and recovery codes, and keep an identifier with no personal data so a deleted account cannot be silently re-used.
- Records that outlive deletion. Payment records stay for the accounting period above, and the audit log for its period. On-chain transactions are public and permanent; we cannot delete them.
- Backups. Deleted data can remain in encrypted backups until they are overwritten. We do not restore deleted personal data from a backup except to recover from an incident; if we do, we re-apply pending deletions.
- Legal holds. We may keep specific data longer when a valid legal order, an active abuse or fraud investigation, or a legal claim requires it. We keep only what is needed, and delete it once the hold ends.
- Review. We review this schedule at least once a year and on any change to what the Service collects.