Data Retention and Deletion
In one line
How long we keep each kind of data, and how you, your audience, or a platform can ask us to delete it.
The short version
This short version helps you understand the full text. Read the full text for the complete terms.
- We keep data only while we need it for the service, for security, or because the law requires it. (Full text, section 1)
- Disconnecting a channel deletes its tokens at once. (Section 2)
- Closing your workspace starts a 30-day export window; then we delete your content. Backups roll off within a further 35 days. (Sections 2 and 3)
- We keep billing records as long as tax law requires, and a short record that a deletion happened. (Section 2)
- Anyone can ask us to delete their data. Facebook and Instagram users can do it from their Facebook settings, and get a confirmation code. (Section 4)
Full text
Read the full text (about 2 minutes)
1. Principles
We keep personal data for no longer than we need it for the purpose we collected it for, plus any period the law requires. We review this schedule every year.
2. Retention schedule
| Data | Kept for | Then |
|---|---|---|
| Platform access and refresh tokens | Until you disconnect, the platform revokes, or the token expires | Deleted immediately |
| Platform data (profile, page, post, comment, and insight data) | While the channel is connected, and no longer than the platform allows | Deleted or refreshed as the platform requires |
| Drafts, media, Brand Kit, and Checks results | While the workspace is open | Deleted 30 days after closure |
| Provenance records for published posts | Life of the workspace + [6 years] | Deleted |
| Authorisation records | Life of the workspace + [6 years] | Deleted |
| Voice and likeness data | Until consent is withdrawn or the licence ends | Deleted within 30 days |
| Account data | While the workspace is open | Deleted 30 days after closure |
| Billing and tax records | As tax law requires (usually 6 to 10 years) | Deleted |
| Security logs and audit events | 12 months | Deleted |
| Error reports (Sentry) | 90 days | Deleted by the provider |
| Support emails | 2 years after the last message | Deleted |
| Backups | Rolling 35 days | Overwritten |
| Record of a deletion request | 3 years | Deleted |
[PERIODS IN BRACKETS — counsel to confirm.]
3. Closing your workspace
3.1 The owner can close the workspace in Settings. Scheduled posts are cancelled and channels are disconnected.
3.2 You have 30 days to export your content in a common format (JSON and the original media files). After 30 days we delete it, except as section 2 says.
3.3 Published posts remain on the platforms. Delete them there, or ask us to delete them for you before you close the workspace.
4. Deletion requests
4.1 From a customer: in Settings, or by email to [CONTACT EMAIL] from the account owner's address.
4.2 From someone who appears in content, or comments on a channel: we pass the request to the business that controls the content and help it respond. If we hold data about you as controller, we act on it directly.
4.3 Facebook and Instagram users: remove qypu in Facebook Settings, then Apps and websites, and choose to send a deletion request. We return a confirmation code and a status page at /legal/data-deletion.
4.4 Google and YouTube users: revoke access in your Google Account; we then delete stored YouTube data within 7 days, or sooner where the YouTube API Services policies require.
4.5 We confirm completion of a deletion request, and tell you about any data we must keep and why.
5. Legal holds
If we receive a valid legal demand or need data to defend a legal claim, we may keep the specific data concerned until the matter ends.
Change log
- 2026-10-10 · 0.1.0 · First draft.
Open questions for counsel
We publish these while the page is a draft, so you can see what is not settled yet.
- Confirm tax-record periods per jurisdiction (for example, 6 years UK, 10 years in several EU states, 5 years Australia and Singapore, 7 years NZ).
- Confirm the 35-day backup rotation matches the Supabase plan in use.
- Provenance and Authorisation record retention: balance limitation periods against minimisation.
Useful for: Business owners, Your staff, IT and security reviewers, Platform reviewers. To save this page as a PDF, use your browser's Print command. Back to the trust centre.