Data · version 0.1.0 · effective: DRAFT

Data Retention and Deletion

DRAFT — requires review by qualified counsel in each jurisdiction. Not in force.

In one line

How long we keep each kind of data, and how you, your audience, or a platform can ask us to delete it.

The short version

This short version helps you understand the full text. Read the full text for the complete terms.

  • We keep data only while we need it for the service, for security, or because the law requires it. (Full text, section 1)
  • Disconnecting a channel deletes its tokens at once. (Section 2)
  • Closing your workspace starts a 30-day export window; then we delete your content. Backups roll off within a further 35 days. (Sections 2 and 3)
  • We keep billing records as long as tax law requires, and a short record that a deletion happened. (Section 2)
  • Anyone can ask us to delete their data. Facebook and Instagram users can do it from their Facebook settings, and get a confirmation code. (Section 4)

Full text

Read the full text (about 2 minutes)

1. Principles

We keep personal data for no longer than we need it for the purpose we collected it for, plus any period the law requires. We review this schedule every year.

2. Retention schedule

DataKept forThen
Platform access and refresh tokensUntil you disconnect, the platform revokes, or the token expiresDeleted immediately
Platform data (profile, page, post, comment, and insight data)While the channel is connected, and no longer than the platform allowsDeleted or refreshed as the platform requires
Drafts, media, Brand Kit, and Checks resultsWhile the workspace is openDeleted 30 days after closure
Provenance records for published postsLife of the workspace + [6 years]Deleted
Authorisation recordsLife of the workspace + [6 years]Deleted
Voice and likeness dataUntil consent is withdrawn or the licence endsDeleted within 30 days
Account dataWhile the workspace is openDeleted 30 days after closure
Billing and tax recordsAs tax law requires (usually 6 to 10 years)Deleted
Security logs and audit events12 monthsDeleted
Error reports (Sentry)90 daysDeleted by the provider
Support emails2 years after the last messageDeleted
BackupsRolling 35 daysOverwritten
Record of a deletion request3 yearsDeleted

[PERIODS IN BRACKETS — counsel to confirm.]

3. Closing your workspace

3.1 The owner can close the workspace in Settings. Scheduled posts are cancelled and channels are disconnected.

3.2 You have 30 days to export your content in a common format (JSON and the original media files). After 30 days we delete it, except as section 2 says.

3.3 Published posts remain on the platforms. Delete them there, or ask us to delete them for you before you close the workspace.

4. Deletion requests

4.1 From a customer: in Settings, or by email to [CONTACT EMAIL] from the account owner's address.

4.2 From someone who appears in content, or comments on a channel: we pass the request to the business that controls the content and help it respond. If we hold data about you as controller, we act on it directly.

4.3 Facebook and Instagram users: remove qypu in Facebook Settings, then Apps and websites, and choose to send a deletion request. We return a confirmation code and a status page at /legal/data-deletion.

4.4 Google and YouTube users: revoke access in your Google Account; we then delete stored YouTube data within 7 days, or sooner where the YouTube API Services policies require.

4.5 We confirm completion of a deletion request, and tell you about any data we must keep and why.

If we receive a valid legal demand or need data to defend a legal claim, we may keep the specific data concerned until the matter ends.

Change log

  • 2026-10-10 · 0.1.0 · First draft.

Open questions for counsel

We publish these while the page is a draft, so you can see what is not settled yet.

  • Confirm tax-record periods per jurisdiction (for example, 6 years UK, 10 years in several EU states, 5 years Australia and Singapore, 7 years NZ).
  • Confirm the 35-day backup rotation matches the Supabase plan in use.
  • Provenance and Authorisation record retention: balance limitation periods against minimisation.

Useful for: Business owners, Your staff, IT and security reviewers, Platform reviewers. To save this page as a PDF, use your browser's Print command. Back to the trust centre.