Policies
Data Retention
Last updated: June 17, 2026 · Version 0.1 (DRAFT)
We keep personal data only as long as needed for the purpose it was collected, or as required by law, then delete or irreversibly anonymise it. Erased data may briefly persist in encrypted backups until they age out within our disclosed backup window; a suppression list prevents restored backups from resurrecting erased records.
| Data category | Retention period | Legal basis |
|---|---|---|
| Account profile (name, email) | 3 years from last activity (default) | Contract / consent |
| Authentication (password hash, sessions) | Until account deletion; sessions expire sooner | Contract |
| Consent records | Life of relationship + statutory minimum (append-only) | Legal obligation |
| Data-request (DSR) tickets + closure evidence | Statutory minimum after closure | Legal obligation |
| Billing / invoices (GSTIN etc.) | As required by Indian tax law | Legal obligation |
| Uploaded files | With your account; erased on request / deletion | Contract / consent |
| Security & audit logs | ≥ 180 days in India (CERT-In) | Legal obligation |
| Marketing consent + email suppression | Until withdrawal; suppression kept to honour opt-out | Consent |
Security logs are retained in India (ap-south-1) for at least 180 days to meet CERT-In requirements — this is the one carve-out to our erasure timelines, and it is disclosed here and in the India DPDP Notice.