Retention timelines are consistent across billing, automated deletion jobs, backups, and this documentation. This page explains what we keep, for how long, and how you can delete data yourself.
Cancelled workspaces
- Grace period: Until end of current billing period; full access continues
- Access ends: At grace period end; workspace closed; deletion schedule begins
- 60 days after access ends: Personal data anonymised (soft delete)
- 90 days after access ends: Permanent deletion (hard delete) from production systems
During the grace period you may reactivate or export data. After hard delete, recovery is not available except from encrypted backups within the backup retention window (see below).
Other data categories
- Audit logs: Retained 2 years, then purged automatically
- Cookie consent records: 1 year
- Privacy requests: 3 years after completion (compliance evidence)
- Billing records: Retained as required by tax law (typically 6 to 7 years)
- Support correspondence: Up to 3 years after ticket closure unless linked to an active legal matter
- Marketing contact data: Until you unsubscribe or request deletion, plus a short suppression record
- Backups: Supabase encrypted point-in-time recovery; rolling schedule independent of application lifecycle
Account deletion
Individual users can delete their account from Profile → Security → Delete my account. This removes personal profile data and revokes access. Workspace content may remain if other members exist; workspace admins control workspace deletion.
Workspace deletion
Workspace admins can delete a workspace from Workspace Settings. Deletion follows the cancelled workspace schedule above. Organisation-level billing may continue if other workspaces remain active.
Self-service export
Before deletion, export your data from Profile → Privacy → Download my data (JSON format). Workspace admins may export audit logs as CSV from workspace compliance settings.
Legal holds
We may retain data longer where required by law, regulation, litigation, or regulatory investigation. Affected data is isolated and access is restricted to authorised personnel.