Data retention
These are the periods the application actually enforces, on a daily schedule. They are generated from its configuration, so this page cannot say one thing while the software does another.
Deleted on a schedule
| What | Kept for | Why that long |
|---|---|---|
| Run progress events | 90 days | They exist to drive the live view while a brief is running. Nothing reads them afterwards, and they are most of the growth. |
| Model call records | 2555 days | The internal meter behind a charge. Never shown to a customer, but it has to outlive any plausible billing query. |
| Expired sessions | 30 days | Each row holds an IP address and a browser. Kept only as long as a session might plausibly be resumed. |
Not deleted on a timer, and why
An agency's work is not expired by a clock. Outputs, their citations and their approval trails are the record a client may ask for years later, and quietly deleting them would be worse than keeping them. They are removed when a workspace is deleted, which is a decision somebody takes.
- Approvals. A sign-off is the record that a named human approved promotional material for a medicine. See the privacy notice for why the approver's name is retained even after that person's account is erased.
- The credit ledger. Append-only, and the financial record of what an agency owes. Deleting a row would not just lose history; it would make the balance wrong.
- Briefs, outputs and citations. The agency's own work.
- Withdrawn documents. Kept as records on purpose. The row is what excludes the document from retrieval, because the service that indexes documents has no deletion operation — so removing the record would put the text back into circulation. That is the opposite of what retention is for.
Deleting a workspace
An owner can request deletion, which starts a grace period and then removes everything in the workspace permanently. Export anything you need to keep before that date; we cannot recover it afterwards, and neither can support.