Data Retention Summary
1. The rule
A retention period is a maximum, not a target. Data kept beyond its period is a liability rather than an asset. Four categories are kept indefinitely and section 4 says which and why.
This summary supports the Privacy Policy. Where the two differ, the Privacy Policy governs.
2. How long each kind of data is kept
| What it is | Kept for | Removed when |
|---|---|---|
| Your working data: lists, watchlists, reviews, sign-offs, document requests, notification routes, onboarding progress | The life of your account, plus 30 days | 30 days after you close the account |
| Derived state: digests, drift events, score history | 24 months, rolling | It passes 24 months, or you close the account |
| A published profile and its endorsements and domain claims | While published, plus 30 days | 30 days after you unpublish. An opt-out is immediate |
| Records of who accessed a document you shared | 24 months | It passes 24 months. These records cannot be altered before then |
| Team membership | The life of the workspace | Immediately on removal |
| Access tokens and feed credentials | The life of the account | Immediately on rotation or closure |
| Rate limiting counters | 7 days | It passes 7 days |
| Invitations that were never accepted | 12 months | It passes 12 months |
| Requests sent to a trust centre | 24 months | It passes 24 months |
| Dispute records | Indefinitely. See section 4 | Never |
3. Backups
A nightly encrypted database dump is taken and kept for 30 days.
A deletion is not complete until it has aged out of backups. Data deleted from live systems is gone from them immediately and persists in backup copies for up to 30 days, after which those copies expire automatically. That is the honest statement and it is the one to rely on.
Error reports, transactional email records and application logs are held by the providers named in the Sub-Processor List, under their own retention periods.
4. What is kept indefinitely, and why
Four categories. Each is a deliberate exception.
Dispute records, including facts that were corrected or withdrawn. The purpose of a correction record is to show what a page used to say. A correction history that can be erased is not a correction history.
Opt-out records. When a listed company opts out permanently, the descriptive content is deleted and only the domain and the fact of the opt-out are kept, so that a later observation cannot recreate the listing. Keeping less would break the promise that the opt-out is permanent.
Corporate and formation records, as statute requires.
Executed agreements, for the life of the agreement plus the applicable limitation period.
5. Deleting your data
| What you ask for | What happens | How long |
|---|---|---|
| Close your account | Working data purged from live systems | 30 days |
| Opt a listing out | Descriptive content deleted; domain and opt-out fact retained | Immediate |
| Erasure of personal data | Live systems purged; dispute and opt-out records assessed individually | 30 days |
| Backup expiry | Automatic, no action needed | Within 30 days of deletion |
An erasure request touching a dispute record is assessed rather than executed automatically, because the correction history exists to protect other parties and a blanket rule in either direction would be wrong. Where a record is retained against a request, you are told which record and why.
Requests go to privacy@trooth.co.