How retention, deletion, backup expiry, anonymization, and exceptions work. Last updated July 22, 2026.
This Policy applies to account data, workspace content, operational records, credentials, billing records, backups, and metrics. A shorter signed customer period applies where feasible; a longer legal requirement controls only affected data. Deletion includes secure erasure, cryptographic erasure, irreversible anonymization, or controlled lifecycle expiry.
The table is the default. A signed order form or lawful hold may modify a specific row.
| Data class | Retention | Legal basis / purpose | Deletion |
|---|---|---|---|
| Core account identity | Active account + 30 days | Contract; administration; security | Remove active records and mappings; backups rotate |
| OAuth and email authentication | Active account + 30 days | Contract; authentication; fraud prevention | Revoke sessions, mappings, and tokens; expire backups |
| Organization membership | Active membership + 30 days | Contract; authorization; audit | Delete membership; retain only scheduled audit evidence |
| Workspace metadata and content | Active workspace + 30 days | Contract; customer instructions | Delete records, objects, indexes, artifacts, and controlled replicas |
| Source code and repository snapshots | Active workspace + 30 days | Contract; requested build operations | Delete snapshots, caches, and objects; revoke grants |
| Build artifacts and previews | Configured lifecycle; no later than 30 days after workspace deletion | Contract; service delivery | Stop routing and remove artifacts, volumes, and objects |
| Conversation log | Active workspace + 90 days after conversation or deletion | Contract; collaboration; recovery; support | Scheduled deletion of messages, events, and indexes |
| Agent prompts and outputs | Parent workspace or conversation schedule | Contract; requested processing | Delete with parent data and derived indexes |
| Agent traces containing customer content | Active workspace + 90 days | Contract; debugging; security | Delete payloads; retain anonymized metrics where possible |
| Audit and security logs | 90 days by default | Legitimate interests; accountability; security | Partition expiry; investigation holds reviewed at closure |
| Support tickets | Support relationship + 24 months | Contract; claims | Delete or anonymize ticket and attachments |
| Sales communications | 24 months after substantive interaction | Legitimate interests; consent | CRM lifecycle deletion or suppression |
| Billing, invoices, credit ledger | 7 years | Tax; accounting; disputes | Delete after statutory period or legally anonymize |
| Metered usage ledger | 7 years when billed; otherwise 24 months | Contract; accounting; pricing disputes | Delete details; retain anonymized aggregates |
| Integration credentials and BYO model keys | While configured; prompt revocation on removal | Contract; customer instruction; security | Revoke grant, delete encrypted secret, invalidate leases |
| Session and necessary cookies | Session or stated cookie lifetime | Contract; security | Browser expiry, logout, and server revocation |
| Optional analytics cookies | Consent duration or shorter cookie-policy period | Consent | Withdrawal, expiry, and provider lifecycle deletion |
| IP addresses and infrastructure logs | 30–90 days | Legitimate interests; security; reliability | Rotation, hashing where feasible, and partition expiry |
| Performance and feature analytics | Up to 13 months when pseudonymous | Legitimate interests; product improvement | Raw-event expiry, identifier removal, or aggregation |
| Error reports | Up to 12 months | Legitimate interests; reliability | Error-store lifecycle deletion |
| Aggregated service and financial metrics | Indefinite when anonymized | Legitimate interests; planning and reliability | Irreversible anonymization before retention |
| Backups | 30-day rolling window | Resilience; disaster recovery | Automated encrypted generation rotation |
| Deleted data in backups | No later than 60 days after deletion begins | Resilience balanced with erasure | Live deletion within 30 days; backup expiry within next cycle |
| Sandbox filesystem and snapshots | Active sandbox; no later than 30 days after workspace deletion | Contract; execution and continuity | Terminate sandbox and delete volume and snapshots |
| Temporary agent working files | Run or lease; ordinarily under 24 hours | Contract; execution | Sandbox teardown and ephemeral destruction |
| Model-provider request data | Selected provider terms; Armalo copy follows workspace schedule | Customer instruction; contract | Delete Armalo copy; customer manages provider account |
| AI training data | Not created by default; opt-in only | Consent or written agreement | Opt-out stops collection; delete or de-identify under terms |
| Data subject request records | Completion + 3 years | Legal obligation; accountability | Delete request content; retain anonymous outcomes |
| Contracts and legal notices | Term + 7 years | Legal obligation; claims | Contract lifecycle deletion |
| Abuse reports | 90 days after closure | Legitimate interests; safety; claims | Delete content; retain minimal fingerprint only if necessary |
Users may delete eligible content. Owners and authorized administrators may delete workspaces. Account holders may request account deletion; Data Subjects may email privacy@armalo.ai. Valid erasure requests are fulfilled within 30 days unless law permits or requires an extension. Active records, indexes, caches, derived artifacts, controlled replicas, and applicable subprocessor copies are included.
Account deletion disables access and starts deletion. Personal workspaces owned only by that account are scheduled for deletion; organization workspaces remain under organization authority. Credentials are revoked, sandboxes and previews terminate, and active data is removed within 30 days. Legally required billing records remain for seven years. Backup copies expire no later than 60 days after deletion begins.
Indefinite aggregated metrics must be anonymous, not merely pseudonymous. Names, email, full IP, OAuth and account IDs, workspace IDs, repository URLs, identity-bearing paths, raw messages, credentials, prompts, source code, and customer file content are excluded or removed. Hashing alone is not anonymization where re-identification remains reasonably possible.
Encrypted backups use a 30-day rolling window and are restricted to resilience and recovery. They are not used for analytics or ordinary access. Active deletion completes within the ordinary window; affected backup generations expire no later than 60 days after deletion begins. Restores reapply deletion markers before normal operation.
Backups are encrypted and stored in the EU-primary Hetzner environment with Cloudflare edge controls; E2B sandbox snapshots follow the same residency.
Deletion can pause for a scoped legal hold, proportionate security or fraud investigation, tax or accounting duty, sanctions or regulatory requirement, legal claim, or minimal suppression record. Exception data is need-to-know, cannot be repurposed incompatibly, and is deleted when the exception ends.
Material retention changes receive at least 60 days’ notice unless law or urgent security needs require earlier effect. Armalo will not retroactively extend data already scheduled for deletion without a valid basis.
Email privacy@armalo.ai with the account, workspace, data category, and authority to act. Do not include passwords, OAuth codes, API keys, or secrets.
Contact privacy