POLICY / 03

DATA
RETENTION.

EFFECTIVE AUGUST 7, 2026.

The complete retention schedules for Kill the CRM. The Privacy Policy summarizes these; this page is the full schedule.

01

The retention choice.

Active source and derived data follow the retention choice selected in Account:

  • Until deletion. Content is kept until you delete it or the account.
  • Rolling 24 months. Content older than 24 months is purged on a rolling basis.
  • Rolling 12 months. Content older than 12 months is purged on a rolling basis.
  • Rolling 90 days. Content older than 90 days is purged on a rolling basis.

02

Changing the choice.

A change to a shorter window has a 24-hour cancelable period before it takes effect. Once purging under a shorter window has run, already-purged data cannot be restored. A change to a longer window applies only to data still held; it does not recover anything already purged.

03

Cancellation and deletion.

  • After cancellation. When the subscription entitlement ends, read and export access remains for 30 days. Deletion then begins.
  • Direct deletion. A deletion request uses a 24-hour cooling-off period before local processing begins. Local product data is then removed.
  • Backups. Content backups use 30-day standard windows. A deleted tenant is not restored from backup.

04

System schedules.

  • Incomplete or unverified accounts expire after 7 days.
  • Unknown or unauthenticated inbound delivery keeps only minimal hashed delivery metadata, for 7 days. Content is not retrieved after the routing check fails.
  • Export downloads expire after 24 hours or on first successful download, whichever comes first.
  • Redacted application logs expire after 30 days.
  • Resend email copies use 30-day standard windows.

05

Provider retention.

Anthropic currently states that commercial API inputs and outputs are not used to train its models by default, and normally deletes API inputs/outputs within 30 days. It may retain limited data longer for documented usage-policy, legal, or contractual reasons; its current policy describes up to two years for flagged inputs/outputs and up to seven years for safety scores. See the Subprocessors page for the full provider list.

06

What remains.

Content-free billing, consent, security, fraud, and deletion records remain only as reasonably required for accounting, disputes, legal obligations, and abuse prevention. See the Privacy Policy for scope and rights.