POLICY / 03

KEEP.
EXPORT.
DELETE.

EFFECTIVE AUGUST 7, 2026.

Cancellation, export, and deletion are separate self-serve controls. The schedules are explicit.

01

What is kept.

Kill the CRM keeps only work the verified owner deliberately sends, the derived memory, answers, and corrections linked to that work, and account, consent, billing, security, and audit information needed to operate the service.

02

Choose a source schedule.

UNTIL I DELETE ITKeep active source and dependent memory until deletion or the post-cancellation schedule.
24 MONTHSPurge each source and dependent memory 24 months after receipt.
12 MONTHSPurge each source and dependent memory 12 months after receipt.
90 DAYSPurge each source and dependent memory 90 days after receipt.

A shorter Account choice enters a 24-hour cancelable pending state and shows affected source counts and earliest purge time. After purge, the content cannot be restored. A longer choice applies only to content that still exists.

03

Cancellation is not deletion.

Cancellation stops renewal. It does not delete content. When trial or paid entitlement ends, Account becomes read/export-only for 30 days. Deletion then begins unless the owner reactivates or requests earlier deletion.

04

Export.

The verified owner can request a machine-readable ZIP through Account. It includes a versioned manifest and checksums, normalized selected source emails, extracted attachment text, source-linked memory, questions, answers, no-evidence outcomes, corrections, settings and consent, billing references, and relevant audit history. It excludes full card data, credentials, and provider secrets. The single-use download expires after 24 hours or first successful download.

05

Deletion.

Deletion is self-serve and separate from cancellation. It requires recent authentication and typing the agent address. Confirmation pauses new ingestion and answers and starts a 24-hour cooling-off period. The owner can cancel during that period. Once local processing begins, deletion cannot be undone.

Local sources, attachments, extracted text, memory, questions, answers, corrections, sessions, addresses, jobs, and exports are removed. The subscription is canceled if still renewable. A content-free completion record remains for limited billing, dispute, fraud, and legal needs.

Resend email copies and encrypted content backups use 30-day standard windows. Anthropic normally deletes API inputs/outputs within 30 days but may retain limited data longer for documented usage-policy, legal, or contractual reasons. Its current policy describes up to two years for flagged inputs/outputs and up to seven years for safety scores. The completion receipt separately shows local deletion, Resend and backup deadlines, Anthropic’s normal deletion estimate, the policy version, the exception disclosure, and whether any provider receipt exists. It does not certify provider erasure without a receipt. Deleted tenant content is never restored into active service from backup.

06

Other schedules.

RecordSchedule
Incomplete Checkout / unverified account7 days
Unauthorized inbound minimal hashed delivery metadata7 days; no content retrieval after routing failure
Export artifact24 hours or first download
Redacted application logs30 days
Content backup roll-off after deletionUp to 30 days
Resend email copies after deletion30-day standard window
Anthropic commercial API inputs/outputsNormally within 30 days, with documented longer usage-policy, legal, or contractual exceptions
Content-free consent, billing, security, and deletion recordsOnly as long as reasonably required