How retention, deletion, backup expiry, anonymization, and exceptions work. Last updated October 2, 2026.
This Policy applies to account data, workspace content, operational records, credentials, billing records, backups, and metrics. A shorter signed customer period applies where feasible; a longer legal requirement controls only affected data. Deletion includes secure erasure, cryptographic erasure, irreversible anonymization, or controlled lifecycle expiry.
The table is the default. A signed order form or lawful hold may modify a specific row.
Enforcement status, October 2, 2026: our policy is to complete accepted erasure requests within 30 days, subject to lawful exceptions. What runs automatically today: the tenant audit log (the record of actions taken in a workspace) is removed after 30 days, and a few operational records (delivery queues, page-visit records, and duplicate-request markers) are removed on a schedule. Conversation logs are not deleted automatically at their 90-day period. For every other period in the table, the period is our commitment, but removal at the end of that period is not yet automatic. We fulfill those through a deletion request, and you can email privacy@armalo.ai to confirm what has been deleted for your account. Request logs have no automatic expiry yet. They are append-only and cannot yet be deleted on request; if a request covers them, we will tell you.
| Data class | Retention | Legal basis / purpose | Deletion |
|---|---|---|---|
| Core account identity | Active account + 30 days | Contract; administration; security | Remove active records and mappings; backups rotate |
| OAuth and email authentication | Active account + 30 days | Contract; authentication; fraud prevention | Revoke sessions, mappings, and tokens; expire backups |
| Organization membership | Active membership + 30 days | Contract; authorization; audit | Delete membership; retain only scheduled audit evidence |
| Workspace metadata and content | Active workspace + 30 days | Contract; customer instructions | Delete records, objects, indexes, artifacts, and controlled replicas |
| Source code and repository snapshots | Active workspace + 30 days | Contract; requested build operations | Delete snapshots, caches, and objects; revoke grants |
| Build artifacts and previews | Configured lifecycle; no later than 30 days after workspace deletion | Contract; service delivery | Stop routing and remove artifacts, volumes, and objects |
| Conversation log | Active workspace; routine retention 90 days after the conversation | Contract; collaboration; recovery; support | Accepted erasure or workspace deletion removes active-system data within 30 days; automatic removal at the routine window is not yet in place |
| AI Cofounder prompts and outputs | Parent workspace or conversation schedule | Contract; requested processing | Delete with parent data and derived indexes |
| AI Cofounder traces containing customer content | Active workspace + 90 days | Contract; debugging; security | Delete payloads; retain anonymized metrics where possible |
| Tenant audit logs | 30 days by default | Legitimate interests; accountability; security | Automatic daily removal after the retention period; investigation holds reviewed at closure |
| Request logs | No automated expiry today | Legitimate interests; security; accountability | No automatic expiry yet; append-only, cannot yet be deleted on request |
| Support tickets | Support relationship + 24 months | Contract; claims | Delete or anonymize ticket and attachments |
| Sales communications | 24 months after substantive interaction | Legitimate interests; consent | CRM lifecycle deletion or suppression |
| Billing, invoices, credit ledger | 7 years | Tax; accounting; disputes | Delete after statutory period or legally anonymize |
| Metered usage ledger | 7 years when billed; otherwise 24 months | Contract; accounting; pricing disputes | Delete details; retain anonymized aggregates |
| Integration credentials and BYO model keys | While configured; prompt revocation on removal | Contract; customer instruction; security | Revoke grant, delete encrypted secret, expire short-lived grants |
| Session and necessary cookies | Session or stated cookie lifetime | Contract; security | Browser expiry, logout, and server revocation |
| Optional analytics cookies | Consent duration or shorter cookie-policy period | Consent | Withdrawal, expiry, and provider lifecycle deletion |
| IP addresses and infrastructure logs | 30–90 days | Legitimate interests; security; reliability | Rotation, hashing where feasible, and partition expiry |
| Performance and feature analytics | Up to 13 months when pseudonymous | Legitimate interests; product improvement | Raw-event expiry, identifier removal, or aggregation |
| Error reports | Up to 12 months | Legitimate interests; reliability | Error-store lifecycle deletion |
| Aggregated service and financial metrics | Indefinite when anonymized | Legitimate interests; planning and reliability | Irreversible anonymization before retention |
| Database backups | 7-day rotation | Resilience; disaster recovery | Automated encrypted generation rotation |
| User-uploaded files | No backup coverage currently | Resilience; disaster recovery | Not backed up today - deletion of the live object is final; backup coverage for uploads is planned |
| Deleted data in database backups | Within the 7-day backup rotation after live deletion | Resilience balanced with erasure | Live deletion on accepted request; backup expiry within the 7-day rotation |
| Cloud workspace filesystem and snapshots | Active workspace; no later than 30 days after workspace deletion | Contract; execution and continuity | Terminate the workspace and delete volume and snapshots |
| Temporary AI Cofounder working files | Retained while the run is active | Contract; execution | Workspace teardown and ephemeral destruction |
| Model-provider request data | Selected provider terms; Armalo copy follows workspace schedule | Customer instruction; contract | Delete Armalo copy; customer manages provider account |
| AI training data | Not created by default; opt-in only | Consent or written agreement | Opt-out stops collection; delete or de-identify under terms |
| Data subject request records | Completion + 3 years | Legal obligation; accountability | Delete request content; retain anonymous outcomes |
| Contracts and legal notices | Term + 7 years | Legal obligation; claims | Contract lifecycle deletion |
| Abuse reports | 90 days after closure | Legitimate interests; safety; claims | Delete content; retain minimal fingerprint only if necessary |
Users may delete eligible content. Owners and authorized administrators may delete workspaces. Account holders may request account deletion; Data Subjects may email privacy@armalo.ai. Valid erasure requests are fulfilled within 30 days unless law permits or requires an extension. Active records, indexes, caches, derived artifacts, controlled replicas, and applicable subprocessor copies are included.
Account deletion disables access and starts deletion. Personal workspaces owned only by that account are scheduled for deletion; organization workspaces remain under organization authority. Credentials are revoked, cloud workspaces and previews terminate, and active data is removed within 30 days. Legally required billing records remain for seven years. Database backup copies expire within the 7-day rotation after live deletion.
Indefinite aggregated metrics must be anonymous, not merely pseudonymous. Names, email, full IP, OAuth and account IDs, workspace IDs, repository URLs, identity-bearing paths, raw messages, credentials, prompts, source code, and customer file content are excluded or removed. Hashing alone is not anonymization where re-identification remains reasonably possible.
Encrypted database backups use a 7-day rotation and are restricted to resilience and recovery. They are not used for analytics or ordinary access. User-uploaded files are not currently backed up, so a restore cannot recover them; backup coverage for uploads is planned. Active deletion completes on an accepted request; affected database backup generations expire within the 7-day rotation after live deletion. Restore procedure requires reapplying deletion markers before normal operation.
Backups are encrypted and stored in the Hetzner environment in the United States (Hetzner us-west) with Cloudflare edge controls; cloud workspace snapshots follow the same residency.
Deletion can pause for a scoped legal hold, proportionate security or fraud investigation, tax or accounting duty, sanctions or regulatory requirement, legal claim, or minimal suppression record. Exception data is need-to-know, cannot be repurposed incompatibly, and is deleted when the exception ends.
Material retention changes receive at least 60 days’ notice unless law or urgent security needs require earlier effect. Armalo will not retroactively extend data already scheduled for deletion without a valid basis.
Email privacy@armalo.ai with the account, workspace, data category, and authority to act. Do not include passwords, OAuth codes, API keys, or secrets.
Contact privacy