Tracemill Retention Schedule

Version: retention-v1
Effective date: September 12, 2026

This schedule is incorporated into the Terms. The DPA controls personal-data conflicts; applicable law and expressly agreed Order terms control as provided in the Terms. We are not a backup/evidence archive. Keep your own copies. Ordinary retention continues during trials, suspension and export.

1. While using the Service

DataRetention rule
Temporary authoring sessions/draftsExpire 7 days after the last qualifying write. Reads do not renew expiry. Published private content is separate.
Raw authoring-upload objectsLifecycle expiration is configured for 14 days after upload, independent of session activity. Physical removal follows provider processing; this is not a guaranteed physical-deletion deadline. A refreshed session may outlive an old upload.
Daily posture historyTeams 90 days; trial 30 days unless the Order states otherwise. This is a history-granularity window, not deletion of all underlying records.
Runs/events, validation evidence, historical and archived records, private content/revisions, configuration, workspace membership/activity and integration credentialsRetained as needed for the active ordered Service, subject to shorter periods above and earlier deletion requests. After subscription or trial end, the deletion schedule below applies. Archiving is not deletion; explicit deletion and credential revocation are addressed in Section 3.
Routine API, delivery-worker and Cloud web application logsConfigured retention of 30 days. This does not cover Sentry, database audit logs or other security/access-log stores, and is not a verified physical-deletion deadline.
Download-distribution access logsStored log objects are configured to expire 90 days after creation; physical removal may follow provider processing. This is separate from Plausible website analytics.
Support correspondence and attachmentsRetained as needed to provide support and handle related requests or disputes. Customer content remains subject to the DPA's deletion rules, including copies in forwarded correspondence.
Sentry diagnostics and other routine access logs not listed aboveRetained for troubleshooting and security under configured retention periods, only as needed for those purposes. Customer Personal Data remains subject to the DPA's deletion rules.
Operational measurements not otherwise listed, including feature-use measurements if collectedRetained only as needed to operate, secure or improve the Service within the Terms' Operational Data limits and applicable privacy obligations; delete or deidentify when no longer needed.
Separate login identityRetained while needed to provide access to an active account or workspace. On a valid account-deletion request, we delete information no longer needed, subject to the limited security, legal and trial-eligibility retention described in this schedule. Membership deletion does not itself remove access to another workspace.
Necessary platform-security metadataRestricted to security purposes and access. Configured periods: network flow logs expire after 365 days; database and operator-session logs retain one year; CloudTrail uses a 366-day lock, 400-day current-version expiration and 30-day noncurrent-version expiration. Provider processing may delay physical removal. These settings do not override the DPA or authorize retaining customer payloads, private logic, evidence or live credentials merely because they enter a log.
Minimal trial-eligibility recordEmail or matching identifier, trial-used flag and only needed metadata, potentially surviving account deletion without fixed expiry while the one-trial-per-email rule remains effective and retention necessary/lawful. Periodically review necessity; delete when unjustified. No marketing/analytics use; applicable privacy rights remain.
Billing, contract and privacy-request recordsMinimum records needed for accounting, proof of agreement, requests or disputes, for applicable legal periods/necessary resolution, with purpose-specific review and deletion. No underlying customer content is preserved by this exception.
Deletion-enforcement recordsMinimum identifiers, scope, times/status only, until all copies capable of restoring affected data expire and deletion is verified; then delete or irreversibly anonymize unless limited evidence must legally remain. Protect separately against restoration rollback; no other use.

2. After subscription or trial end

For 30 days after subscription end, you may request export of still-retained associated data through available functions or reasonable support assistance. Earlier category expiry still applies. We verify authority and provide a lawful secure alternative where reasonably feasible if direct access is restricted.

Unless law or the DPA requires otherwise, active copies are deleted within 30 days after that window closes; residual backups within 90 days after active deletion. These are outer limits, not guaranteed retention or ongoing testing access. You may request earlier deletion. Trial expiry starts the same clock unless a valid Order continues the Service; signup discloses this and we send an expiry notice. Cancel-at-period-end starts the clock at actual end, not cancellation request time.

Data needed for a remaining Order stays protected; shared-data termination clocks start when the last relevant Order ends. A new effective Order before termination deletion begins cancels pending purge only for needed, still-retained data. It does not override explicit deletion instructions, pause normal retention or restore expired data. Purchase after deletion begins does not guarantee recovery.

Payment-related access restriction alone does not start this schedule. When a subscription is terminated for nonpayment under the Terms' notice-and-cure process, the schedule starts on actual termination, not retroactively at payment failure or the prior billing period's end.

3. What deletion covers

We act on valid explicit deletion requests without waiting for the workspace's subscription to end, subject to the DPA and applicable law. Revoked Tracemill access credentials stop authorizing access immediately; only necessary revocation/audit records and protected backup copies may remain under this schedule. Revoke credentials issued by your SIEM or other external providers through those providers. Removing an individual login or membership does not itself delete a shared workspace or other users' data.

We purge active stores and require appropriate deletion by our providers; hiding a record is not erasure. Backups stay protected and beyond ordinary use until expiry; deletions are reapplied before restored data becomes available. We verify recoverable-copy expiry and completion before removing the minimal deletion record. On reasonable request, we confirm completion and explain permitted records or backup expiry still pending.

Necessary lawful security/business records may remain only for their specified purposes and periods, not as an excuse to retain customer content. Processor-only personal data retention must follow lawful instructions or a legal storage requirement. Legally required preservation is limited to its duty and ends when that duty ends. An immutable storage setting alone is not a legal retention duty.

Our deletion does not remove copies in your SIEM/storage, downloads, independent clients or AI providers. Revoke unneeded integration permissions. Email support@tracemill.io for export/deletion requests. Changes to this schedule follow the Terms' contractual update rules; a webpage edit cannot silently extend an accepted deadline.