Data Retention Policy

Retention policies are usually written aspirationally. This one describes what the software actually does. The short version: VERA keeps your data for as long as your account exists and does very little automatic deletion, because a business tool that quietly deletes last year's invoices is a worse product. Deleting your account is what removes your data, and that deletion is immediate and thorough.

Version
1.0
Effective
July 28, 2026
Last updated
July 28, 2026
Revisions
1
On this page (5 sections)
  1. 1. Principles
  2. 2. Retention by category
  3. 3. What VERA does not delete automatically
  4. 4. Backups
  5. 5. Data you hold as a controller

1. Principles

Data is retained for as long as it is needed for the purpose it was collected for, plus any period the law requires. For an operational business tool, that period is normally the life of the account: your estimates, invoices, customer records, and audit history are records you need to be able to look back at.

Deletion in VERA means removal from the live database. It is not a soft-delete flag, and there is no recycle bin from which an account can be restored.

2. Retention by category

The table below states the actual behavior of the system today.

DataRetentionHow it ends
Account, business profile, brand kitLife of the accountDeleted when you delete your account
Customer and operational records (leads, contacts, companies, deals, jobs, appointments, technicians, support tickets)Life of the accountDelete individual records in the app, or all of them by deleting the account
Estimates, invoices, imported documents and their original file copiesLife of the accountDelete individually in the app, or by deleting the account
Uploaded photographs, logos, and generated imagesLife of the accountDelete in the app, or by deleting the account
Content drafts, proposals, and generated contentLife of the accountDelete in the app, or by deleting the account
Audit trail and security eventsLife of the account. Append-only; never edited or deleted in ordinary operationRemoved with the account
Industry Radar news articles30 daysPruned automatically on each scan
Connector credentials (OAuth tokens, API keys)Until you disconnect the integrationRemoved on disconnect, and on account deletion
Session tokensUntil expiry, sign-out, or revocationRevoked immediately by password reset, sign out of all devices, or suspension
Email verification and password reset tokens24 hours and 1 hour respectively, single useExpire or are consumed; cleared on account deletion
OAuth flow state cookies10 minutesExpire in the browser
Rate-limit countersOne fixed window per key, overwritten when the window resetsOverwritten in place. Rows may persist keyed to an email address or IP address until the next attempt from that key
Webhook delivery ids (replay protection)Retained as a small provider and event-id recordNot user-scoped; not removed by account deletion
Platform admin audit logRetained after the affected account is removed, by designKept as an operator accountability record
Stripe billing recordsHeld by Stripe under its own retention and financial record obligationsGoverned by Stripe, not by VERA
Server and error logsRetained by the hosting provider under its default log retentionRotated by the provider

3. What VERA does not delete automatically

Apart from the Industry Radar prune and the token expiries above, VERA does not currently run scheduled deletion of your data. If you want something gone, delete it in the app or delete the account.

Some plan descriptions refer to a task history window of 30 days, 6 months, or 12 months by tier. Treat those as descriptions of the history the interface is designed to surface, not as a deletion schedule; VERA does not currently purge history when a window elapses.

4. Backups

VERA does not operate its own backup tooling. Durability and point-in-time recovery depend on the managed database provider hosting the deployment, under that provider's capabilities and retention.

This means we cannot promise that deleted data is purged from every provider-held backup snapshot immediately. It is removed from the live database at once and would age out of provider snapshots on the provider's cycle. We also cannot restore an account you deleted, even from a backup.

5. Data you hold as a controller

For personal data about your own customers, you decide the retention period; VERA retains it for as long as you keep it in the account. If your own retention policy is shorter than the life of your VERA account, delete those records in the app when their period ends. VERA does not enforce a retention schedule on your behalf.

Change history

Every revision of this document, newest first. Material changes are notified to account holders before they take effect where practicable.

  1. v1.0July 28, 2026

    Initial Data Retention Policy published.

Questions about this document?

Legal and contracts: support@myvera.io. Privacy and data rights: support@myvera.io. Security reports: support@myvera.io.

Related

This document is a carefully drafted policy written against how VERA actually works. It is not legal advice, and it should be reviewed by a licensed attorney in your jurisdiction before you rely on it.