Data Retention

Version 2026-08-01 · Effective 1 August 2026

How long each kind of data stays in Aulay. These are the schedules the software actually runs, not aspirations.

Your account and your work

DataRetention
Account, profile, subscription stateUntil you delete your account
Workspaces, projects, sessions, stored credentialsUntil you delete them, or until you delete your account
Agent transcripts — your prompts and the agent’s outputKept with the session while it exists. Structured invocation records of the same content are pruned after 90 days
Session activity timeline (busy / idle / needs-input)90 days
Feedback reports and attached screenshotsUntil you delete your account
Waitlist entryUntil you are invited, or until you ask us to remove it

Logs

DataRetention
Application logs14 days
Platform and runtime events90 days
Authentication security log — sign-ins, failures, token issue, with IP address and user-agent180 days
Application audit log — which account changed what, and when. Records no IP address, no user-agent, and no request contentsKept in the live database; archived copies are held for 365 days and then deleted
Rate-limit counters keyed on email address and IPExpire within an hour; swept every 15 minutes

Backups

BackupRetention
Nightly database backup, encrypted, stored off-site30 days
Monthly database backup, encrypted, stored off-site365 days
Archived audit records365 days

How deletion interacts with backups

When you delete your account, your data is removed from our live systems within 30 days. It will still exist for a time inside encrypted backups, because a backup is a point-in-time image and editing one would defeat its purpose.

Our commitment about those copies:

  • They are encrypted and stored off-site.
  • They are never opened, searched, mined or selectively restored to reach an individual record.
  • They are deleted on the rotation above — 30 days, or 365 for a monthly image.
  • If we ever restore a backup after a disaster, every deletion made since that backup was taken is replayed against the restored data before the system returns to service. We keep a record of deletions outside the database precisely so that this is possible.

What survives account deletion

  • Anonymised security log entries. We keep the event and its timestamp and remove the IP address, user-agent, and any other identifying detail. We rely on this to investigate abuse across accounts.
  • Invoices and payment records held by Stripe, which both they and we are required to retain for financial and tax purposes.

Everything else goes: account, profile, sessions, transcripts, projects, credentials, preferences, usage counters and support history.

Questions

If you want to know what we hold about you specifically, ask at privacy@aulay.io and we will send you a copy. See the Privacy Policy for your other rights.

Previous versions of this document are available on request.