RetainerMeter / Legal / Retention schedule

Effective 24 August 2026

RetainerMeter Web retention and deletion schedule

How retention works. RetainerMeter keeps active workspace data only for the service, export, recovery, security, and legal purposes described below. Separate payment, tax, consent, fraud-prevention, and business records may follow different legally required periods.
Record domainPeriod/actionReason
Trial or approved pilot workspace and authenticationFull access through the account's stated end date; 14-day read-only grace; 30-day inaccessible/restorable period; then delete active dataTrial or pilot access, export opportunity, short recovery window, then minimization
Unused pilot approvalReservation expires after 7 days; remove the stored application email from the pilot registry within 30 further daysRelease the limited place and minimize application data
Ended paid workspace and authenticationFull through paid-through; 14-day read-only grace; 30-day inaccessible/restorable period; then delete active dataHonour paid access and provide a bounded recovery/export window
Verified self-service deletionOffer final backup, then remove active workspace/authentication data within 24 hoursCustomer request, subject to records that must lawfully be retained separately
Provider residual backupsExpire under the provider's applicable backup and recovery terms; unavailable to the customerDisaster recovery with bounded provider-controlled expiry
RetainerMeter billing/tax ledgerRetain for the applicable statutory periodTax, accounting, reconciliation, chargeback, and legal obligations
Authentication codesExpire after 10 minutes; remove expired consumed records during maintenanceAuthentication security and replay prevention
Sessions30-day rolling expiry; revoke on logout-all, sensitive rotation, deletion, or lifecycle purgeAccount access and security
Portable pre-restore snapshotShort operational recovery window, then automatic expiryRecover from failed or mistaken replacement without indefinite duplication
Lifecycle email jobs and content-free operational eventsRetain for a proportionate troubleshooting and audit period consistent with operational and legal needsDelivery idempotency, security, billing, deletion evidence, and reliability
User-directed invoice email at the email providerProvider-controlled retention under the provider's current terms and settingsMessage delivery and troubleshooting; the provider copy is not a RetainerMeter invoice-file archive
Consented campaign analyticsFollow the website's documented first-party retention; missing attribution remains unknownAggregate acquisition measurement without workspace content or fingerprinting

Warnings

Access messages are scheduled relative to the account's stated full-access end, grace end, and deletion date, so the same warnings remain accurate for the standard trial and an approved longer pilot. Equivalent paid-end warnings are based on the authoritative paid-through date.

Ambiguity guard

The lifecycle worker must not delete a workspace when subscription or lifecycle state is ambiguous. It records the failure for operational review instead.

Separate domains

Deleting Web content does not require deletion of every payment, tax, consent, fraud-prevention, or legal record. Each separate record category needs its own documented purpose and period. Customers remain responsible for exporting statutory business records before purge or account deletion.