TRUST CENTER

Retention and deletion

Current product defaults and lifecycle behaviour; contractual periods may be shorter and must be recorded per customer.

Last reviewed: 31 August 2026

Default 365 days

Privacy-reduced analytics

Expired analytics and behavioural aggregates are purged by the scheduled lifecycle job.

Default 730 days

Article feedback

Reader feedback and optional comments are deleted after the configured period.

Default 365 days

Learning progress

Old learning progress and completed integration evidence are removed according to the configured period.

Default 90 days

AI interactions

Stored assistant questions and source references are removed after the configured period.

10 minutes

Prepared export link

The signed download grant expires and owner membership is checked again. The generated JSON is not persisted by Beetl.

Default 30 days

Organisation cooling-off

Confirmed owner deletion requests become eligible after the cooling-off period. The lifecycle job deletes tenant database records transactionally and then removes private objects. Failed object cleanup is recorded without object keys for operator remediation.

Deployment evidence required

Backups

Backup retention and deletion propagation depend on the production provider. The approved customer agreement must state the period and restore isolation procedure.