Trust

Retention and Export

This page clarifies dashboard availability, compliance audit record retention, export paths, and deletion process. It is not legal advice or a custom retention agreement.

Data categoryExamplesRetention posture
Customer-facing dashboard decision recordsSignal source, decision outcome, policy flags, response code, timestampsRetention targets: Developer 30 days, Pro 1 year, Enterprise negotiated. Records are purged by an operator-scheduled retention job (purge_gpc_signals_before); until that schedule is configured for an environment, records are retained — see the retention note below.
Compliance audit recordsDecision evidence retained for compliance support and service operationMay differ from dashboard availability; governed by Privacy Policy or signed agreement
Account and site configurationCompany name, user email, domains, DPA status, API key metadataRetained while the account is active, then deleted subject to legal and operational requirements
Billing recordsPlan, Stripe customer ID, subscription status, invoices handled by StripeRetained as needed for billing, tax, accounting, dispute, and legal obligations

Retention note

Retention targets are enforced by an operator-scheduled purge job (purge_gpc_signals_before) per environment. Customers should not assume automatic deletion until the schedule is confirmed for their environment; contact support for the current operational status of a specific environment.

Export Process

  • Use dashboard evidence views for current self-serve decision-record access.
  • For larger exports or enterprise workflows, contact support with the account, site, requested period, and desired format.
  • GPCGuard may verify requester authority before exporting customer data.
  • Exports are scoped to the requesting tenant and do not include other customer data.

Deletion Process

Customers can request account closure or deletion review through support. Some records may be retained when needed for legal, billing, security, audit, or operational obligations. Enterprise agreements can define custom deletion and retention handling.

Tenant Isolation

Dashboard data is tenant-scoped through authenticated user paths and database policy boundaries. Export and deletion work should be scoped to the requesting account and verified before release or removal.