Data Retention Policy
Retention policies are usually written aspirationally. This one describes what the software actually does. The short version: VERA keeps your data for as long as your account exists and does very little automatic deletion, because a business tool that quietly deletes last year's invoices is a worse product. Deleting your account is what removes your data, and that deletion is immediate and thorough.
- Version
- 1.0
- Effective
- July 28, 2026
- Last updated
- July 28, 2026
- Revisions
- 1
On this page (5 sections)
1. Principles
Data is retained for as long as it is needed for the purpose it was collected for, plus any period the law requires. For an operational business tool, that period is normally the life of the account: your estimates, invoices, customer records, and audit history are records you need to be able to look back at.
Deletion in VERA means removal from the live database. It is not a soft-delete flag, and there is no recycle bin from which an account can be restored.
2. Retention by category
The table below states the actual behavior of the system today.
| Data | Retention | How it ends |
|---|---|---|
| Account, business profile, brand kit | Life of the account | Deleted when you delete your account |
| Customer and operational records (leads, contacts, companies, deals, jobs, appointments, technicians, support tickets) | Life of the account | Delete individual records in the app, or all of them by deleting the account |
| Estimates, invoices, imported documents and their original file copies | Life of the account | Delete individually in the app, or by deleting the account |
| Uploaded photographs, logos, and generated images | Life of the account | Delete in the app, or by deleting the account |
| Content drafts, proposals, and generated content | Life of the account | Delete in the app, or by deleting the account |
| Audit trail and security events | Life of the account. Append-only; never edited or deleted in ordinary operation | Removed with the account |
| Industry Radar news articles | 30 days | Pruned automatically on each scan |
| Connector credentials (OAuth tokens, API keys) | Until you disconnect the integration | Removed on disconnect, and on account deletion |
| Session tokens | Until expiry, sign-out, or revocation | Revoked immediately by password reset, sign out of all devices, or suspension |
| Email verification and password reset tokens | 24 hours and 1 hour respectively, single use | Expire or are consumed; cleared on account deletion |
| OAuth flow state cookies | 10 minutes | Expire in the browser |
| Rate-limit counters | One fixed window per key, overwritten when the window resets | Overwritten in place. Rows may persist keyed to an email address or IP address until the next attempt from that key |
| Webhook delivery ids (replay protection) | Retained as a small provider and event-id record | Not user-scoped; not removed by account deletion |
| Platform admin audit log | Retained after the affected account is removed, by design | Kept as an operator accountability record |
| Stripe billing records | Held by Stripe under its own retention and financial record obligations | Governed by Stripe, not by VERA |
| Server and error logs | Retained by the hosting provider under its default log retention | Rotated by the provider |
3. What VERA does not delete automatically
Apart from the Industry Radar prune and the token expiries above, VERA does not currently run scheduled deletion of your data. If you want something gone, delete it in the app or delete the account.
Some plan descriptions refer to a task history window of 30 days, 6 months, or 12 months by tier. Treat those as descriptions of the history the interface is designed to surface, not as a deletion schedule; VERA does not currently purge history when a window elapses.
4. Backups
VERA does not operate its own backup tooling. Durability and point-in-time recovery depend on the managed database provider hosting the deployment, under that provider's capabilities and retention.
This means we cannot promise that deleted data is purged from every provider-held backup snapshot immediately. It is removed from the live database at once and would age out of provider snapshots on the provider's cycle. We also cannot restore an account you deleted, even from a backup.
5. Data you hold as a controller
For personal data about your own customers, you decide the retention period; VERA retains it for as long as you keep it in the account. If your own retention policy is shorter than the life of your VERA account, delete those records in the app when their period ends. VERA does not enforce a retention schedule on your behalf.
Change history
Every revision of this document, newest first. Material changes are notified to account holders before they take effect where practicable.
- v1.0July 28, 2026
Initial Data Retention Policy published.
Questions about this document?
Legal and contracts: support@myvera.io. Privacy and data rights: support@myvera.io. Security reports: support@myvera.io.
Related
This document is a carefully drafted policy written against how VERA actually works. It is not legal advice, and it should be reviewed by a licensed attorney in your jurisdiction before you rely on it.
