Data Retention & Deletion Policy
Version 2026.3 · Last updated: 2026-08-30 · Effective: pending approval
ThutaTech services are currently in private beta: public sign-up is closed and no paid plans are on sale yet. Statements about accounts and billing describe how the Services will operate at public launch.
This is a draft pending legal review. It is not the final version and is not legal advice.
RETN-01 — Approach
This policy states, per data category, how long data is kept and how it is deleted. Where no retention period is currently defined in our systems, the table says "not yet defined" rather than stating an invented period. Items marked "not yet defined" are governance gaps we are resolving before public launch; they are tracked as launch blockers.
RETN-02 — Retention table
| Category | Retention | Deletion path | Status |
|---|---|---|---|
| Account profile (Account Center) | While account exists | Deleted automatically when you delete your account (Clerk deletion → cleanup webhook) | Verified |
| Subscription records | Subscription rows are removed with account deletion; billing/transaction records may be retained as required for tax and accounting law | Automatic + legal-hold retention | Verified (statutory period to be confirmed at legal review) |
| Credit wallets & reservations | While account exists | Deleted automatically with account | Verified |
| Credit ledger & usage events | While account exists | Deleted automatically on account deletion (implemented 2026-07-18) | Verified in code |
| API tokens & OAuth connections | While account exists | Deleted automatically on account deletion (implemented 2026-07-18) | Verified in code |
| Security & admin audit logs (Account Center) | Proposed: 18 months (pending owner confirmation) — retained after account deletion for fraud-prevention/legal purposes | Automatic purge job to be implemented | Proposed |
| Studio career documents & analyses (resumes, job matching) | While account exists | Deleted automatically on account deletion (implemented 2026-07-18) | Verified in code |
| App Builder projects, prompts, generated code | While project/account exists; residual copies purged within a proposed 30 days (pending owner confirmation + purge job) | Project deletion in product | Proposed |
| Studio projects, uploads, exports | While project/account exists; storage objects purged within a proposed 30 days of deletion (pending owner confirmation + purge job) | Project deletion in product | Proposed |
| Flow workflows | While account exists | Delete in product | Verified structure |
| Flow execution logs & webhook payloads | Proposed: 90 days (pending owner confirmation + purge job) | Automatic purge job to be implemented | Proposed |
| Flow audit logs | Default 365 days, then archived to Cloudflare R2; deletion after archive is configurable | Automatic job | Verified in code |
| Thuta Agent sessions, memory, tool-execution records (pre-release) | Not yet defined | Not yet defined | Pre-release; define before GA |
| Thuta IDE local data | On your device — you control it | Delete files / app data | Verified (local-first) |
| IDE device sign-in requests | 10 minutes (approval window), then auto-deleted by a daily sweep | Automatic | Verified in code |
| IDE sign-in tokens | On your device keychain until sign-out; server-side refresh token until revoked or 60 days | Sign out in IDE / revoke in Account Center → API Tokens; deleted with account | Verified in code |
| Web analytics (learn.thutatech.com, Vercel Web Analytics) | Aggregate statistics retained by Vercel per plan tier — proposed 12 months (plan tier to be confirmed); the per-visitor hash is discarded after 24 hours and IP addresses are not retained | Provider-managed; data is not attributable to an individual, so there is no per-user deletion path | Provider default |
| Support messages | Proposed: 2 years (pending owner confirmation) | Support request | Proposed |
| Backups | Managed-provider backups (database host, storage provider); schedules not yet confirmed | Rolling per provider | Owner confirmation required — no "35-day" claim is made |
RETN-03 — Account deletion — what happens
Deleting your account automatically removes your profile, subscription, wallets, reservations, credit ledger, usage events, API tokens, OAuth connections, and all Studio career records (implemented 2026-07-18). What remains: security audit logs (fraud-prevention/legal basis, per the period above) and payment transaction records held by PayPal under its own rules. For anything else, contact info@thutatech.com and we will process the request in accordance with the APPI.
RETN-04 — Legal holds
We retain data beyond the periods above where required for legal, tax, accounting, fraud-prevention, or dispute-resolution obligations, and delete or anonymize it when the obligation ends.
RETN-05 — Changes
Retention periods finalized by the owner and counsel will be published here with a version change, before public launch.