This page describes how long we retain different categories of data, why, and how data is removed when retention expires. It supplements Section 7 of our Privacy Policy, which has a high-level summary.
We are honest about what's automated versus what requires manual operation today. As the service grows, we will automate more enforcement; this page will be updated when that happens.
User-deletable data: kept while you use the service, removed shortly after you delete it.
| Category | What it includes | Retention | Basis | Deletion mechanism |
|---|---|---|---|---|
| Account profile | Name, email, profile fields, settings | While the account exists; deleted with the account | Service provision | Account deletion (below) |
| Inactive free accounts | The whole account: workspaces, templates, cases, files, credentials | Deleted 180 days after the last sign-in by anyone in the organization, after three warning emails (30 days, 10 days, and 1 day before) and a 30-day recovery period in which any sign-in cancels the deletion. Paying accounts are never deleted for inactivity. | Data minimization; storage cost | Automated nightly sweep |
| Workspace settings | Workspace name, mailboxes, automations, send templates, document sources | While workspace exists; 30 days after workspace or account deletion | Service provision | Manual quarterly sweep |
| Cases + documents | All case data, file uploads, extracted values, activity timeline | While the case exists; 30 days after case, workspace, or account deletion | Service provision | Manual quarterly sweep |
| Email body capture | Body text from automation-ingested emails (only when explicitly enabled per automation) | Until the case is deleted | User opt-in per automation | Auto-cleanup on case delete |
Records we retain to demonstrate compliance and meet legal obligations. The rows below say which of them survive a deletion request.
| Category | What it includes | Retention | Basis | Deletion mechanism |
|---|---|---|---|---|
| Sensitive-data audit log | A per-account collection for sensitive-field read, write, and decryption events. Nothing writes to it today, no IP address or user agent is recorded for these events, and the app has no screen or export that reads it back | Not retained for a fixed period. Deleted with the account | None today. Would be statute of limitations on privacy claims once events are recorded | Deleted by the account purge along with every other account subcollection. No separate pruning |
| Legal acceptance records | Terms of Service, Privacy Policy, Cookie Policy, and DPA acceptance events with signer info, IP, timestamp | 7 years | Demonstrating contract formation in disputes | Not currently auto-pruned |
| Document e-signature records | Portal "Review & Sign" signing events: signer identity, consent record, IP, user agent, intent timestamps, and tamper-evident document hashes | 7 years | Demonstrating signature validity in disputes | Not currently auto-pruned |
| Billing records | Subscription state, invoices, payment events, plan history | 7 years | Tax and accounting obligations; fraud prevention | Stripe retains independently; we mirror what we need |
| Stripe webhook event log | Idempotency dedup records to prevent duplicate event processing | 90 days | Webhook deduplication; debugging | Not currently auto-pruned (small volume) |
Tokens and identifiers used to keep you signed in and authorize integrations.
| Category | What it includes | Retention | Basis | Deletion mechanism |
|---|---|---|---|---|
Session cookies (session) | Firebase Auth session cookie | 5 days | Authentication user experience | Auto-expires |
| OAuth tokens (Drive, Gmail, Calendar) | Encrypted access and refresh tokens for user-granted integrations | While the connection is active; deleted on revoke or account deletion | Required for the OAuth-gated feature | Auto-clear on revoke; manual cascade on account delete |
Cookie consent (_legal_consent) | Your cookie banner choice (necessary, analytics, experiments, marketing) | 1 year | Demonstrating consent | Auto-expires; user can update at any time at /legal/preferences |
| Analytics events (GA4 + BigQuery export) | Anonymous usage events; authenticated events carry the account's user id | 14 months (425-day table expiration on the BigQuery dataset; GA4 retention set to 14 months) | Legitimate interest in product analytics | Automatic table expiration; per-user erasure on data subject request |
Data sent to Google's Gemini API for document extraction and template fill features.
| Category | What it includes | Retention | Basis | Deletion mechanism |
|---|---|---|---|---|
| Gemini API requests | Prompts (PDF text, image data, case data) and extracted values, sent to Google | Not used for model training. Google logs prompts and responses for a limited period for abuse monitoring under its published terms. Document Blueprint does not store separate copies of prompts. | Per Google's published Gemini API terms | Google-managed |
Logs maintained by Google Cloud for operational debugging, plus the first-party product event records described below. Apart from those two, Document Blueprint does not keep separate application-level logs of your activity.
| Category | What it includes | Retention | Basis | Deletion mechanism |
|---|---|---|---|---|
| Cloud Logging (Firebase + Cloud Functions) | Server-side request logs, error logs, and client crash reports. A crash report includes your user id (when signed in) and, if you have allowed analytics cookies, a short trail of your last interface actions before the crash (control labels and page paths, never document content), so we can reproduce the error | 30 days (Google default) | Operational debugging | Auto-prune by Google Cloud |
| Firebase Auth audit logs | Login events, account creation events | 30 days | Operational debugging; fraud detection | Auto-prune by Google |
| reCAPTCHA Enterprise risk scores | Per-request attestation scores produced by Firebase App Check, which verifies traffic comes from our genuine app | Not retained by us beyond the verification request | Abuse prevention | N/A (Google manages on their side) |
Records of emails sent or received in connection with the service.
| Category | What it includes | Retention | Basis | Deletion mechanism |
|---|---|---|---|---|
| SendGrid transactional email logs | Delivery and bounce records for invitations, billing notices | 30 days (SendGrid default) | Deliverability debugging | Auto-prune by SendGrid |
| privacy@ inbox + support email | DSR requests, privacy inquiries, support threads | Until resolution + 3 years (statute of limitations on privacy claims) | DSR compliance and audit trail | Manual (per DSR runbook) |
Disaster-recovery snapshots maintained by our cloud infrastructure.
| Category | What it includes | Retention | Basis | Deletion mechanism |
|---|---|---|---|---|
| Firestore version retention | Prior document versions, readable at a past timestamp but not exportable | 1 hour (Firestore default; Point-in-Time Recovery is not enabled) | Recent-state recovery | Auto-managed by Google |
| Cloud Storage object versions | Older versions of uploaded files | No version-retention rule is configured. The committed lifecycle rules only move objects to cheaper storage classes at 30 and 90 days | Not relied on for recovery | N/A |
| Manual exports | Ad-hoc backups (none currently scheduled) | N/A | N/A | N/A |
We are honest about which retention windows are auto-enforced and which require manual operation today:
A record of each automated account deletion (email address, date, counts) is kept for 7 years with the other legal records in section 2.
We may update this retention schedule from time to time. We will provide at least 30 days' written notice (by email or by updating this page) before changing a retention period in a way that materially affects how long your data is kept.
For privacy or retention questions: privacy@documentblueprint.com.