Data Retention Policy
Retention policies are usually written aspirationally. This one describes what the software actually does. The short version: VERA keeps your data for as long as your account exists and does very little automatic deletion, because a business tool that quietly deletes last year's invoices is a worse product. Deleting your account is what removes your data, and that deletion is immediate and thorough.
- Version
- 1.1
- Effective
- August 12, 2026
- Last updated
- August 12, 2026
- Revisions
- 2
On this page (5 sections)
1. Principles
Data is retained for as long as it is needed for the purpose it was collected for, plus any period the law requires. For an operational business tool, that period is normally the life of the account: your estimates, invoices, customer records, and audit history are records you need to be able to look back at.
Deletion in VERA means removal from the live database. It is not a soft-delete flag, and there is no recycle bin from which an account can be restored.
2. Retention by category
The table below states the actual behavior of the system today.
| Data | Retention | How it ends |
|---|---|---|
| Account, business profile, brand kit | Life of the account | Deleted when you delete your account |
| Customer and operational records (leads, contacts, companies, deals, jobs, appointments, technicians, support tickets) | Life of the account | Delete individual records in the app, or all of them by deleting the account |
| Estimates, invoices, imported documents and their original file copies | Life of the account | Delete individually in the app, or by deleting the account |
| Uploaded photographs, logos, and generated images | Life of the account | Delete in the app, or by deleting the account |
| Content drafts, proposals, and generated content | Life of the account | Delete in the app, or by deleting the account |
| Audit trail and security events | Life of the account. Append-only; never edited or deleted in ordinary operation | Removed with the account |
| Raw location readings from mileage recording | 30 days by default. The account holder can shorten or extend this, or set it to zero so readings are never stored | Pruned automatically by a scheduled sweep. The trip they measured survives; the breadcrumbs behind it do not |
| Mileage trips, vehicles, and reimbursement records | Life of the account. A trip that has been submitted is voided rather than deleted, so the money trail survives. Voided trips are pruned after the account's trip retention window, which cannot be set below one year. Approved and reimbursed trips are never automatically removed | Delete an unsubmitted draft in the app, or remove everything by deleting the account |
| Geocoding and routing cache | 30 days for addresses, 7 days for routes | Expires automatically. Keyed by a hash of the normalized request and holds no account identifier, so it is not swept by account deletion and cannot be traced back to a person |
| Text message conversations, MMS media, and consent records | Life of the account | Deleted with the account, consent and opt-out records included. Export before deleting if you need the record for your own compliance file |
| Social posts, their media, and the publishing queue | Life of the account | Deleted with the account, which also stops anything still queued from being published. Content already published to a platform stays on that platform under its own retention |
| Receipts, mileage proof images, and other uploaded files | Life of the record they belong to | Deleted when you delete the record, and with the account |
| Voice conversations | The transcript is kept with its conversation for the life of the account. No audio recording is created or kept at any point | Deleted with the conversation, or with the account |
| Industry Radar news articles | 30 days | Pruned automatically on each scan |
| Connector credentials (OAuth tokens, API keys) | Until you disconnect the integration | Removed on disconnect, and on account deletion |
| Session tokens | Until expiry, sign-out, or revocation | Revoked immediately by password reset, sign out of all devices, or suspension |
| Email verification and password reset tokens | 24 hours and 1 hour respectively, single use | Expire or are consumed; cleared on account deletion |
| OAuth flow state cookies | 10 minutes | Expire in the browser |
| Rate-limit counters | One fixed window per key, overwritten when the window resets | Overwritten in place. Rows may persist keyed to an email address or IP address until the next attempt from that key |
| Webhook delivery ids (replay protection) | Retained as a small provider and event-id record | Not user-scoped; not removed by account deletion |
| Platform admin audit log | Retained after the affected account is removed, by design | Kept as an operator accountability record |
| Stripe billing records | Held by Stripe under its own retention and financial record obligations | Governed by Stripe, not by VERA |
| Server and error logs | Retained by the hosting provider under its default log retention | Rotated by the provider |
3. What VERA does not delete automatically
Scheduled deletion is deliberately narrow. It runs against raw location readings, voided mileage trips past their window, the routing cache, Industry Radar articles, and the short-lived tokens above. Everything else stays until you remove it: a business tool that quietly deletes last year's invoices is a worse product. If you want something gone, delete it in the app or delete the account.
Where a retention period is configurable, it is configurable by the account holder rather than by us, and the setting applies going forward. Changing it does not restore data a previous setting already removed.
Some plan descriptions refer to a task history window of 30 days, 6 months, or 12 months by tier. Treat those as descriptions of the history the interface is designed to surface, not as a deletion schedule; VERA does not currently purge history when a window elapses.
4. Backups
VERA does not operate its own backup tooling. Durability and point-in-time recovery depend on the managed database provider hosting the deployment, under that provider's capabilities and retention.
This means we cannot promise that deleted data is purged from every provider-held backup snapshot immediately. It is removed from the live database at once and would age out of provider snapshots on the provider's cycle. We also cannot restore an account you deleted, even from a backup.
5. Data you hold as a controller
For personal data about your own customers, you decide the retention period; VERA retains it for as long as you keep it in the account. If your own retention policy is shorter than the life of your VERA account, delete those records in the app when their period ends. VERA does not enforce a retention schedule on your behalf.
Change history
Every revision of this document, newest first. Material changes are notified to account holders before they take effect where practicable.
- v1.1August 12, 2026
Added retention rows for raw location readings, mileage trips and vehicles, the geocoding cache, messaging and consent records, social posts and their queue, uploaded receipts and proof images, and voice transcripts. Corrected the claim that Industry Radar was the only scheduled prune.
- v1.0July 28, 2026
Initial Data Retention Policy published.
Questions about this document?
Legal and contracts: support@myvera.io. Privacy and data rights: support@myvera.io. Security reports: support@myvera.io.
Related
- Privacy Policy
- Cookie Policy
- SMS Opt-In Policy
- GDPR Rights
- California Notice
- DPA
- Subprocessors
- Account Deletion
This document is a carefully drafted policy written against how VERA actually works. It is not legal advice, and it should be reviewed by a licensed attorney in your jurisdiction before you rely on it.
