DATA LIFECYCLE

Retention Policy

The current controlled-beta retention rules for accounts, receipts, and captured artifacts.

Effective and last updated: August 13, 2026

Published source-custody periods

New captured artifact bytes receive an explicit expiry at creation: Free 30 days, Builder 365 days, Pro 1,095 days, and Scale 2,555 days. Expired bytes are deleted automatically during API activity and cannot be downloaded afterward. Existing beta artifacts created before this policy receive a one-year transition period from their original capture date.

Account and billing records

Profile and workspace data are kept while the account is active. Stripe customer and subscription identifiers, invoices, transaction records, security logs, and support correspondence may be kept longer when needed for tax, fraud prevention, dispute resolution, security, or legal obligations.

Export and deletion

Account owners can export account and receipt JSON or delete their account from Dashboard → Settings → Data. Active Stripe subscriptions must be cancelled first. Deleting Elucora’s stored copy cannot recall a portable receipt or transparency hash already exported, cached, or shared by a customer or third party.

Artifact availability

A receipt signature can remain cryptographically valid even if the preserved artifact is later deleted or unavailable. Applications that require long-term independent evidence should download the owner-only artifact, verify its SHA-256 hash, and retain it under their own policy.

Contractual retention

Self-serve custody periods are product behavior, not a negotiated retention SLA. Customers needing legal hold, custom deletion schedules, a DPA, or contractual remedies must complete an enterprise agreement before relying on Elucora for regulated records.