Legal Center

Data Retention and Account Deletion Policy

How long Projments keeps each kind of data, what deletes it, how to close an account, and what survives deletion because the law requires it.

Effective
16 August 2026
Last updated
16 August 2026
Version
1.0

In short

  • Work content stays until you delete it or close the account — we do not expire your projects behind your back.
  • Ask us to delete your account and we complete it within 30 days, including files in object storage.
  • Invoices and a minimal record of the account survive deletion, because tax and accounting law requires them.

This summary is for orientation only. The sections below are the document that applies.

1. The principles we apply#

  • We keep personal data only as long as it serves the purpose it was collected for, or as long as the law requires.
  • Work content belongs to the workspace that created it and is kept until that workspace deletes it. We do not impose a silent expiry on customer data.
  • Data that is inherently sensitive — screenshots above all — is kept for the shortest period that still makes the feature useful.
  • When we delete, we delete from the database and from object storage, not only from the interface.

2. Retention schedule#

DataHow long we keep itWhat deletes it
Account and profile — name, email, password hash, avatar, settingsFor the life of the accountAccount deletion (§4); removed within 30 days of the request
Workspace content — projects, tasks, submissions, checklists, clients, contracts, expenses, salesUntil deleted by the workspaceDeleting the item, the project, the workspace, or the owning account
Files, sheets and drawings in object storageUntil deleted by the workspaceDeleting the file or its parent; deleting the workspace; account deletion. An unpaid or cancelled subscription does not delete them — see §5
Time entries and sessionsFor the life of the workspace — these are business records your organisation relies on for payroll and invoicingDeleting the project or workspace; account deletion
Screenshots and activity samplesGoverned by the retention period your workspace sets in Settings → Snapshots (default 30 days)Deleting the time session, the project or the account they belong to; and on request from the workspace owner — see the note below
Chat messages, room posts and attachmentsUntil deleted by the sender, an administrator, or with the workspaceMessage deletion; workspace deletion; account deletion
Call records — who, when, how longFor the life of the workspace. Audio and video are never recordedWorkspace deletion; account deletion
3D room scans and their thumbnailsUntil deleted by the account that owns them. Scans survive deletion of a workspace, because they belong to the person who captured themDeleting the scan; account deletion
Notifications and device push tokensNotifications until dismissed or superseded; tokens until the device unregisters or signs outSign-out, uninstall, account deletion
Billing and invoice recordsThe period tax and accounting law requires — commonly 5 to 10 years, depending on jurisdictionExpiry of the statutory period. These records SURVIVE account deletion
Support requests and their messagesUp to 24 months after the request is closedAutomatic expiry, or earlier on request where no dispute is open
Audit records of administrative actionsUp to 24 months, as evidence in abuse and security investigationsAutomatic expiry
Password reset tokensMinutes — they are single-use and short-lived, and stored only as a hashUse or expiry
Rate-limit countersMinutes to hoursA scheduled sweep clears expired windows
Server and diagnostic logsUp to 90 daysAutomatic rotation
BackupsRolling, up to 30 daysDeleted data disappears from backups as the rotation passes it. We do not restore a backup to recover data you asked us to delete

3. Getting your data out#

Export before you delete — deletion is not reversible.

  • Reports export to Excel and PDF from the Reports section, including time, tasks, expenses and sales.
  • Files and sheets download individually from the workspace.
  • Room scans export as a plan bundle from the scanner library.
  • If you want everything at once, ask for a full export in our Support Center and we will provide it in a machine-readable format within 30 days.

4. Closing your account#

To close an account, raise a request in our Support Center from the account you want deleted, and say clearly that deletion is what you are asking for. Raising it from the account is how we verify that the request comes from the account holder — we will not delete someone’s work because a stranger knows their email address.

What happens then

  1. We confirm the request and tell you what will be lost, including any workspaces you own and the data of members in them.
  2. Cancel any active subscription first, or ask us to cancel it — deletion does not by itself stop a Stripe subscription, and a live subscription would keep billing an account that no longer exists.
  3. You get a window of at least 7 days to export, unless you ask us to proceed immediately.
  4. We then delete the account and its data from the database and from object storage, and the deletion completes within 30 days of your request.
  5. Sessions are revoked at once: any device still signed in is signed out the next time it contacts the server.

What is deleted

  • Your profile, credentials, settings and sessions.
  • Your time entries, sessions, screenshots and activity records.
  • Your device tokens, notifications and personal preferences.
  • Room scans you own, with their thumbnails and previews.
  • Workspaces you own and the content in them, including other members’ content in those workspaces.

What survives, and why

  • Invoices and payment records — retained for the statutory tax and accounting period. They name you and the amounts; we cannot lawfully delete them on request.
  • Audit and security records of administrative actions, kept for their retention period as evidence in investigations.
  • Content in workspaces you do not own — messages you sent, tasks you completed, time you logged for someone else’s organisation. That is their business record, held under their lawful basis, and it is theirs to delete. We anonymise your personal identifiers where we can do so without destroying the record’s meaning; ask that workspace’s owner for anything further.
  • Backups, until the rotation described above passes.

5. Suspension, downgrade and inactivity#

  • A suspended account cannot sign in, but its data is retained while the suspension is resolved.
  • Downgrading to the Free plan does not delete data. What it does is enforce Free-plan limits — features stop, and storage above the allowance can no longer grow.
  • A subscription that ends — cancelled, or unpaid after a failed renewal — does exactly the same thing. The account is locked to the Free plan and every project, task, expense, sale, time record and file it holds stays where it is. Pay again and all of it returns, untouched, with nothing to restore.
  • Nothing is deleted on a timer for non-payment. If a long-expired account is holding a large amount of storage we may eventually remove it, but only as a deliberate decision taken by an administrator and recorded, never automatically. Write to us and we will tell you what we hold.
  • We do not currently delete accounts for inactivity. If we ever introduce an inactivity policy, we will give at least 60 days’ notice by email before it applies to you.

6. Requests from team members#

If you are a member of someone else’s workspace and want your screenshots, time records or messages deleted, that decision belongs to the workspace owner: it is their record, kept under their lawful basis, and we process it on their instructions. Ask them first. Write to us if they do not respond and we will pass the request on, tell you what we hold, and delete anything we hold as controller — your account, credentials, sessions and preferences — which we can always do.

7. Contact#

Deletion and export requests, and general help: our Support Center. See also the Privacy Policy and the Terms of Service. This version is 1.0, effective 16 August 2026.

Other documents