Retention

How long we keep data, and why.

This schedule explains how Qytherion AI retains, archives, anonymizes, and deletes workspace records across Qytherion AI, Qytherion AI Call Center, and related Twilio-connected workflows.

Quick look

  • Active and free-tier access. Workspace data stays available while your account is active, including on the standard free tier after paid cancellation or payment failure.
  • No default wipe on cancel. Subscription cancellation or payment failure does not unilaterally destroy chat history, configurations, or logs—only verified deletion requests do.
  • Compliance exceptions. Certain legal, tax, and telecom records may be retained longer when required by law or provider obligations.
  • Deletion requests. Verified requests are acknowledged quickly and processed on a documented timeline.

1. Retention Schedule

Retention by record type

Different datasets serve different operational and legal purposes, so they follow different retention windows.

Workspace configuration and content. Chat history, specialist library entries, prompts, dashboard configurations, and workflow assets are retained while the account remains active—including on the rate-limited free tier after paid cancellation or payment failure—unless a verified deletion request is processed.

Qytherion AI Call Center campaign data. Lead queues, routing state, call outcomes, and messaging status records are retained during active use and while the account or campaign remains accessible; closure or plan downgrade may rate-limit outbound capabilities without deleting historical records unless a verified deletion request or legal hold applies.

Consent and communication evidence. Consent receipts, opt-in source metadata, opt-out logs, and delivery/call attempt evidence may be retained up to 24 months (or longer if required by law, carrier policy, or dispute handling).

Operational telemetry and diagnostics. System logs, trace events, and service reliability metrics are retained up to 12 months for security and performance troubleshooting, then deleted or anonymized.

Security and fraud signals. Access logs, authentication events, and abuse-detection artifacts may be retained up to 24 months where necessary for account protection, incident response, and documented cooperation with network operators on confirmed abuse.

Billing and tax records. Invoices, payment events, and tax-related records may be retained for the period required by financial, accounting, and legal obligations.

Support and account communications. Support tickets, implementation notes, and service correspondence are typically retained up to 12 months after closure unless earlier deletion is approved and permitted.

2. Lifecycle States

Active, archive, anonymize, delete

Records move through defined stages to balance portability, recovery, and compliance.

Active state. Data is accessible to authorized users and used to deliver live platform functionality.

Free-tier state. After paid cancellation or payment failure, workspace records remain on the account under a standard, rate-limited free tier rather than being moved to destructive offboarding archive.

Anonymized state. Where feasible, analytics data is de-identified and retained only in aggregate form for trend analysis and reliability tuning.

Deleted state. Records are removed from production systems and then age out of backups according to backup retention schedules.

Legal hold state. Deletion may be paused for records subject to legal claims, regulatory inquiry, fraud review, or active contractual obligations.

3. Deletion & Export Requests

How to request erasure, export, or urgent purge

Workspace owners and authorized admins can initiate lifecycle requests.

Standard deletion request. Submit via account support channel or email [email protected]. We target acknowledgement within 1 business day and processing within 5 business days for eligible records.

Accelerated purge request. For incidents, M&A events, or urgent legal needs, mark the request urgent. We may temporarily freeze automations, revoke tokens, and prioritize data removal sequencing.

Export request. Export packages may be delivered as encrypted ZIP/JSON/CSV bundles with schema notes for migration and audit continuity.

Identity verification. To protect customer data, we verify requester authority through account records and a secondary confirmation channel before actioning high-risk requests.

Completion evidence. Upon request, we can provide a written deletion or export completion summary with timestamped workflow notes.

Scope limits. Some records cannot be immediately erased where retention is required for billing integrity, anti-fraud controls, legal obligations, or ongoing disputes.

4. Backups & Resilience

How backup copies are handled

Backups protect service continuity but are still governed by retention controls.

Encrypted backups. Critical data stores are backed up on scheduled intervals with encryption at rest and in transit.

Backup retention window. Backup copies generally persist up to 30 days, after which they are rotated out, unless a legal hold or incident recovery process requires temporary extension.

Delayed deletion in backups. Deletion from production environments may not appear instantly in immutable or rotating backups; final removal occurs as backup cycles expire.

Access controls. Backup access is restricted to authorized personnel under confidentiality obligations, with access logging and periodic review.

5. Regional Storage & Subprocessors

Data location expectations

Infrastructure and subprocessors may vary by workload, failover, and customer requirements.

Primary regions. Primary hosting is typically US-based, with failover and provider-managed redundancy that may involve additional regions.

Telecom provider flows. Call and messaging metadata may be processed by downstream providers (such as Twilio and carriers) under their own compliance requirements.

Regional pinning. Where technically feasible and contractually supported, region preferences can be evaluated for enterprise workspaces.

Cross-border responsibility. Customers are responsible for ensuring their campaign and data transfer practices meet applicable jurisdictional requirements.

6. Governance

Policy precedence and updates

This schedule works alongside our broader legal and compliance framework.

Related policies. This document should be read with our Privacy Policy, Terms of Service, Acceptable Use Policy, and Proof of Consent process.

Conflict handling. If a signed enterprise agreement specifies different retention terms, that signed agreement governs for the covered customer.

Policy changes. We may update retention schedules to reflect legal, security, or provider changes. Updated versions are published on this page.

Questions. For retention clarifications or data lifecycle requests, contact [email protected].