Data Retention and Deletion Policy

Exactly how long each kind of data lives on Leviro Toolbay, what happens to it when you close your account, and how to have yours deleted.

Effective

Principles

  • Content we do not need, we do not store. Files you send to a cloud tool are processed in memory and released when the request ends.
  • Files we generate for you are short-lived by design and are deleted automatically on a timer, not on request.
  • Records we must keep — the credit ledger, payment records, and the admin audit trail — are append-only, because they exist to be auditable.
  • Operational data expires on its own. Analytics, error reports, and quota counters carry database-level expiry rules, so nothing depends on someone remembering to clean up.
  • Nothing about your account is kept after you ask us to delete it, apart from the minimum financial records described below, and those are detached from your identity.

Retention at a glance

DataHow long we keep it
Content used by browser-only toolsNever leaves your device — we never receive it
Files uploaded to a cloud toolHeld in the server's memory for that one request; not written to long-term storage
Files uploaded to a queued tool (document translation)Stored until the job runs, then deleted — at most 30 minutes
Generated files you can download10 minutes from creation, then deleted automatically
PDF pipeline artifacts15 minutes by default (administrator-configurable between 5 and 60 minutes)
PDF cost quotes and processing leasesExpire automatically; leases last at most 30 minutes
Account profile (email, name, avatar, sign-in method)Until you ask us to delete your account
Password hashUntil you delete your account or change your password
Email verification and password-reset tokensSingle use; expire after 1 hour and are removed when used or reissued
Sessions (browser and platform name, truncated IP, last used)30 days, then removed automatically; also revoked on sign-out, on rotation, and on reuse detection
Access token cookie15 minutes
Credit ledger (grants, deductions, refunds, adjustments)Kept for accounting; anonymised rather than deleted when an account is closed
Payment orders and settlement recordsKept for accounting; anonymised rather than deleted when an account is closed
AI usage records (feature, model, tokens, cost, prompt version, outcome)Kept for cost reporting — never includes the content you submitted
Paid-run usage records (which feature, when, credits charged)Kept while your account exists
Weekly free-allowance counters60 days, then deleted automatically
Dynamic QR scan analytics (country, device, OS, browser, referrer)For your plan’s history window — 7 days on a free account, up to a year on a paid plan — then deleted automatically. Deleting the QR code removes them immediately.
Support and feedback messagesUntil the request is resolved and you ask us to remove it
Consented product analytics (content-free events and random session ID)90 days, then deleted automatically
Server error reports (redacted; no user content or secrets)90 days from the last occurrence, then deleted automatically
Admin audit trailAppend-only; retained as a security record
Database backups30 days, then pruned automatically

Uploaded files in more detail

When you use a cloud tool, your file arrives over HTTPS and is held in the server's memory for the duration of that one request. It is validated (size, declared type, and real file signature), processed, and released. We do not archive your original upload.

One kind of tool is different, and we would rather say so than let you assume otherwise. Document translation can take several minutes, which is longer than a browser will hold a connection open, so the work runs in a queue instead: your document is written to disk under a random name, waits its turn, and is deleted as soon as the translation finishes — normally within seconds of it completing, and never more than 30 minutes even if the job fails. Nothing serves that directory to the internet. The job record that tracks its progress keeps the name of your file and any glossary you supplied, so the finished translation can be named after the original — and it expires on the same clock as everything else in it. This is the only tool that works this way today; if another one joins it, this page will say so.

The result is different: some tools have to write an output file so your browser can download it. Those files get random, unguessable names and are deleted on a timer — 10 minutes for the general tools, 15 minutes by default for the PDF pipeline. Download your result before then; once it expires it is gone and cannot be recovered. The random name is how the file is stored, not what you see: your browser saves it under a readable name built from the one you gave us, so a translated contract is still recognisably your contract.

Deletion does not depend on a single timer surviving. A sweep runs every minute and removes anything past its window based on the file's age on disk, so a restart or a crash cannot leave a file behind indefinitely, and the PDF pipeline sweeps expired artifacts on startup for the same reason.

What "anonymised rather than deleted" means

Financial records have to stay consistent even after an account is closed, otherwise balances stop reconciling and we cannot answer questions about past payments — including from a payment provider or a tax authority. So when we delete an account, we remove the identifying data (email, name, avatar, sign-in identifiers) and keep the ledger and payment rows detached from any person.

What is left is an amount, a date, a reason, and a reference. It is no longer linked to you and cannot be used to identify you.

Backups

We take a nightly database backup and keep backups for 30 days. A backup is a snapshot of the database as it was that night, so data you asked us to delete can survive in an older snapshot until that snapshot expires.

We do not restore a backup in order to recover deleted personal data. If a backup ever has to be restored after a failure, we re-apply outstanding deletion requests to the restored database.

Asking us to delete your data

There is no self-service delete button yet. Email [email protected] from the address on the account, or use the contact page, and we will delete the account and its personal data. We aim to complete deletion within 30 days and will confirm when it is done. We may ask you to confirm the request from the account email address before acting on it.

You can also ask us to delete something narrower — a support thread, a dynamic QR code and its scan history, or your referral attribution — without closing the account.

Deleting your account does not refund an unused credit balance. If you want a refund, read the Refund Policy and ask for it before you ask us to close the account.

Changes

Retention windows can change as the product changes. This page is the authoritative list, and its effective date moves whenever a window does.

Other policies