Data Retention Policy
Retention windows per data type, including the current implementation status for each category.
Last updated: August 30, 2026 This page is the canonical, plain-language answer to " how long does Sistava keep what? ". It supplements (and does not replace) Section 8 of our Privacy Policy , Section 12 of our Data Processing Agreement , and Section 18.A of our Terms of Service (Data Portability & Switching). The table shows both our maximum retention windows and the current implementation status for each category.
1. Honest Defaults, Transparent Practice
Sistava is an early-stage product. To improve the platform, optimize infrastructure, debug issues, investigate abuse, and understand how AI employees are used, we currently retain most operational and behavioral data for up to two (2) years by default. This is longer than some smaller vendors retain data, and we want you to know that up front rather than discover it later. We do not sell your data, we do not share it for advertising, we do not transfer it to data brokers, and we use it only to operate, secure, and improve the Services as described in our Privacy Policy. As we mature, we expect to shorten these windows; any future reduction will apply prospectively and will be announced on this page.
2. Categories & Retention Windows
The table below lists every category of customer data we process, the maximum retention window we apply today, what triggers deletion, and how that control is currently handled. Automatic means a scheduled cleaner is configured. Source-managed means a scoped infrastructure cleaner or underlying storage system enforces expiry. Manual means deletion follows a verified request or customer action. Planned means the maximum is published but the end to end control is not yet automated. Data outside the scope of these categories (for example, data we are legally required to retain for tax or accounting reasons, or data we are required to preserve for an active legal hold) is governed by Section 4 below.
- Data category — Retention — Status — Trigger / notes
3. How Deletion Actually Happens
Automatic categories are processed by a daily scheduled cleanup. Storage lifecycle categories are expired by the underlying storage system on their scoped object prefix. Each application category is handled independently and in bounded batches to avoid database lock contention. We record the configured policy, deletion counts, known storage measurements, and outcome for each retention cycle. Before a retention-window change is deployed, we run a dry run to verify what it would delete. When you exercise your right to erasure (GDPR Article 17) by emailing [email protected] , we verify and respond to the request subject to the legal-retention exceptions in Section 4 below. The account-erasure workflow is shown as Planned until its cross-system verification is live. Backup timing is shown separately in the table above.
4. When We Keep Data Longer
We may retain your data beyond the windows in the table above when:
- We are legally required to (for example, billing records for tax law, security logs for incident investigation, or data subject to a lawful preservation order).
- We are defending against an active or threatened legal claim, regulatory investigation, or dispute.
- The data has been flagged as related to abuse, fraud, security incidents, or violations of our Acceptable Use Policy, and we need it to enforce our policies, protect the platform, or protect other customers.
- You have an active subscription, an active workspace, or an active integration that depends on the data.
- The data has been fully anonymized and is no longer personal data under GDPR.
5. Your Controls
You can shorten retention for your own data at any time by:
- Deleting individual chat conversations from the workspace UI.
- Deleting AI employees, which removes their memory, notes, journal, and configuration after the 90-day terminated-employee window.
- Deleting files from your Drive.
- Requesting account deletion. The table shows the current implementation status for that workflow.
- Submitting a GDPR Article 17 erasure request to [email protected] .
- Exporting your data first under Section 18.A of the Terms of Service before deletion, if you want to keep a copy.
6. Reconciliation with Other Pages
We mention retention in several places on the website. This page is the canonical, binding reference for any disagreement. Specifically:
- The retention summary in our Data Security page summarizes these controls. This table is the binding source for each retention window and its implementation status.
- Section 8 of our Privacy Policy describes retention in legal prose. This page is the operational table that prose refers to.
- Section 12 of our Data Processing Agreement describes return-or-deletion obligations after termination of a customer agreement. Those obligations apply on top of the standard windows in this table.
- The pricing comparison table on our pricing page shows different retention windows per plan tier (currently advertised as 30 days / 90 days / 1 year / 2 years / Custom). Those tier-based retention controls represent a future product offering and have not been implemented in the backend yet. Today, retention is uniform across all plans according to the table in Section 2 above , and that is the legally binding reality. When tier-based retention controls ship, this page and the pricing page will be updated together.
7. Changes to This Schedule
We may change the retention windows in this Schedule at any time. Where a change reduces retention (we delete data sooner), the change applies prospectively to all data going forward and we will use commercially reasonable efforts to give advance notice. Where a change extends retention (we keep data longer), we will publish the change here before it takes effect and explain why.
8. Contact
For questions about retention, deletion requests, or any other data protection matter, contact [email protected] .