Draft · Pending legal review · 2026-09-10. This page is a working draft published for transparency; it is not yet a signed agreement. Where it conflicts with a signed service agreement, the signed agreement prevails.
Data Retention
Draft dated September 10, 2026
This page forms part of the Data Processing Agreement. It lists every category of data the Canlah console and AI staff platform holds for you, how long we keep it, how it is deleted, and whether a backup exists. Periods marked "[To be confirmed]" are not yet enforced automatically and are pending a decision.
1. Retention by data category
"You delete" means a control in the console; "on request" means an email to privacy@canlah.ai actioned by the CANLAH AI team.
| Data | Kept for | How it is deleted |
|---|---|---|
| Account (name, email, sign-in providers) | Life of the account; 30 days after termination | On request. Self-service account deletion is not yet available [To be confirmed] |
| Signed-in sessions | 30 days from last activity (refreshed daily while in use) | Expire automatically; you can sign out any device under Account → Signed-in devices |
| Passkeys | Until you delete them | You delete, under Account → Passkeys |
| AI staff container and persistent volume (workspace, memory, skills, output files, channel configuration) | Until the staff member is deleted | On request, executed by CANLAH AI operations (see Section 2). Immediate and irreversible |
| Staff record in the console (name, persona, model, approval mode) | Until the staff member is deleted | Removed with the staff member. An assignment record marked "deleted" and a "bot.deleted" event are kept as an audit trail [retention period to be confirmed] |
| Chat history with AI staff (console conversations) | Until you delete the conversation | You delete, per conversation, in the console. Not removed automatically when the staff member is deleted [To be confirmed whether it should be] |
| Brand profile, facts, intent ledger, plans and plan cards, approval records | Life of the account; 30 days after termination | On request |
| Brand documents and delivered reports (R2 objects) | Until you delete the document | You delete in the console: the database row and the stored file are removed together |
| Social account connections | Until you disconnect | You disconnect under Account → Social accounts; this revokes our publishing access. The platform token held by PostForMe is [To be confirmed] deleted at the same time |
| GA4 / Search Console authorisation (encrypted refresh token) | Until you revoke | You revoke from your Google Account or on request; further access stops immediately |
| Audit leads on canlah.ai (email, role, industry, audited URL, score, booking) | 90 days from last interaction, unless you are a customer (Privacy Policy, Section 8) | Scheduled purge is not yet automated; currently deleted on request [To be confirmed] |
| Quick website audit results | Not persisted server-side beyond the request [To be confirmed] | — |
| Deep website audit HTML / PDF | 7 days (storage lifecycle rule) | Automatic. The score summary stays with your brand audit history for the life of the account |
| Operational logs (Cloudflare Workers observability, AI staff container logs) | [To be confirmed] | Automatic rotation by the provider |
2. What happens when an AI staff member is deleted
Since 8 September 2026 the console has no delete button: a staff member is deleted only by CANLAH AI operations, on your request, because the action is irreversible. The deletion runs in this order, and the record is only removed once the resources are gone:
- •The staff member's container is stopped and removed together with its persistent volume — workspace, memory, generated files and channel configuration. [To be confirmed: whether the hosting layer deletes the volume immediately or after a grace period.]
- •Its channel credentials and runtime secrets are deleted, its per-bot API keys are revoked, and its inter-agent identity token is revoked.
- •Its entries in the staff registry and provisioning ledger are removed, so the same slot cannot be silently reused.
- •Its record in the console is deleted; the assignment record is marked "deleted" and a "bot.deleted" event is written with the operator's identity.
What is not deleted: your chat history with that staff member, your brand profile and documents, plans and plan cards, and reports already delivered. These belong to the brand, not to the staff member, and remain until you delete them or the account ends.
There is no backup of the staff member's volume. If you ask for the same role again, a fresh staff member is provisioned from the current brand profile; its previous memory is not restored.
3. Backups
Console and lead databases (Cloudflare D1): Cloudflare keeps a point-in-time history ("Time Travel") that allows the whole database to be restored to any minute within the last 30 days [To be confirmed for our plan]. This means a deleted row may remain recoverable by Cloudflare for up to 30 days after deletion; we do not use it to restore individual customer data.
Brand documents and reports (Cloudflare R2): relies on the provider's built-in durability; no separate backup copy is kept.
AI staff volumes (Google Compute Engine host): no snapshot or backup is configured. Deletion is final.
Deep audit artefacts (Google Cloud Storage): none; objects expire after 7 days.
4. Deleting your whole account
Email privacy@canlah.ai from your account address. We stop all AI staff, delete them as described in Section 2, delete your brand data and console records, and confirm in writing. We aim to complete this within 30 days. Records we are required to keep by law (for example invoices) are retained for the statutory period only.
5. Contact
Data requests: privacy@canlah.ai. General enquiries: admin@canlah.ai.