Found in 275 of 352 platforms tracked (78% adoption) · 1630 provisions
This clause establishes ADP's post-termination data handling obligations, ensuring that data is either returned or securely destroyed rather than retained indefinitely, subject to EEA legal requireme…
This clause limits ADP's data retention to what is necessary for specified purposes, constraining indefinite or open-ended storage of personal data.
There is no fixed retention period; data persists indefinitely unless AI21 Labs acts on its own or a valid deletion request is submitted, placing the burden of data removal partly on the user.
Closing an account does not guarantee deletion of all associated personal data, as Acorns retains authority to keep certain information under legal requirements or permissions.
If Contact Data is lost within the Services, users have no recourse to ActiveCampaign as a backup source, because users bear sole responsibility for independent backup.
Deletion is tied to specific triggering actions by the user, and is limited to data processed under two specific legal bases: contract performance and consent.
Account closure does not end Adobe's retention of personal information tied to contracts or business transactions; that data persists for a fixed ten-year period measured from last interaction.
Users have a defined and limited window to retrieve or migrate their Content after their license ends; after 30 days, Adobe may permanently delete it.
A deletion request does not guarantee erasure; Adyen can override it on grounds of legitimate business purposes or legal compliance, limiting the practical effect of the deletion right.
American Airlines has committed to a defined maximum retention period for biometric data, tied to purpose fulfillment or a three-year outer limit, which is consequential given the sensitivity and irr…
American Airlines may hold personal data for up to seven years after a customer relationship ends, which is a substantial retention window affecting how long your information remains in American Airl…
Customers have no right to continued storage of their data after termination, and Amplitude may permanently delete it without any obligation to notify or preserve it.
The handling of physical DNA material—storage versus destruction—is determined by a one-time selection made at registration, with no indication of a later opt-in or opt-out mechanism in this excerpt.
The clause establishes a defined, time-bound obligation on Ancestry to delete Genetic Information from every named system category upon request.
Physical biological material may be stored by Ancestry on an ongoing basis, subject to a separate consent decision by the user.
Ancestry holds account and profile Personal Information indefinitely unless the user takes the affirmative step of deleting their account.
The clause establishes that Apple has neither storage nor access to data processed through Private Cloud Compute, defining a hard boundary on Apple's data access.
A design mandate that user data must not be retained after processing eliminates persistent storage as a vector for data exposure or subsequent misuse.
Atlassian's obligation to maintain a security program creates an ongoing contractual duty of data protection, giving the customer a basis to expect and enforce security standards over the life of the…
The retrieval window is fixed at twenty days; content not retrieved within that period may become inaccessible, making the deadline operationally significant.
Non-US users face a shorter inactivity threshold than US users before account deletion may occur, resulting in earlier potential loss of account and data.
US users' accounts and associated data are subject to permanent deletion after a defined inactivity period, with no indication of recovery.
The clause is consequential because it establishes that customer data cannot be deleted within three years, limiting any practical effect of deletion requests during that period.
Retention is governed by two independent bases—Privacy Policy purposes and legal or regulatory obligations—meaning data may be retained beyond a user's relationship with Binance.US if either basis re…
Account deletion or termination does not result in immediate erasure of personal data; Bluesky retains it for defined purposes under its Privacy Policy.
This clause limits Bluesky's own data holdings of sensitive biometric information, meaning Bluesky itself does not build a store of such data from the verification process.
Failure to act within the 14-day window eliminates Box's obligation to preserve Content and may result in permanent loss of that Content.
Retention is not time-limited by a fixed period; it continues as long as Brex determines any of the stated purposes apply, including open-ended legal and enforcement grounds.
Deletion is contingent on necessity, meaning Cerebras retains logs for as long as it determines they are necessary to provide services, without a fixed time limit.
This establishes that content you submit to and receive from Cerebras's core AI services is not retained, which is a significant data minimization commitment.
Zero data retention approval eliminates the logging of prompt and generation data entirely, providing a higher level of data privacy than the default 30-day retention policy.
The 30-day retention period defines how long Enterprise User data remains on the Platform, subject to the qualifier 'generally,' which signals exceptions may exist.
Legal obligations or contractual requirements can override the default 30-day deletion schedule, meaning data may be retained for an unspecified longer period without user control.
Users who believe that deleting their account erases their data would be mistaken; the clause makes clear that prompt and generation data persists on Cohere's systems for up to 30 days after account …
The 30-day deletion default is qualified by three exceptions, meaning data may be retained indefinitely in circumstances that users may not control or be aware of.
Custom Models built during the Agreement will not be retained or returned after termination or expiration, resulting in their permanent loss.
Retention is tied to multiple independent bases, meaning data may be kept beyond the life of the user relationship if legal obligations or protective interests require it.
The clause establishes a hard maximum retention period of two years for biometric facial data, a particularly sensitive category of personal data.
The existence of ZDR agreements with all providers establishes a contractual constraint preventing model providers from retaining or training on user data.
This establishes an explicit exception to ZDR commitments: abuse-triggered data may be retained by model providers or Cursor outside the standard zero-retention framework.
Audio data, which can be highly sensitive, is not retained indefinitely but is removed at a defined point tied to service completion.
Pro users' content is not retained beyond the immediate service need, and a defined deletion point tied to service completion limits DeepL's ongoing possession of user-submitted material.
Unlike paid tiers, the free API Developer plan carries no deletion or retention limit, meaning submitted and processed content may be kept by DeepL without any time constraint.
Permanent data loss at trial end—with no recovery option absent a subscription purchase or prior export—creates a hard deadline that, if missed, results in irreversible loss of the customer's data.
The clause permits Duolingo to use user-submitted content to train proprietary AI models, meaning user interactions directly feed Duolingo's AI development.
This establishes that communications and content within EA services are not private and may be captured and retained by EA for moderation, meaning users have no expectation of confidentiality in thos…
This establishes a firm deadline by which customers' Content will be permanently destroyed, regardless of the cause of termination, which affects data recovery options.
The clause sets a defined maximum retention period for generated voice data, with a legal compliance carve-out that could extend retention in some circumstances.
The clause places a defined outer limit on how long biometric data—a sensitive category—can be held, protecting users from indefinite retention.
The three-year retention limit establishes a defined maximum period for retention of voice-generated data, with a legal compliance exception that could extend that period.
The 7-day maximum and permanent deletion commitment define the outer boundary of how long Eufy retains this sensitive audio data when users do not retrieve it.
A user's deletion or anonymization request submitted to Eventbrite does not automatically remove data already held in an Organizer's independent databases, limiting the practical effect of such reque…
A defined retention ceiling gives users a baseline expectation for how long their data is held, while the legitimate business interest exception allows Fastly to extend retention beyond that ceiling.
Users cannot selectively delete their personal information while retaining their Figma account; deletion of personal data is conditioned on account deletion.
Users of open models have a default of no data logging or storage, with any logging requiring affirmative opt-in rather than passive consent.
Deletion is triggered only upon Fireworks AI learning of the child's age; it implies no proactive age-verification mechanism beyond the notice-based trigger.
Absent any user-initiated deletion request, account information is retained without any time limit, meaning data persists through extended periods of inactivity.
The timing of biometric data destruction is controlled entirely by GOAT's instruction to Persona, meaning the biometric identifier persists indefinitely until GOAT initiates the destruction order.
Because Garmin does not retain payment card details, that data is not held in Garmin's systems and therefore cannot be exposed through a Garmin data breach.
Closing an account does not end Gemini's retention of a user's Personal Information; data persists for compliance-driven purposes.
A retention period of up to three years means precise location data — among the most sensitive personal data categories — may be held by General Motors for an extended period.
The commitment creates an affirmative obligation on GitHub to safeguard private repository contents, establishing a baseline confidentiality standard.
The 90-day deletion window means user data is not retained indefinitely after account closure, but also that recovery is impossible once the account is canceled.
Retention is bounded by purpose and obligation, but the open-ended category of 'other business obligations' leaves the outer limit of retention undefined.
Permanent loss of access to historical Report data upon termination means users cannot retrieve past analytics information after the agreement ends.
The clause sets a firm maximum retention period for Customer Personal Data while preserving a legal-obligation exception, giving customers a concrete deadline for data deletion.
It establishes that a user's deletion of their own activity does not result in deletion of human-reviewed chats, creating a category of data outside the user's control for up to three years.
It establishes that in the absence of user action, chat data is retained for 18 months, and it defines the exact alternative retention periods available to users.
Retention is conditioned on a continuing legitimate business need, which limits indefinite retention but leaves the scope of that need to Greenhouse's determination.
This clause establishes a necessity ceiling on retention, but the legal-obligations carve-out means Grindr may retain data beyond the original collection purpose when law permits or requires it.
An active account means Grindr retains the associated data indefinitely with no automatic expiry, regardless of how long ago the data was created.
This clause creates a conditional deletion obligation triggered by Gusto's awareness that a child under 13 submitted personal information, providing a protective measure for minors.
This clause establishes a time-bound deletion obligation that limits how long Harvey AI retains your data after the relationship ends, with an exception if you direct otherwise.
Data retention and deletion timelines are not fixed by the Privacy Policy but are instead determined by the individual Customer Agreement, meaning different customers may have different deletion term…
A ten-year retention period means personal health and coaching records persist long after a user stops using the Service, with potential implications for privacy and data exposure.
Account closure does not immediately end Hinge's retention of user data; the safety retention window means data persists for a defined period even after a user has left the platform, and longer still…
The 30-day deletion rule provides a time-limited retention guarantee for biometric face data, but the safety and legal exceptions create conditions under which retention may extend indefinitely.
Permanent deletion means the data cannot be recovered after the trial period, making the decision to subscribe before trial expiry consequential and irreversible.
The obligation is qualified by 'commercially reasonable efforts,' meaning deletion is not absolute or guaranteed, which limits the protection afforded to children whose data was inadvertently collect…
The 15-day default retention period is qualified by open-ended exceptions that permit indefinite retention, meaning deletion does not guarantee prompt removal of inputs.
Outputs are retained permanently with no expiration, meaning user-generated content persists in Inflection AI's systems indefinitely.
A user's deletion request or end of their contractual relationship with Intuit does not guarantee erasure; legal and regulatory obligations may override those requests and compel continued retention.
US Tax Return Information is geographically restricted to US processing and storage by default, limiting cross-border data flows unless the user actively consents to transfer.
A legal retention obligation means a deletion request does not result in complete erasure of all personal data, limiting the practical effect of the right to be forgotten.
The clause creates a default deletion commitment while carving out an exception that can limit how much data is actually deleted, depending on applicable legal obligations.
The deletion obligation is triggered only by termination for cause and must occur within a defined thirty-day window, setting both a condition and a deadline for data deletion.
The 48-hour post-processing retention limit means user data is not stored indefinitely, but also means users cannot expect to retrieve their content from LlamaIndex's S3 storage after that window.
This clause creates an ongoing obligation for Loom to maintain a security program, providing customers a basis to assess whether Loom's security practices meet the standard of 'appropriate' measures.
This clause establishes that Customer Data will not be retained indefinitely after the relationship ends, though the specific timeline and process depend on the Documentation, and legal obligations m…
Transactional data is held for a defined minimum period of at least seven years, meaning users cannot expect this information to be deleted sooner.
Account deletion does not guarantee erasure of all personal information; Lyft retains the right to keep data under qualifying conditions even after a deletion request is fulfilled.
The deletion is permanent and covers all associated data including Campaigns, meaning there is no recovery mechanism for data lost following account termination.
The clause establishes that retention periods are not fixed and that regulatory obligations in the financial sector may require Mercury to retain certain Personal Information beyond a standard necess…
A seven-year public retention period means political ads remain publicly accessible and attributable long after a campaign ends, creating an extended transparency and accountability record.
This clause sets a ceiling on how long Meta may hold Event Data, which bounds the period during which that data can be used for the purposes permitted under the Terms.
This clause establishes a mandatory deletion obligation on Meta, limiting how long Contact Information can be held to the duration of the match process.
The retention period is bounded by necessity and user instruction but contains a broad carve-out allowing longer retention whenever law requires or permits it, which may extend retention beyond the u…
This clause limits MetaMask's collection and retention of Personal Information to what is necessary for defined purposes, establishing a data minimization commitment.
Recall captures a continuous record of on-screen activity; the local-only storage commitment and the user-action requirement before any transmission are the primary privacy safeguards limiting exposu…
Users stand to permanently lose access to data and content stored under a closed account, making account closure an irreversible data loss event in the absence of a legal obligation on Microsoft to p…
It establishes both the delay before deletion takes effect and the finality of deletion once the grace period expires.
It specifies which game data is permanently deleted upon account deletion, making clear that game progress and associated data cannot be recovered.
This clause governs what happens to Personal Data at the end of the service relationship, but the choice between deletion and return, and the timing, are governed by Mistral AI's own policies and pro…
Deletion is immediate and unconditional upon discovery, providing a firm protective commitment for children's data.
The clause establishes a maximum retention period for customer and enterprise personal data tied to inactivity, meaning data is not held indefinitely.
User deletion requests may not result in actual deletion if Noom determines legal obligations require retaining the data.
Retention tied to original purpose limits prolonged data holding, but the legal obligations, disputes, and enforcement carve-outs can extend retention indefinitely in practice.
Immediate deletion upon cancellation means there is no grace period to retrieve uploaded content after the account is cancelled.
This clause establishes that Customer Data does not automatically disappear upon termination—it depends on Customer instruction—and that legal retention obligations can override the return or deletio…
The clause specifies the operational mechanism for account wind-down and data retention obligations post-termination. It defines the scope of data subject to deletion and the timeframe within which d…
The thirty-day deletion obligation gives Customer assurance that its content will not be retained indefinitely, subject to two defined exceptions.
The clause establishes a default deletion timeline for API data, with the only exception being a legal retention obligation.
The clause defines a deletion window but preserves OpenAI's ability to retain data longer under legal obligation or a reasonably necessary harm-protection determination.
The clause establishes that API data is not immediately discarded and may be held for up to 30 days for defined operational and safety purposes.
The retention and use of flagged content by sub-processors is double-limited: by time (review period only) and by purpose (assisting OpenAI's review only), constraining how sub-processors can handle …
The clause makes zero data retention available but conditions it on endpoint eligibility and possession of a qualifying use case, meaning it is not universally available.
A user's deletion request does not guarantee data removal; OpenSea retains discretion to keep data under several broad but qualified grounds.
The retention period is open-ended and determined by Oscar Health's own belief of necessity across multiple broad categories, meaning personal information may be kept indefinitely after account closu…
Account closure or a deletion request does not guarantee complete erasure of Personal Information; PayPal maintains the right to retain some data.
Personal Information is retained for a substantial fixed period after the relationship ends, meaning data is not deleted promptly upon account closure or termination.
A fulfilled deletion request does not guarantee complete removal of a user's personal data from Peloton's systems.
The thirty-day deadline creates a concrete, time-bound data disposal obligation on Perplexity AI, and grants Customers the option to recover their data rather than have it deleted, subject only to a …
This establishes a qualified deletion obligation on Pinecone at termination, with the scope and timing of deletion governed by the Documentation and Agreement rather than stated as immediate or absol…
The claim establishes that the retention limitation is conditional on applicable law requiring it, meaning the obligation to limit retention does not apply universally but only where law mandates it.
Users' chat content may be retained indefinitely on third-party developer servers and used to train AI models, representing a significant secondary use of conversational data beyond the original inte…
Closing an account does not result in deletion of all personal information; Public.com continues to hold certain data, limiting the user's ability to fully remove their information.
The retention standard is open-ended—Ramp may retain Personal Information indefinitely as long as any business, operational, or legal purpose exists, with no defined maximum retention period.
Account deletion does not guarantee erasure of personal data when a legal order requires its preservation, meaning user-initiated deletion has limits.
Deleting an account does not guarantee deletion of Personal Information, because Redfin's retention is governed by its own business purposes and legal obligations.
The clause establishes a specific, time-bound obligation on Replit to delete user data following an account deletion request, giving users a defined window for data removal.
Retention is tied to account activity and service necessity rather than a fixed time limit, meaning data may be held indefinitely while an account remains open.
The 180-day ceiling and the storage-setting dependency mean a user's recorded footage does not persist indefinitely and may be retained for less time than the maximum, affecting how long evidence or …
Automatic deletion upon storage period expiration means users lose permanent access to recordings at a defined threshold, with no indication that deletion can be prevented or reversed.
Users who close their accounts or stop using Robinhood's services may have certain data retained for up to five additional years, limiting the practical effect of any deletion or departure.
A defined outer retention limit of three years, with an earlier cutoff when the collection purpose is fulfilled, places a concrete cap on how long biometric data is held.
The policy explicitly prohibits both storage and use of customer prompt data for model training by third-party LLMs, and asserts exclusive customer ownership of that data, directly addressing a key c…
Customer Content remains within the selected geographic region, which determines which data protection laws apply to that data.
The duration of personal data processing is tied directly to active customer use and to separately agreed retention periods, meaning data is not processed on an indefinite or open-ended basis beyond …
The retention commitment is qualified by 'endeavor', meaning it is a best-effort obligation rather than an absolute one, and retention is tied to the necessity of the original processing purposes.
Merchants cannot expect their store data to be promptly deleted upon closure or termination; a two-year retention period precedes any deletion process.
Audio and video from a user's home are actively held on SimpliSafe's systems for a defined 30-day window, meaning sensitive recordings persist beyond any single event.
User-initiated deletion from an account does not remove the data from SimpliSafe's systems, meaning users cannot eliminate SimpliSafe's copy of their recordings through account actions.
Retention is tied to account activity and business necessity, meaning data is not deleted upon any single triggering event and may persist for financial reporting purposes beyond service use.
A deletion request does not guarantee removal of personal information; Skillshare retains discretion to keep it when it determines retention is necessary for stated legitimate business interests.
The seven-year general limit establishes a default retention ceiling, but the listed exceptions mean data may be held indefinitely in qualifying circumstances.
The deletion commitment is qualified by design intent rather than a guarantee, and two user-controlled exceptions mean deletion is not automatic in all cases.
Retention is governed by three separate triggers—user instruction, operational need, and legal obligation—meaning data may persist beyond a user's preferences if law or operational need requires it.
The right to retrieve Customer Data is time-limited to 30 days and conditioned on written notice, meaning data may become inaccessible if the customer fails to act promptly or provide proper notice.
The Security Exhibit defines the scope of Sourcegraph's obligations regarding User Content, Code, and Confidential Information for all generally available products, establishing a baseline security f…
Deletion of a child's personal data is conditional on Sourcegraph Cody's determination that it is appropriate, meaning deletion is not automatic upon notification.
The Zero Retention commitment means Partner LLMs hold no persistent copy of customer inputs, outputs, or embeddings, limiting the window during which that data could be exposed or misused.
The immediate deletion commitment limits the window during which sensitive age-verification data—which may include biometric or document information—is retained by Spotify.
Retention is not limited to the duration of an active account; data may be kept after account closure for legal, enforcement, and fraud-related purposes, potentially for an extended and indeterminate…
This sets an outer retention limit tied to the purposes stated in the notice, bounding how long personal information may be held under those purposes.
Data is retained indefinitely by default after the relationship ends, meaning former customers have no general right to have their information destroyed.
Customers who believe they are deleting their full relationship with State Farm by using the in-app deletion feature are only removing their app-specific credentials and account; other State Farm acc…
An account deletion request does not guarantee erasure of a customer's information, because State Farm retains the right to keep it for legal, auditing, regulatory, and business purposes.
The claim establishes that account termination triggers a deletion process for Personal Data, while preserving Steam's ability to retain data where legal requirements or prevailing legitimate purpose…
The claim establishes a legally mandated retention period for certain transactional data that operates independently of user preferences or account deletion.
A regulatory requirement mandates that certain data from Indian payment transactions remain stored within India, constraining where Stripe India may hold that data.
Closing an account or ceasing to use Stripe's Services does not end Stripe's retention of your Personal Data, which continues for compliance and fraud purposes.
A regulatory requirement—not solely a contractual choice—mandates that certain data from Indian payment transactions remain stored within India.
A defined maximum retention period for biometric data limits how long this sensitive information is held, giving users a concrete outer boundary for its storage.
The clause binds both Synthesia and its vendors to a purpose-limited retention standard, preventing indefinite storage of Biometric Data.
The clause ties the retention period to a specific, short-duration technical event, minimising how long authentication-purpose Biometric Data is held.
The clause ties the Biometric Data retention period directly to the Avatar's availability, meaning the data persists as long as the Avatar does unless the Customer intervenes.
The clause establishes permanent destruction as the default outcome for Biometric Data, with a carve-out only for legal obligations to retain.
All data tied to an account is permanently deleted after 18 months of inactivity by default, with no user-initiated action required to trigger deletion.
Secret chat messages exist only on users' devices and leave no server-side record, meaning Telegram cannot produce secret chat content in response to legal demands or data breaches affecting its serv…
The commitment is to take steps toward destruction rather than guaranteeing destruction, and the timeframe is governed by variable applicable law, meaning retention periods may differ by jurisdiction.
There is no time limit on data retention while an account is active, meaning accumulated personal data is held indefinitely unless the account is closed.
A minimum five-year retention period means user data in Indonesia is preserved for an extended period, limiting the practical effect of any deletion or erasure rights during that window.
Transaction data is subject to a fixed 10-year retention period driven by legal obligation, meaning users cannot request its earlier deletion on that basis.
The 30-day deletion rule is subject to two exceptions — legal obligation and safety/security — which can extend retention beyond the default period.
Regional data residency is not absolute; Twilio retains the ability to move Customer Content outside the selected region when investigating fraud or abuse, which is a meaningful limitation on the reg…
The use of 'endeavors' rather than an absolute commitment limits the strength of this retention obligation, which affects the reliability of the data minimization assurance.
The duration of personal data processing by sub-processors is directly linked to both active service use and contractually agreed retention periods, meaning data is not automatically deleted upon sto…
Customers who have not selected a regional data arrangement should expect their account and service usage data to be processed in the United States, with the legal and compliance implications that en…
Account closure does not necessarily result in full data deletion, as Twitch retains discretion to keep certain information for its stated purposes or legal obligations.
Data may be held for up to 7 years based on Uber's own tax, insurance, legal, or regulatory needs, with account deletion as the only user-side condition that can shorten that period.
A deletion or access request does not guarantee that Uniswap will stop retaining the information, as legitimate interests and legal obligations can override such requests.
This establishes an automatic data deletion trigger tied to inactivity for child accounts, with a specific future effective date, creating a time-bounded retention limit.
Personal information is retained for a minimum of 10 years after the relationship ends, and an open-ended exception permits indefinite retention beyond that period.
The claim establishes that retention is bounded by a minimum necessary standard, but applies across multiple broad purposes, which collectively define how long data may be kept.
This establishes a binding outer time limit on how long Walgreens may retain biometric data, with an earlier trigger if the collection purpose is fulfilled sooner.
Walmart is bound by a specific destruction obligation tied to purpose completion or a fixed time limit, giving biometric data a defined maximum retention period.
This clause establishes a binding destruction schedule for biometric data, which is among the most sensitive categories of personal information and cannot be changed if compromised.
A comprehensive route history of all journeys is retained, meaning Waze holds a cumulative record of a user's travel history, not just recent or selected trips.
Retention is tied to active use or purpose fulfillment with no fixed time limit, meaning Personal Information may be held indefinitely as long as either condition is met.
This clause informs Clients that regulatory obligations override data deletion requests, meaning Client Personal Information will generally be retained regardless of a deletion request.
This clause places a time-bound destruction obligation on vendors handling biometric data, limiting how long that sensitive category of data may be retained in the identity-verification supply chain.
California residents who are Wealthfront Clients are on notice that their deletion rights are generally unavailable due to regulatory obligations, substantially limiting a key California privacy righ…
The obligation to delete is conditioned on discovery and is limited to unintentional collection without parental consent, and the commitment is to 'take steps' to delete rather than guaranteeing imme…
This clause establishes that Windsurf holds unilateral discretion over the retention period for Feedback Data and User Interaction Data, with no defined maximum retention limit.
This clause establishes a default data retention limit tied to the active customer relationship, with customers holding the ability to specify alternative retention terms.
It establishes that Writer's stated default is minimal data retention tied to active platform use, not indefinite storage.
It establishes that customers have direct control over automated deletion of their data at the organization level.
Wyze retains Facial Data, which may constitute biometric information, for a defined 180-day window after service termination rather than deleting it immediately.
Users face permanent loss of their data and content upon account closure, with recovery dependent on legal obligation rather than user preference.
Account closure does not result in full deletion of a user's information; Yelp retains the right to keep data beyond what is publicly visible.
Data collected in YouTube Kids, including sensitive voice recordings, may be associated with and retained in a child's Google account when they are signed in, expanding where that data is stored.
The retention period is open-ended during the relationship and extends significantly beyond it, meaning B2B personal data may be held for a very long time depending on relationship length.
Biometric data collected for enhanced features has a defined maximum retention period of two years from last interaction, but may be deleted earlier if Zoom determines it is no longer necessary, adeq…
The deletion obligation is subject to broad legal carve-outs, meaning personal data may be retained beyond the standard retention period for a range of legal and regulatory reasons.
Retention is tied to ongoing use, stated purposes, and legal requirements, meaning AWS may hold personal information for the duration of a user's relationship with AWS Offerings and potentially beyon…
Closing an account does not guarantee immediate deletion of personal information; AWS retains discretion to keep data for legal and legitimate business purposes.
Data retention duration determines how long a user's personal information remains in Afterpay's systems and subject to potential use or disclosure.
The claim establishes a two-stage deletion timeline, meaning deleted conversations persist on Anthropic's back-end for up to 30 days after the user removes them from their visible history.
Retention tied to active use and multiple open-ended operational purposes means personal information may be kept for extended or indefinite periods beyond a user's expectations.
The retention limit ties how long Baseten may hold Personal Data directly to the stated purposes, creating a boundary on indefinite storage.
The clause defines the baseline retention period, meaning personal information is held throughout the entire duration of the account or contractual relationship.
The clause operationalizes data retention constraints by tying data lifecycle management to dual criteria: functional necessity and legal compliance ceilings. This establishes a procedural framework …
The clause creates a dual retention framework: a general principle limiting retention to necessary periods, paired with a carve-out that permits extended retention post-deletion for specific operatio…
The reasonably necessary standard governs how long Calendly can hold Personal Data, limiting indefinite retention but leaving duration to Calendly's judgment.
Retention duration is tied to external references (Section 3 business purposes) and unspecified legal obligations, meaning users cannot determine a fixed deletion timeline from this clause alone.
The absence of a specified data retention limit means the company retains operational discretion over retention duration based on stated purposes, rather than a defined schedule or automatic deletion…
The temporary-only nature of cached file storage under privacy mode limits how long file contents remain on Cursor's systems.
Abuse-flagged data is subject to a different retention pathway than ordinary data, meaning it may be stored longer or under different conditions before deletion.
The retention limitation constrains how long Cursor may hold personal data, tying retention to operational necessity and defined legitimate purposes rather than allowing indefinite storage.
Even without storing raw code, Cursor may retain derived representations and identifying metadata about a user's codebase.
The clause establishes the operational conditions under which account data is removed from the service platform. It creates two separate termination pathways: one automatic upon failed payment proces…
The retention period is not fixed and extends beyond active use of the Services if law or legitimate business or commercial purposes require it, meaning personal information may be held indefinitely …
This limits how long Datadog may hold personal information, meaning data should not be stored indefinitely beyond its original collection purpose.
The retention period is tied to defined purposes rather than being indefinite, but a legal carve-out allows retention beyond those purposes when law requires or permits it.
The retention period is not fixed—it is tied to active service provision and Policy-described uses, with a legal-override carve-out that could extend retention beyond what the user might otherwise ex…
The 30-day delay means account information is not immediately removed upon deletion, leaving a window during which the data still exists on Dropbox's systems.
The clause establishes a specific upper bound on IP address retention but includes an exception for exceptional circumstances that could extend retention indefinitely.
Egnyte does not commit to a fixed deletion timeline, meaning personal information may be held indefinitely as long as a qualifying purpose exists.
Retention is tied to active service use or purpose fulfillment, meaning personal data is not automatically deleted after a fixed period.
Retention tied to use and purpose means personal information may be held indefinitely if disputes or other purposes persist, with no fixed deletion deadline.
The retention period is open-ended and tied to Figure AI's own assessment of necessity, meaning data may be held indefinitely as long as a business or commercial purpose exists.
Users who delete their accounts may have data—including sensitive device-recorded health data—retained in Fitbit's systems for up to 90 days, extending the period of potential exposure.
The qualifier 'usually' means retention is not guaranteed to be strictly limited, and 'legitimate business interests' provides GOAT a broad secondary basis for extended retention beyond the original …
This clause establishes that Prompts submitted outside the code editor are retained by GitHub Copilot, which is a distinct data handling practice from what may apply within the code editor.
Retention does not end at account closure; GitHub may continue holding Personal Data beyond that point to satisfy legal or contractual needs.
Users cannot know the exact retention period for their specific data without additional information, and the 180-day ceiling applies only to 'most' types, not all.
The retention period is open-ended beyond the contractual duration because it extends for any period that is legally required or permitted, which may be indefinite depending on applicable law.
The retention period is not fixed; Home Depot's discretion over what is 'reasonably necessary' means personal information may be held indefinitely beyond the active relationship.
Retention continues by default until one of three conditions is met, meaning data is not automatically deleted after a fixed period unless a specific legal or user-driven trigger occurs.
Retention is governed by three independent triggers — purpose fulfillment, legal requirements, or user deletion request — meaning data may persist until all applicable conditions are addressed.
The retention period is tied to service necessity rather than an indefinite or fixed term, which bounds how long Khan Academy holds personal data.
Because three broad retention purposes are identified with no fixed time limit, personal information may be held indefinitely as long as LangChain determines any one purpose remains active.
Users cannot expect transaction data to be deleted before the 7-year period expires, as the retention is tied to Lime's accounting obligations.
This clause defines the baseline duration for which Linear holds Personal Data, meaning data is not deleted simply because it is no longer actively used but persists for the full account lifetime.
The retention period is bounded by a 30-day window, but the qualifier 'generally' and the explicit carve-out for exceptions mean deletion is not guaranteed for all data.
The qualifier 'usually' means this retention limit is not absolute, leaving open the possibility that personal data may be kept beyond what is reasonably necessary in some circumstances.
The retention standard is necessity-based across multiple open-ended purposes, meaning personal data may be kept for extended and variable periods tied to legal, operational, and contractual timeline…
The 14-day window establishes a concrete, time-bound obligation on Medium to remove account data after closure.
This clause establishes a temporal limit on how long Midjourney holds Personal Data, tying retention directly to stated purposes.
Account deactivation does not guarantee deletion of Services Data; Miro retains discretion to keep data for multiple broadly stated purposes.
The clause defines the operational duration of data retention and establishes user-initiated deletion as the mechanism for terminating storage. This determines the period during which Mistral AI main…
The provision creates differentiated retention schedules across API product lines, with standard APIs subject to the 30-day rolling window while specialized APIs (Agents and Fine-Tuning) maintain lon…
The provision creates differentiated retention schedules across API product lines, establishing operational periods during which Mistral AI maintains access to input and output data for service deliv…
This establishes an outer bound on how long Nintendo holds personal data, grounded in the 'reasonably necessary' standard rather than an indefinite retention period.
A defined retention period of 25 months determines how long Pinterest holds log data that may include records of user activity.
Users who update their information to correct or change it cannot assume the prior version is deleted, because Redfin may retain it under legal obligations.
The retention period is tied to service necessity, meaning Replicate determines how long data is kept based on that standard rather than a fixed time limit.
The provision operationalizes Revolut's data retention obligations under anti-money laundering and financial services regulations, which typically mandate multi-year record preservation. The extended…
Voice chat content is not immediately discarded; filing a report without resulting account action triggers a longer retention period for all parties' communications.
This clause establishes the operational framework under which RHS monetizes securities lending activity. By retaining all compensation from lending activities, RHS creates a revenue stream from accou…
Retention is bounded by the purposes enumerated in Section 4, meaning data should not be kept indefinitely or for unrelated purposes.
Customers have a choice between two geographic regions for where their data is hosted and stored, which has implications for applicable data protection laws.
This limits indefinite retention of personal data, tying storage duration to the specific purpose for which data was originally gathered.
Because message history is stored on user devices rather than Signal's infrastructure, Signal does not hold or control users' message archives.
The retention period is open-ended and tied to active contractual obligations, meaning personal data is not deleted on a fixed schedule but persists as long as the service relationship requires it.
Customers cannot assume their information is deleted after their relationship with State Farm ends, as retention continues for multiple stated purposes.
The clause establishes a general limit on how long Tabnine holds user information, but the qualifier 'reasonable business and lawful needs' gives Tabnine meaningful discretion over the retention peri…
The retention period is open-ended and tied to service delivery and policy purposes rather than a fixed time limit, meaning data may be held indefinitely while a user remains a customer.
Users who request deletion of their data cannot expect it to be removed immediately; the data may remain in Waze's systems for up to approximately 2 months after the request.
The retention period is open-ended and tied to dual criteria—collection purpose and legal obligations—meaning data may be kept indefinitely where regulatory requirements demand it.
The clause sets a limiting principle on how long Weights & Biases holds personal data, but the law-based carve-out means retention can extend beyond the policy's stated purposes.
Undelivered messages remain on WhatsApp's servers in encrypted form for up to 30 days, which defines both the window of attempted delivery and the outer limit of retention.
Delivered messages do not remain on WhatsApp's servers, limiting what WhatsApp retains and can access or share after delivery.
Users who believe uninstalling the app ends WhatsApp's retention of their data may unknowingly leave their information stored for an extended period.
The deletion commitment is conditional on no contrary statement being made, meaning Windsurf can retain audio by disclosing that it will do so.
The reasonably necessary standard means retention duration is not fixed and may vary depending on purpose, leaving users uncertain about how long their data is held.
The retention period is not fixed; it lasts as long as Workday determines a legitimate business need exists, which may extend significantly beyond the end of a service relationship.
Different retention periods apply to different categories of data, meaning some personal information may be held for substantially longer depending on how it was collected.
Termination of the contractual relationship does not guarantee deletion of personal data; Zendesk retains the right to hold data for surviving obligations.
Monitor emails you the same day a platform you choose changes these clauses.
A data retention clause is a provision in a platform's terms of service or privacy policy governing data retention-related rights, obligations, or restrictions.
ConductAtlas tracks 275 platforms with data retention clauses - roughly 78% of platforms in the archive. 448 are classified as high severity.
Severity reflects the magnitude of rights waived, availability of opt-out, breadth of users affected, financial or legal exposure created, and the degree of discretion retained by the platform.