Per data class
How long each data class is kept
Tollcast data falls into ten classes, each with a different retention window. The table below is the source of truth — privacy and any other page that lists a retention value refers to this one.
| Data | Window | 30-day delete |
|---|---|---|
| Account profile (name, email, handle, primary platform) | While account is active | Yes |
| Auth sessions + better-auth state | 14 days rolling, refreshed on activity | Yes |
| Voice-training samples pasted at /voice | Until you replace or delete them | Yes |
| Voice profile (derived tone / cadence) | Until account deletion or manual reset | Yes |
| Generated drafts and video scripts | Until approved, rejected, or 30 days pass | Yes |
| Mentions surfaced into /inbox | Until the queue is cleared or 30 days pass | Yes |
| Stripe subscription + invoice data | Until you cancel; archives retained for tax/audit | Tax-archive only |
| Email-verification & password-reset tokens | Until consumed or expired (1h for verification) | Yes |
"30-day delete" means the data is purged from the active database within 30 days of an account-deletion request, with backup snapshots aged out the same window. Stripe tax-archive is the only carve-out — it's the legal record for billing and is governed by Stripe's own retention policy.