← Back to Security
Data retention
How long Michi keeps each kind of data, and what triggers deletion
Michi is operated by Nefra, Inc., a Delaware corporation (United States). For users in the European Economic Area, Sila Technologies B.V. (Antwerp, Belgium), an affiliated entity of Nefra, Inc., acts as the data controller for personal data under GDPR.
We keep data only as long as it's useful to you or required by law. Most categories can be deleted on-demand from the app. The schedule below is the default, and your organisation can tighten any customer-configurable category from Settings, Security and Privacy.
| Category | Retention | Trigger |
|---|---|---|
| Organisation and all its data | RetentionUntil the owner requests deletion, then a 30 day grace period | TriggerAn owner requests deletion in Settings → DataA reminder email is sent 2 days before the deletion runs, so an accidental request can be cancelled during the grace period. |
| Your individual account | RetentionUntil you delete it. Deletion is immediate, with no grace period | TriggerDelete my account in Settings → SecurityDeleting your account erases everything that is yours: your transcripts, the mailboxes and calendars you connected with what was synced from them, your Founder AI chat and AI tool results, notifications, imports, exports, preferences, profile picture and sign-in. Your name stays on the records your team keeps, and billing, audit and terms-acceptance records are kept. The organisation and its shared records are not deleted. |
| Platform records (companies, contacts, deals, notes, tasks) | RetentionUntil the customer deletes them, or until the organisation is deleted | TriggerPer-record delete, or organisation deletionA deleted record is recoverable for 30 days, then permanently removed by a daily job. |
| Email messages (Gmail / Microsoft sync) | RetentionPer customer setting — default unlimited, configurable 30/90/365 days | TriggerDaily retention cronEmails synced from your own mailbox are deleted when you delete your account, along with the suggestions Michi drew from them. |
| Meeting transcripts (raw text) | RetentionPer customer setting — default keep forever, configurable 30/60/90/180/365 days | TriggerNightly transcript-retention cronThe AI extraction is erased at the same time as the raw text. It reconstructs the same meeting, so keeping it would not be a deletion. |
| AI extraction outputs | RetentionSame as the parent record | TriggerPlatform record deletion |
| Saved AI tool results | Retention180 days | TriggerDeleted daily once older than 180 days, and deleted with the organisationEach run of an AI tool, such as Lens, Dossier or Compass, is saved so you can open it again without paying twice. A saved Lens brief on a company is also deleted when you mark that company as the wrong match. If you delete your account, the results you ran are deleted with it. |
| Founder AI chat history | RetentionUntil you delete your account, or the organisation is deleted. There is no scheduled purge | TriggerAccount deletion, or organisation deletionYour questions to Founder AI and its answers. Michi shows them only to you, they are included in your data export, and they are deleted when you delete your account. |
| Audit log | RetentionFor the life of the organisation | TriggerDeleted with the organisationKept for forensic and compliance purposes and never deleted by user action. We do not currently run a scheduled purge, so entries persist for the life of the organisation. |
| Billing records (invoices, payment history) | Retention10 years | TriggerLegal requirement (Belgian accounting law)Stored by Stripe; we only retain Stripe customer IDs and invoice references. |
| Server logs | Retention30 days | TriggerVercel platform retention policy |
| Webhook event log (stripe_events, webhook_events) | Retention180 days | TriggerDeleted with the organisation, and purged daily after 180 daysUsed for replay during incidents and for idempotency. Payment event records are deleted outright. Provider event records keep only their delivery id, so a resent webhook is still recognised as a duplicate, and the message content itself is erased. |
| Data export files (the ZIP you download) | Retention7 days | TriggerDaily purge, and deleted with the organisationAn export is a complete copy of your data, so it is kept only briefly. The download link itself expires after 24 hours; ask us for a new one while the file is still there. |
| Uploaded files (import spreadsheets, term sheets, logos) | RetentionUntil you delete them, or until the organisation is deleted | TriggerOrganisation deletion. Import spreadsheets are removed within 24 hours of uploadRemoved from file storage as well as from the database when an organisation is deleted. |
| Profile picture | RetentionUntil you replace or remove it, or delete your account | TriggerYou change it in Settings, or delete your accountYour avatar belongs to you rather than to a company, so it is kept if an organisation you belong to is deleted. Remove it from your profile, or delete your account, to erase it. |
| Backup snapshots | Retention30 days (daily PITR) | TriggerSupabase platform rotationRequired for disaster recovery; deletion requests are honoured by re-running deletions after restore. |
Need a custom retention period for an enterprise contract? Email dpo@michiplatform.com.