Your portfolio content — projects, files, CV, profile — is kept for as long as your account exists and is deleted when it is. The records below are the operational ones kept alongside it, each with a fixed ceiling enforced by a nightly job rather than by anyone remembering.
Portfolio view records — 90 days to 3 years, depending on the portfolio owner's plan
One row per view of a portfolio, project, variant or secure link. It holds a daily-rotating keyed hash of the visitor rather than an IP address, and a referrer reduced to its origin.
The window matches what each plan can actually read, plus headroom so upgrading reveals traffic you already had. Your all-time view total is a counter with no visitor information in it and is kept for the life of the account.
Sent email records — 180 days
Which message was sent to your address, when, and whether it was delivered. The contents of a message carrying a sign-in or reset link are erased the moment it is delivered, not after 180 days.
Long enough to answer "did you send me that receipt" across a full billing dispute, and short enough that a delivery log is not a permanent record of your account activity.
Daily transfer counters — 400 days
A byte total per account per day, used for capacity planning and fair-use review. No URL, file name or visitor is recorded.
A little over a year, so this month can be compared with the same month last year. There is no reason to keep a second year of a number that is already an aggregate.
Support messages — 2 years
The message you sent us, the address to reply to, and the plan you were on at the time.
Support history is what stops you having to re-explain a problem, and two years covers a recurring one. It is personal data, so it has a stated ceiling rather than being kept indefinitely.
Administrator access log — 3 years
Every action one of our administrators took, and every time one opened an account view — who, what, when. It records staff activity, not yours.
Deliberately the longest window here. This log exists to answer "who looked at this" after an incident, and an incident is often found long after the fact, so pruning it early would defeat the only reason it exists.
Account deletion
A deletion request is carried out 14 days after it is made, so an accidental or unauthorised request can be reversed. See "Exporting or deleting your data" for what happens during that period.
One record deliberately survives an erasure: the fact that a data request was made, by which address, and when it completed. It is the only proof the request was honoured, and it holds nothing else about you.
Backups
Backups are retained for up to 30 days on a rolling basis and exist to restore the service after a failure, not to answer requests about individual accounts. Deleted data disappears from backups as they roll over, and a backup is never restored to bring back a single deleted account.
This policy describes how the product actually behaves today. If you find something here that does not match what the product does, tell us — that is a bug in one of the two and we will fix it.