Data Retention Policy
Last updated: September 10, 2026
How long account, billing, storage, diagnostics, and deleted-account data are retained.
1. Active Accounts
We retain account, billing, security, and storage metadata while your account is active and as needed to provide the service, resolve disputes, comply with law, and protect users.
Submitting the authenticated in-app closure request does not immediately change sign-in, access, billing, or stored data. Its server-only queue record uses a SHA-256 hash of the Firebase user ID as the document key and contains the operational Firebase user ID, status, privacy version, request/update timestamps, fixed support-notification delivery status and code, notification timestamps and attempt count, and resolution fields when handled. It contains no email copy, free-text reason, card detail, billing identifier, or file identifier. A pending request has no automatic expiry and remains until automated processing or support resolves it. After audited resolution, it is assigned an expiry 90 days after resolution; scheduled maintenance may remove it later.
2. Deleted Accounts
When a verified account closure is completed, RonikCloud attempts to remove app account records, storage credentials, personal stored file objects, and every verified linked Stripe customer profile with its reusable payment details. Organization-owned workspace records may remain with the organization after membership is removed. App-store payment credentials remain controlled by the store account. Some provider logs, transaction and invoice records, security records, backups, and audit records may remain where required or allowed by law.
To prevent delayed Stripe activity from recreating a deleted account, RonikCloud retains a long-lived suppression record containing only a SHA-256 hash of the Firebase user ID, deletion state, and deletion timestamps. It contains no email, card detail, file identifier, or raw user ID. After deletion succeeds, it is assigned an expiry 400 days after completion.
To block writes made with an already-issued sign-in token, RonikCloud also keeps a minimal profile tombstone and server-only rule-enforcement block at Firebase-user-ID-addressed document paths. They contain only deletion state, privacy version, timestamps, and expiry. After deletion completes, those records are assigned a 48-hour expiry. If closure is incomplete and authentication remains, closing-state deletion and enforcement records remain until the user retries or support safely resolves the deletion; removing them sooner could reopen account writes. Scheduled maintenance removes completed-deletion records after expiry, and a delayed maintenance run may complete removal after the expiry time.
3. Subscription Lapse
If a paid subscription is not renewed, account access and stored data may be scheduled for permanent deletion after the in-app retention notice period, currently designed around a three-month lapse window unless changed by policy, law, or support action.
4. Backups and Logs
Firestore metadata has point-in-time recovery enabled from 16 September 2026, retaining historical metadata for up to seven days. File-storage versioning preserves prior versions of subsequent writes; a finite version-expiry policy is still being established. Verified account closure removes the discoverable personal object versions. Recovery procedures must reapply completed deletions before restoring customer access.
Provider backups, security logs, diagnostic events, and audit records may have separate retention windows. We keep these only as long as needed for security, reliability, accounting, legal compliance, and abuse prevention.
Completion confirms removal from active service systems and the provider inventories available to us. It does not mean that every provider-internal backup is physically overwritten at that instant. Google Cloud publishes an internal deletion period of up to 180 days after a customer deletion instruction under its processing terms, subject to legal retention. Such residual copies are outside normal account access; they are not used to reopen your account.
Opt-in client error reports expire 30 days after receipt and are removed by a daily cleanup process, unless a longer period is required for an active security investigation or legal obligation.
Manual workspace support reports expire no later than 90 days after receipt. Legacy reports are migrated without extending 90 days from their original creation time; already expired or unsafe legacy records are deleted.