Keep the evidence. Release the raw source.
Retention depends on the purpose of each data class. Shield minimizes durable source content while keeping the evidence, decisions, and security records needed to make the workflow reviewable.
Process the source transiently.
Pasted conversation or email content is scanned without being stored in the permanent report. Successful governance file extraction removes the uploaded original; the report retains masked findings and hashes.
Expire reports on a defined schedule.
The configured Professional Annual model supports up to 730 days of report history. Firestore TTL marks report records for expiry while audit events preserve the minimum operational trail.
Use short-lived inputs and outputs.
PII-removal jobs use private uploaded originals, encrypted redaction selections, generated outputs, job status, and verification data. Original and downloadable objects are governed by expiry metadata rather than public permanent URLs.
Keep categories, not leaked secrets.
Forg3t retains normalized source, date, category, severity, counts, and hashes. It does not request or retain raw passwords, extracted breach values, or third-party provider credentials from the user.
Revoke access and orchestrate deletion.
Provider and Gmail credentials remain encrypted until disconnected or account deletion. Account deletion revokes refresh access and runs retryable cleanup across account data, storage objects, credentials, billing links, and identity records.
Choose retention during onboarding.
You can begin with a shorter sensitive-data retention period and adjust your workflow from there.
