Retention schedule · Updated September 11, 2026

Keep the evidence. Release the raw source.

Retention depends on the purpose of each data class. Shield minimizes durable source content while keeping the evidence, decisions, and security records needed to make the workflow reviewable.

01
Conversation and governance sources

Process the source transiently.

Pasted conversation or email content is scanned without being stored in the permanent report. Successful governance file extraction removes the uploaded original; the report retains masked findings and hashes.

02
Governance evidence

Expire reports on a defined schedule.

The Shield Annual membership supports up to 730 days of report history. Firestore TTL marks report records for expiry while audit events preserve the minimum operational trail.

03
File cleanup

Use short-lived inputs and outputs.

PII-removal jobs use private uploaded originals, encrypted redaction selections, generated outputs, job status, and verification data. Original and downloadable objects are governed by expiry metadata rather than public permanent URLs.

04
Retired features

What they stored was deleted on September 11, 2026.

Breach and dark web monitoring, the open-web exposure scan, and privacy requests were retired on September 10, 2026, and no new lookups, searches, or requests are made. For breach results Forg3t kept normalized source, date, category, severity, counts, and hashes; it never requested or retained raw passwords, extracted breach values, or third-party provider credentials from the user. All of it, the breach and exposure results, the identity vaults, and the privacy-request records with their timelines, was deleted on September 11, 2026. A copy exported just before is kept in a private storage bucket in the EU for 30 days in case a deletion has to be undone, and is then deleted automatically.

05
Connections and account closure

Revoke access and orchestrate deletion.

Account deletion revokes refresh access and runs retryable cleanup across account data, storage objects, credentials, billing links, and identity records.

Want something gone sooner?

Ask, or delete the account.

Write to privacy@forg3t.io to delete a stored record before its retention period ends, or delete your account in Account settings to remove everything at once.