Retention schedule · Updated July 27, 2026

Keep the evidence. Release the raw source.

Retention depends on the purpose of each data class. Shield minimizes durable source content while keeping the evidence, decisions, and security records needed to make the workflow reviewable.

01
Conversation and governance sources

Process the source transiently.

Pasted conversation or email content is scanned without being stored in the permanent report. Successful governance file extraction removes the uploaded original; the report retains masked findings and hashes.

02
Governance evidence

Expire reports on a defined schedule.

The configured Professional Annual model supports up to 730 days of report history. Firestore TTL marks report records for expiry while audit events preserve the minimum operational trail.

03
File cleanup

Use short-lived inputs and outputs.

PII-removal jobs use private uploaded originals, encrypted redaction selections, generated outputs, job status, and verification data. Original and downloadable objects are governed by expiry metadata rather than public permanent URLs.

04
Breach intelligence

Keep categories, not leaked secrets.

Forg3t retains normalized source, date, category, severity, counts, and hashes. It does not request or retain raw passwords, extracted breach values, or third-party provider credentials from the user.

05
Connections and account closure

Revoke access and orchestrate deletion.

Provider and Gmail credentials remain encrypted until disconnected or account deletion. Account deletion revokes refresh access and runs retryable cleanup across account data, storage objects, credentials, billing links, and identity records.

Set your starting preference

Choose retention during onboarding.

You can begin with a shorter sensitive-data retention period and adjust your workflow from there.