Information lifecycle
Data Retention and Deletion Policy
Effective and last updated: August 5, 2026
Default schedule
| Record | Default retention | Reason |
|---|---|---|
| Active mailbox messages and attachments | Until user deletion/account deletion or documented hold | Provide email service |
| Trash and spam | 30 days | Recovery and anti-abuse review |
| Drafts | Until sent or deleted | User-directed storage |
| Deleted account | 30-day grace period by default, then purge | Prevent accidental loss and process disputes |
| Sessions/tokens | Until expiry/revocation; stale records periodically deleted | Authentication and security |
| Detailed IP/user-agent security data | Normally anonymized after 90 days | Security investigation and data minimization |
| Consent records | 5 years by default | Demonstrate choices and compliance |
| Completed privacy requests | 3 years by default | Compliance evidence and appeals |
| Abuse, legal, incident and audit records | Based on legal, safety, limitation and investigation needs | Safety, legal obligations and defense of claims |
| Backups | Rotating schedule configured by operations | Resilience; deletion occurs through normal backup expiration unless preservation is required |
Holds and exceptions
Deletion may be delayed for a valid preservation request, litigation hold, security incident, abuse investigation, financial obligation, statutory recordkeeping requirement or protection of users and the public. Holds must be documented, scoped and reviewed.
Address reuse
Deleted usernames should remain unavailable for a defined safety period to prevent impersonation or receipt of messages intended for a former account holder. Operations must configure and document the reuse period before launch.