KlaritiQKlaritiQ
Legal

Retention & deletion

Last updated: 7 September 2026 · Applies to klaritiq.in and the KlaritiQ platform

How long each kind of data stays, which button removes it, and what the word 'erased' means for each one.

The short version
  • Nothing is kept "just in case". Data lives while you use the service and for a 30-day safety window after you delete.
  • Three delete buttons: one assessment (erased at once), your account (locked now, erased in 30 days), an organisation (hidden now, erased in 30 days).
  • Uploaded files are not kept unless an organisation turns retention on, and then only until the expiry it sets.
  • What survives erasure: proof that consent was given (without your IP or browser), anonymous benchmark aggregates, and a tombstone user id so audit logs of surviving organisations still make sense.

The three deletions

One assessment · immediate

Profile → My assessments → Delete
Erased now
answers, email, IP address and telemetry wiped from the record; report unavailable

Your account · two-speed

Profile → Delete my account
recent sign-in required
Locked immediately
all sessions ended; sign-in refused; restore link emailed
Day 30 · erased
see table below

If you own an organisation that still has other members, the button asks you to transfer ownership first: the workspace belongs to the team, not to the person leaving. Organisations where you are the only member are deleted with the account and restored with it.

An organisation · two-speed

Settings → Danger zone → Delete organization
owner only, recent sign-in required
Hidden immediately
no member can open it; owner sees it under Recently deleted
Day 30 · erased
every table row and stored file belonging to it

What "erased" means, row by row

When the 30-day account purge runs, this is exactly what happens to each kind of record.

RecordOn account purgeWhy not simply deleted
Login, sessions, linked Google identitySessions and linked identities deleted. The user row becomes a tombstone: email replaced with an unusable placeholder, name set to "Deleted user", profile fields blanked.Audit logs in organisations you belonged to reference your user id. A tombstone lets them keep meaning "someone" without identifying you.
Assessments and answersAnswers, email address, IP address and telemetry wiped from each assessment; the assessment is marked deleted.—
Assessment turn logThe raw text of what you typed, the request bodies and IP addresses are removed. The structural log of which question was answered when remains, without content.The engine's own transcript is erased by an operator with the separate admin key within the same window; see Security.
Consent recordsIP address and browser removed. The record that consent was given on a date remains, pointing at the tombstone.Proof of consent is something DPDP expects a data fiduciary to be able to show.
Command Center chatsDeleted.—
NotificationsDeleted.—
Usage eventsYour user id is removed; the anonymous event stays.Aggregate product analytics; nothing identifies you once the id is gone.
Organisation memberships and invitationsDeleted.—
Newsletter subscription, contact-form and report-delivery records under your emailDeleted.—
Sole-member organisationsPurged on their own 30-day clock, which started when you deleted the account.—
RecordOn organisation purge
Uploaded filesDeleted from storage first.
Every table with an organisation columnAll rows for that organisation deleted: assessments, evidence, initiatives, risks, decisions, policies, tasks, members, invitations, API keys, integrations, notifications, audit log.
The organisation itselfDeleted last.
Case-engine cases linked to itErased by an operator with the admin key inside the window.

Retention schedule

DataKept forThen
Account and profileWhile the account existsTombstoned 30 days after deletion
Assessments, reports, answersWhile the account or organisation existsErased with it; individual assessments at once on request
Uploaded evidence filesNot retained by default. If retention is on: until the organisation's expiry setting (365 days unless changed) or its storage capRaw file deleted by a daily job; the confirmed facts extracted from it remain as the evidence register
Extracted-fact proposals not yet confirmedProposals awaiting review are swept periodically; interrupted extractions are marked failedRe-upload to retry
Workspace recordsWhile the organisation existsErased with it
Command Center chatsWhile the account existsDeleted with it
Audit logWhile the organisation existsDeleted with it (an organisation that no longer exists has nothing for its log to protect)
Consent recordsIndefinitely, pseudonymised after erasure—
Contact-form and assurance-pilot submissionsUntil we close the conversation, or on requestDeleted
Newsletter subscriptionUntil you unsubscribe or your account is erasedDeleted
Usage eventsIndefinitely, without user id after erasure—
Application logs (hosting provider)Short rolling window set by RenderAged out
Database backups (hosting provider)Render's backup retention windowAged out; not restored except to recover from an outage
Aggregate benchmark statisticsIndefinitelyNever identify an organisation or person
What you can set yourself
Organisation owners and admins control file retention (on or off, expiry in days, storage cap) from the evidence settings. Everything else on this page is fixed, and the same for everyone.

If you cannot press the button

Assessments taken without an account, data entered about you by someone else's organisation, or anything else you cannot reach from a profile page: email klaritiq@gmail.com with "Erase" in the subject line and enough detail for us to find the records. We confirm within 7 days and complete within 30.

Related

Privacy Notice · Security · Data processing terms

Questions about anything on this page: klaritiq@gmail.com. We write these pages ourselves, in plain language, to match what the product actually does; they are not a substitute for legal advice to you.