All policies

SiteMinutes · Legal

Data Retention & Deletion Policy

Version 1.0Effective 25 September 2026Draft

Contents
  1. 1. Principles
  2. 2. Retention periods
  3. 3. When a trial ends without a subscription
  4. 4. When a paid plan lapses (non-payment or cancellation)
  5. 5. Closing a workspace or an account on request
  6. 6. Export
  7. 7. Requests from meeting participants
  8. 8. Legal holds
  9. 9. How deletion works

Draft — to be reviewed by a qualified legal practitioner before publication.

Version 1.0 · Effective 25 September 2026

This policy sets out how long SiteMinutes keeps information and how it is deleted. It forms part of the Terms of Service and the Data Processing Addendum.

1. Principles

  • Your files stay with you. SiteMinutes is local-first: recordings, photos and working files are kept on your own devices. The apps never delete a recording by themselves, and deleted photos and plans go to a Trash folder on the device, not straight to oblivion.
  • Keep only what is needed. Temporary copies (such as the audio uploaded for transcription) are deleted as soon as their job is done.
  • Never delete for non-payment in a hurry. A workspace that stops paying becomes read-only; its data is kept for at least 12 months.
  • Deletion is deliberate. Items you delete in the app are first marked as deleted ("soft delete") so mistakes can be undone, and are purged later.

2. Retention periods

InformationWhereKept for
Audio recordings (originals)Your device (and, once sync to your own cloud is available, your own storage)Under your control. SiteMinutes never deletes them
Temporary audio copy for transcriptionSiteMinutes storage (Frankfurt)Deleted as soon as the minutes are written; an automatic daily clean-up removes any copy older than 7 days
PhotosYour deviceUnder your control (not uploaded in the current version)
Transcripts, minutes, minutes review chatSiteMinutes databaseWhile the workspace exists (see sections 3–5)
Projects, meetings, attendance, actions, contract instructions, snagsSiteMinutes database and your devicesWhile the workspace exists
Plans and documents uploaded to a projectSiteMinutes project storageWhile the workspace exists
Items you delete (soft-deleted records)SiteMinutes databasePurged 30 days after deletion
Account information (name, e-mail, role)SiteMinutes databaseWhile the account exists; deleted or anonymised within 90 days after the account is closed
Pending invitationsSiteMinutes databaseUntil accepted or withdrawn; expired invitations removed after 90 days
Billing and payment records (no card numbers)SiteMinutes database7 years after the end of the financial year they relate to (tax and company law)
Payment gateway callback logsSiteMinutes database7 years, as billing records
Support tickets and messagesSiteMinutes database3 years after the ticket is closed
Help assistant conversationsYour browser or app onlyNot stored by our server (unless you attach them to a support ticket)
Help assistant fair-use counterSiteMinutes database1 hour
AI usage records (no content)SiteMinutes database3 years, for cost and abuse control
Legal acceptance recordsSiteMinutes databaseFor the life of the account plus 7 years
Technical and security logsHosting providersFor the short period set by the provider (normally no more than 30 days)
Database backupsSupabaseDaily backups, rolling off after 7 days
Data at AI providersOpenAI / AnthropicOpenAI's transcription endpoint keeps no copy; Anthropic deletes API inputs and outputs within 30 days (up to 2 years if flagged for a usage-policy violation)

3. When a trial ends without a subscription

The workspace becomes read-only straight away: you can view and export everything, but not create new minutes or invite users. We keep the data for 6 months. Before deleting it, we e-mail the owner at least 30 days in advance. Subscribing at any time before that restores full access.

4. When a paid plan lapses (non-payment or cancellation)

  1. A failed or missing payment gives a 3-day grace period with full access.
  2. After that, the workspace becomes read-only. Nobody is removed, and export keeps working.
  3. The data is kept for at least 12 months after the workspace became read-only.
  4. After 12 months we may delete the workspace, but only after e-mailing the billing owner and owners at least 30 days in advance, with a link to export.
  5. Paying again at any time before deletion restores the workspace exactly as it was.

5. Closing a workspace or an account on request

  • The owner can ask us to close a company workspace. We confirm the request with the owner, give 30 days to export, then delete the workspace's content from our live systems within a further 30 days. Backups roll off within 7 days after that.
  • A user can ask us to close their personal account. Records they created in a company workspace belong to the company and stay with it; the user's own account information is deleted or anonymised within 90 days.
  • Billing records and legal acceptance records are kept for the periods in section 2 even after closure, because the law requires it.

6. Export

While an account exists, including while it is read-only, owners and members can export:

  • minutes as A4 PDF;
  • meeting packs (.zip with audio, photos, plans with pins, registers and transcript) from the apps; and
  • minutes from the web app (print or save as PDF).

Ask support if you need a complete machine-readable export of a workspace; we will provide it within 30 days.

7. Requests from meeting participants

A person recorded or named in a meeting may ask for their information to be corrected or deleted. We refer the request to the customer that owns the meeting (the responsible party), who decides, because minutes may need to be kept as a true record (for example under a building contract). We help the customer carry out its decision.

We may keep information for longer than stated above where we are legally required to, or where it is needed to establish, exercise or defend a legal claim. We will delete it once the hold ends.

9. How deletion works

Deletion removes the information from our live database and storage. Copies in backups are overwritten as the backups roll off (within 7 days). Deleted information cannot be recovered after that.