SiteMinutes · Legal
Data Retention & Deletion Policy
Version 1.0Effective 25 September 2026Draft
Contents
Draft — to be reviewed by a qualified legal practitioner before publication.
Version 1.0 · Effective 25 September 2026
This policy sets out how long SiteMinutes keeps information and how it is deleted. It forms part of the Terms of Service and the Data Processing Addendum.
1. Principles
- Your files stay with you. SiteMinutes is local-first: recordings, photos and working files are kept on your own devices. The apps never delete a recording by themselves, and deleted photos and plans go to a Trash folder on the device, not straight to oblivion.
- Keep only what is needed. Temporary copies (such as the audio uploaded for transcription) are deleted as soon as their job is done.
- Never delete for non-payment in a hurry. A workspace that stops paying becomes read-only; its data is kept for at least 12 months.
- Deletion is deliberate. Items you delete in the app are first marked as deleted ("soft delete") so mistakes can be undone, and are purged later.
2. Retention periods
| Information | Where | Kept for |
|---|---|---|
| Audio recordings (originals) | Your device (and, once sync to your own cloud is available, your own storage) | Under your control. SiteMinutes never deletes them |
| Temporary audio copy for transcription | SiteMinutes storage (Frankfurt) | Deleted as soon as the minutes are written; an automatic daily clean-up removes any copy older than 7 days |
| Photos | Your device | Under your control (not uploaded in the current version) |
| Transcripts, minutes, minutes review chat | SiteMinutes database | While the workspace exists (see sections 3–5) |
| Projects, meetings, attendance, actions, contract instructions, snags | SiteMinutes database and your devices | While the workspace exists |
| Plans and documents uploaded to a project | SiteMinutes project storage | While the workspace exists |
| Items you delete (soft-deleted records) | SiteMinutes database | Purged 30 days after deletion |
| Account information (name, e-mail, role) | SiteMinutes database | While the account exists; deleted or anonymised within 90 days after the account is closed |
| Pending invitations | SiteMinutes database | Until accepted or withdrawn; expired invitations removed after 90 days |
| Billing and payment records (no card numbers) | SiteMinutes database | 7 years after the end of the financial year they relate to (tax and company law) |
| Payment gateway callback logs | SiteMinutes database | 7 years, as billing records |
| Support tickets and messages | SiteMinutes database | 3 years after the ticket is closed |
| Help assistant conversations | Your browser or app only | Not stored by our server (unless you attach them to a support ticket) |
| Help assistant fair-use counter | SiteMinutes database | 1 hour |
| AI usage records (no content) | SiteMinutes database | 3 years, for cost and abuse control |
| Legal acceptance records | SiteMinutes database | For the life of the account plus 7 years |
| Technical and security logs | Hosting providers | For the short period set by the provider (normally no more than 30 days) |
| Database backups | Supabase | Daily backups, rolling off after 7 days |
| Data at AI providers | OpenAI / Anthropic | OpenAI's transcription endpoint keeps no copy; Anthropic deletes API inputs and outputs within 30 days (up to 2 years if flagged for a usage-policy violation) |
3. When a trial ends without a subscription
The workspace becomes read-only straight away: you can view and export everything, but not create new minutes or invite users. We keep the data for 6 months. Before deleting it, we e-mail the owner at least 30 days in advance. Subscribing at any time before that restores full access.
4. When a paid plan lapses (non-payment or cancellation)
- A failed or missing payment gives a 3-day grace period with full access.
- After that, the workspace becomes read-only. Nobody is removed, and export keeps working.
- The data is kept for at least 12 months after the workspace became read-only.
- After 12 months we may delete the workspace, but only after e-mailing the billing owner and owners at least 30 days in advance, with a link to export.
- Paying again at any time before deletion restores the workspace exactly as it was.
5. Closing a workspace or an account on request
- The owner can ask us to close a company workspace. We confirm the request with the owner, give 30 days to export, then delete the workspace's content from our live systems within a further 30 days. Backups roll off within 7 days after that.
- A user can ask us to close their personal account. Records they created in a company workspace belong to the company and stay with it; the user's own account information is deleted or anonymised within 90 days.
- Billing records and legal acceptance records are kept for the periods in section 2 even after closure, because the law requires it.
6. Export
While an account exists, including while it is read-only, owners and members can export:
- minutes as A4 PDF;
- meeting packs (.zip with audio, photos, plans with pins, registers and transcript) from the apps; and
- minutes from the web app (print or save as PDF).
Ask support if you need a complete machine-readable export of a workspace; we will provide it within 30 days.
7. Requests from meeting participants
A person recorded or named in a meeting may ask for their information to be corrected or deleted. We refer the request to the customer that owns the meeting (the responsible party), who decides, because minutes may need to be kept as a true record (for example under a building contract). We help the customer carry out its decision.
8. Legal holds
We may keep information for longer than stated above where we are legally required to, or where it is needed to establish, exercise or defend a legal claim. We will delete it once the hold ends.
9. How deletion works
Deletion removes the information from our live database and storage. Copies in backups are overwritten as the backups roll off (within 7 days). Deleted information cannot be recovered after that.