Data Retention and Deletion Policy
Effective September 15, 2026 · Version v1.13
Version v1.13 · Effective September 15, 2026 · Published September 15, 2026
Effective September 15, 2026 · Version v1.13
Version v1.13 · Effective September 15, 2026 · Published September 15, 2026
This policy states how long Octicase retains each category of data and how deletion works. It is the version incorporated by reference into the Terms of Service, and the one referenced by the Privacy Policy, the Data Processing Addendum, the Business Associate Agreement, and the consumer-facing terms. An internal operational policy implements this schedule; if the two ever diverge, the version published here is the one customers and users may rely on. For Protected Health Information, the Business Associate Agreement prevails in the event of any conflict.
| Data type | Retention period |
|---|---|
| Customer Data on the platform | Duration of the subscription or, where there is no subscription, of the account (see the Beta row below), plus a thirty (30) day retrieval window after termination. Deletion from active systems within sixty (60) days of termination. |
| Customer Data of a business customer that holds no subscription (a Beta Participant, or any other no-charge access) | For as long as the account is open, plus a thirty (30) day retrieval window after the access ends, whether it ends because the Beta ends, because the Participant leaves it, or because Octicase closes the account. Deletion from active systems within sixty (60) days of that date. During that window the Participant may export through the platform and, whether or not the export function is working, Octicase supplies a copy on request at no charge, as Section 6.2 of the Beta Participation Agreement provides. Where the Participant accepts a subscription after the Beta, the first row applies from the start of that subscription and nothing is deleted in between. For Protected Health Information the Business Associate Agreement governs the return or destruction and the written certification. |
| Consumer intake answers and summary (account holders) | Removed from active systems within thirty (30) days of the request or of account deletion, as the Consumer Terms of Service promise. Subject to the legal exceptions in Section 4. |
| Account and billing information | Duration of the subscription or, where there is no subscription, of the account, plus seven (7) years, for tax and audit purposes. Where no payment method and no billing record exist, as in the Beta, this row covers the account record alone and the seven-year period runs from the closure of the account. |
| Soft-deleted Customer Data | Thirty (30) days, then hard-deleted. |
| Point-in-time recovery backups | Thirty (30) days. |
| Long-term archival backups | Thirteen (13) months, on a rolling cycle. Data removed from live systems is not restored; residual copies inside backup images expire on that cycle and are not accessed or used for any other purpose. Consumer health data is removed from archival backups within six (6) months of a deletion request, ahead of the ordinary cycle. We delete from active systems within thirty (30) days of the request and, from the moment of the request, the data is on the suppression list: no one on our team can reach it and it is used for nothing while the residual copies expire. Where Washington or Nevada law requires the archived copies to be gone sooner, that period applies and this row does not reduce it. |
| Disaster-recovery replica (secondary cloud), when that replication is in operation; none exists today | Thirty (30) days. |
| Audit logs | Six (6) years, consistent with 45 CFR 164.316(b)(2). |
| Incident and breach records | Six (6) years, including the assessment, the determination, the notifications made, and any decision not to notify with its reasoning (45 CFR 164.414(b), 164.530(j)). |
| Authentication and security logs | Six (6) years, aligned with audit logs, so that what happened can still be demonstrated if a breach is discovered late. |
| Protected Health Information (PHI) | As set out in the Business Associate Agreement. On termination, PHI is returned or destroyed in accordance with that agreement, with written certification. |
| Call recordings and transcripts (where Octicase is the controller) | Seven (7) years where the call relates to a matter; ninety (90) days where it did not become one. Where a recording is a firm's Customer Data, the firm's instructions and the Data Processing Addendum govern. Where the speaker is a consumer using the consumer services, the consumer row of this schedule prevails and the period is thirty (30) days; the seven-year period applies only to recordings made in a firm's matter. |
| Marketing data | Until the individual opts out, or three (3) years after last engagement, whichever is earlier. |
| Payment card data | Octicase does not store full card numbers or security codes. The processor's token, the card brand and the last four digits are retained for the billing relationship plus the tax and audit period. |
| Deletion-request records | Six (6) years, for accountability (45 CFR 164.316(b)(2)). |
| Consumer intake answers, summary and uploads (documents, images, audio, video) without an active account | Thirty (30) days from submission, then deleted from active systems, as Section 8.3 of the Consumer Terms of Service provides. That deletion is not automated today: until the automated schedule is in place Octicase runs it by hand, so thirty (30) days is the period we work to, a given deletion may complete after that date and none happens sooner. The notice and the extension are offered once that schedule is running: where the consumer has given us an email address or phone number that we have not been asked to stop using, we tell the consumer seven days before the first period ends, and the consumer may then create an account, or extend the period once by a further thirty (30) days, to keep the material. Before that, a consumer may ask for deletion at any time and we do it. Subject to the legal exceptions in Section 4. |
| Consumer account record (name, contact details, acceptance records) | Until the consumer deletes the account or asks for deletion, then removed from active systems within thirty (30) days, as the Consumer Terms of Service promise. An account with no sign-in for twenty-four (24) months is treated as inactive: we tell the consumer at least thirty (30) days beforehand, and if there is no response the account and its contents are deleted as this schedule provides. |
| Aggregated intake statistics (aggregate consumer information: counts by type of situation, county and month, written at intake with no record-level identifier) | Retained indefinitely. These counters are aggregate consumer information within the meaning of Cal. Civ. Code Section 1798.140(b), not personal information: they cannot be linked to any person, household, device or account and are not subject to deletion requests. They are published or licensed only where each cell covers at least ten people; smaller cells are suppressed or merged before any use outside Octicase. No counter is written for an intake completed through the guardian flow for a person under eighteen. |
| Platform Engagement transaction records, invoices and receipts | Seven (7) years after the later of the end of the customer's subscription and the end of the seller's agreement with Octicase, for tax and audit purposes. Exportable by the customer under Section 7.5 of the Terms of Service during the subscription and the retrieval window, and by the seller for ninety (90) days after its agreement ends, as the Expert and Consultant Services Agreement or the Partner Agreement provides. The row includes time and service records of a partner's continuing service, and the Firm's attestations, location requests and license-verification records under Section 3.1 of the Partner Agreement, kept for the same period. |
| Platform Engagement deliverables and messages exchanged inside an engagement | Customer Data of the engaging customer, retained and deleted as the first row provides, and in every case accessible to the customer for at least thirty (30) days after delivery or cancellation, as Section 4.16 of the Terms of Service provides. The seller may export its own engagement records for ninety (90) days after its agreement with Octicase ends, to the extent the engaging customer has not deleted them and, for Protected Health Information, subject to the destruction period of the Business Associate Agreement. |
| Access and transfer records for matters shared or transferred between customers (who granted, accepted, changed and revoked access, and when) | Six (6) years, aligned with audit logs. Exportable by each customer that is a party to the sharing or transfer, during its subscription and retrieval window; as an audit record, not deleted on either customer's instruction. |
| Portal inquiries between customers and listed professionals that did not become an engagement | Ninety (90) days after the last message in the thread, then deleted from active systems. Messages inside an engagement follow the deliverables row above. Subject to Section 4. |
| Directory listing data entered by a professional | For as long as the listing exists. On closure or on the professional's request, removed from the Directory within five (5) business days and deleted from active systems within forty-five (45) days of the request, except the engagement and transaction records above and a suppression record. |
| Unclaimed (pre-loaded) directory profiles | Until claimed or removed. Refreshed at each update of the public or licensed source; removed from the Directory within five (5) business days of the professional's objection, and deleted from active systems within thirty (30) days after the license for the source ends or after the objection, keeping only a suppression record. |
| Suppression records (do-not-contact, opt-out and removed-listing records) and records of consent to be contacted | Do-not-contact and opt-out records: at least five (5) years from the request, as 47 CFR 64.1200(d)(6) requires, and for as long as necessary to honor it afterward; they contain only what is needed to recognize the person, number, address or listing. Records of consent to be contacted: five (5) years after the last message sent under that consent. Removed-listing suppression records: for as long as the listing could otherwise be re-created from a public or licensed source. |
| Mailbox and calendar content synchronized but not matched to a matter | Deleted within thirty (30) days of the customer revoking the connection, as Section 4.15 of the Terms of Service provides. Content matched to a matter is Customer Data and follows the first row. |
| Phone numbers used for SMS two-factor authentication | Removed from authentication records within thirty (30) days of the user disabling SMS two-factor authentication, as the Privacy Policy provides; a number that is also used for another purpose follows the period for that purpose. |
| Data an Unverified Customer holds for a law firm it has identified | The firm's data. When either the Unverified Customer's account or the firm's account ends, the identified firm, not the Unverified Customer, has the thirty (30) day retrieval window and gives the instruction to return or delete; deletion from active systems within sixty (60) days of the termination of the account that ended, as the first row provides. |
| Octicase's own compliance documentation (prior versions of this policy and of the published legal documents, Business Associate Agreements, Data Processing Addenda, risk analyses, training records) | Six (6) years from the date of its creation or the date when it last was in effect, whichever is later (45 CFR 164.316(b)(2), 164.530(j)(2)), so that what applied at any time can be demonstrated. |
| Link recipients (name, phone and verified email of a person who registers to view a link a consumer or a Customer sent through the Services, and the access trace) | Six (6) years, aligned with audit logs, as an access record; the content of the link follows the row for the data it belongs to. This row does not cover which videos a person watched or was sent, which follows the Video library viewing records row and is destroyed within one (1) year. |
| Forum posts and answers to consumer questions (where those features are offered) | A professional's forum post: life of the forum account plus one (1) year. An answer to a consumer's question: at least one (1) year after posting, with the attorney's name and date, as the Acceptable Use Policy provides; a copy is given to the attorney on request. |
| Consumer case-level records (the facts of a situation under an identifier that is not a name, kept only where the consumer gave separate permission on a screen of its own) | Kept while that permission stands and in no case longer than twenty-four (24) months, after which the consumer is asked again. Deleted when the consumer asks, including from long-term archival backups within six (6) months of the request. None is kept for anyone under eighteen. Video-viewing history is never part of it. This is personal information, not de-identified data. It is not sold or licensed today, and could be sold or licensed only under the separate signed authorization described in Section 3A of the Consumer Health Data Privacy Policy and Section 4.8(g) of the Privacy Policy, which expires after one year and may be withdrawn at any time; a withdrawal or an expiry ends the sale and the buyer deletes what it holds. |
| Platform usage data (Section 7.3A of the Terms of Service) | Retained indefinitely. It carries no matter content; free text a user entered is removed before an event becomes usage data, and anything relating to an identifiable natural person is de-identified before use. Published or licensed only in aggregate, with a minimum cell of ten customers and ten individuals. Not subject to export, and not subject to access or deletion requests once it is de-identified, because de-identified usage data is not personal information. An event that still relates to an identifiable natural person is personal information until it is de-identified: until then the Privacy Policy governs it and the access and deletion rights it describes apply, as Section 7.3A of the Terms of Service provides. |
| Video library viewing records (which videos a person watched, and which video link was sent to whom) | Destroyed as soon as practicable, and in no case later than one (1) year after the date the information is no longer necessary for the purpose for which it was collected (18 U.S.C. Section 2710(e)). Not disclosed to anyone other than the person concerned without that person's written consent (Cal. Civ. Code Section 1799.3). Never reported to a law firm, never included in aggregated statistics or in case-level records, and never sold or licensed. |
| Records of a customer's or consumer's agreement to model training, and of its withdrawal (who gave it, which version of the text was shown, when, and from where) | Six (6) years after the agreement ends, so that the basis for every use can be shown. Exportable by the customer at any time. |
| Signed authorizations to sell consumer health data, and refusals and withdrawals of one (who answered, which version of the document was shown, when, from where, the buyer named, and the expiry date the system printed) | Six (6) years counted from the latest of the date of signature, the date of any withdrawal and the expiry date printed on the authorization, a formula that satisfies the Washington period of RCW 19.373.070(5) and the Nevada one, which run from different dates. This row governs the authorization and prevails over the row for signed documents and the electronic-signature trail, which does not cover it. Kept whether the authorization was given, refused or withdrawn, because it is the proof of the basis on which a sale was or was not made. The signed authorization carries the person's name and signature and is held as the signed record it is; the case record it covers is held under a pseudonymous identifier, and Octicase does not link the two except where a court or a regulator requires it. Not deleted on a deletion request; the record of the situation that the authorization covered is deleted as the row above provides. |
| Signed authorizations to share medical information with a person the consumer chose, and refusals and withdrawals of one (who signed, which version of the document was shown, when, from where, the recipient named, the items covered, the purpose and the expiry date the system printed) | Six (6) years counted from the latest of the date of signature, the date of any withdrawal and the expiry date printed on the authorization, aligned with audit logs and with the row above for authorizations to sell. Kept whether the authorization was given, refused or withdrawn, because it is the proof of the basis on which a disclosure was or was not made. Not deleted on a deletion request; the information the authorization covered is deleted as the rows for that information provide. |
| Client trust accounting records (Section 4.12 of the Terms of Service) | Five (5) years after the final distribution of the funds concerned, consistent with California Rule of Professional Conduct 1.15(d)(3). The firm remains responsible for keeping its own records; ours are a copy, not the firm's book of account. |
| Verification records (professional license and identity checks, seller onboarding, and payout and tax status) | Six (6) years after the account closes, aligned with audit logs. |
| Signed documents and the electronic-signature trail (who signed, which version, when, and from what address) | Seven (7) years after the document ceases to be in effect, consistent with the ESIGN/UETA Consent and Disclosure. |
| Review moderation records (the review, the decision, the provision relied on, the reason and who decided it, and any appeal) | Six (6) years, aligned with audit logs, and produced to a regulator on request, as the Review Moderation Policy provides. |
| Refusals of a permission, and withdrawals (who answered, which version of the text was shown, when, and from where) | Six (6) years, on the same terms as the record of a permission given, so that we can show what was asked and what was answered. Held under a pseudonymous identifier and used for nothing but that proof. |
| Prepaid credit balances: the record of purchase, amount, age and use | Seven (7) years after the balance reaches zero or is refunded, so that unclaimed-property obligations can be met and evidenced. |
For business customers: on termination, you have thirty (30) days to export your data through the export function; we notify you before deletion begins; and we delete from active production systems within sixty (60) days, returning the data instead where you elect return. Completion is certified to you in writing — for PHI, unconditionally, as Section 12 of the Business Associate Agreement requires.
For consumers: you can delete individual records in the product, or your whole account at any time; removal from active systems happens within thirty (30) days. If you use the consumer service without an account, your intake answers, your summary and the documents, images, audio and video you uploaded are deleted from active systems thirty (30) days after submission, as the Consumer Terms of Service state. That deletion is run by hand until the automatic process is in place, so thirty (30) days is the period we work to, it may complete after that date and it never happens sooner. Once that process is running, and where you have given us an email address or phone number that you have not asked us to stop using, we will tell you seven days before the first period ends, and you will then be able to create an account, or extend the period once by a further thirty (30) days, to keep them; the extension may be taken only once. Until then you can ask us to delete this material at any time and we do it. What remains after that deletion is the aggregated statistics described in the schedule, which carry no identifier, and, only where you gave the separate permission described in the Privacy Policy, the case-level record, which we delete when you ask; if you created an account instead, your data follows the account-holder rows of the schedule.
Backups are not edited record by record. When you ask us to delete, we remove the data from active systems and add it to a suppression list at once: from that moment no one on our team can reach it, it is used for nothing, and it never re-enters a model, a statistic or a data product. If we ever had to restore a backup, we apply the suppression list before the system returns to service. For consumer health data and for case-level records, the residual copies are gone no later than six (6) months after your request, ahead of the ordinary cycle. Deletion from active systems does not immediately erase encrypted backups; residual copies expire on the rolling cycle in the schedule above, are never restored, and are not used for any purpose in the meantime. This is stated plainly because a promise to erase data instantly from every backup would not be accurate.
Where deletion is not required, de-identification may be used as an alternative where the applicable standard is met (45 CFR 164.514(b) for health information). Octicase does not attempt to re-identify de-identified data and does not permit any subcontractor to do so. Aggregated data and de-identified data that Octicase creates under the license in the Terms of Service are not Customer Data, are not subject to return, deletion or export, and survive the deletion of the data they were derived from; the method of de-identification, the minimum-cell rule for aggregate data and the commitment not to re-identify are published in the Privacy Policy.
Subcontractors that process Customer Data or PHI under a written agreement with Octicase retain it no longer than necessary to perform the service — for AI sub-processors, no longer than necessary to return the output and meet their own abuse-monitoring obligations. Where a provider holds content on its own retention terms rather than ours, the Subprocessor List says so and names the control that is missing; the inbound email route is recorded there today. On termination of a subcontractor relationship we obtain confirmation of return or destruction and, for PHI, certification in writing.
Data is retained beyond the periods above only where retention is required by law, or where the data is subject to a litigation hold, a preservation obligation, an ongoing incident investigation, or compulsory legal process. Held data is retained for the matter identified and no more, and is deleted once the obligation ends. A deletion request does not extend to records the law requires us to keep — such as billing and tax records — and where a request is honored in part for that reason, we tell you which categories were retained and why. A consumer's statutory deletion rights are unaffected except as to the specific material identified in a hold.
Consumers: delete records or your account from the product, or contact support@octicase.com; statutory privacy requests go to privacy@octicase.com as Section 8 of the Privacy Policy describes. An active contract is not a ground for refusing a statutory deletion right.
Business customers: deletion and return are governed by Section 4.7 of the Data Processing Addendum and, for PHI, Section 12 of the Business Associate Agreement. Where deletion during an active subscription would disrupt the Services, we confirm the request with your administrator before executing it. Data that an Unverified Customer holds for a law firm it has identified is the firm's data; the firm's instructions govern its deletion and return, and the retrieval window on termination belongs to the firm, as the schedule provides.
Individuals whose information a firm placed on the platform: contact that firm first — it controls the data, and we assist it as the Privacy Policy describes.
We update this policy when retention periods change. A change that shortens a period we have promised, or otherwise reduces your rights, is announced before it takes effect, and prior versions remain available. The schedule above is the single source of truth for retention periods across our public documents; a period stated elsewhere is a restatement of this schedule, not a separate commitment, except that where another document states a longer or different period to your benefit, that period applies.
-- END OF DATA RETENTION AND DELETION POLICY --