GenieFolder

Data Retention & Deletion Policy

Last updated: 2026-09-12

This page summarizes how long GenieFolder keeps each category of data and how deletion works. It complements the Privacy Policy.

1. Design principles

  • Local-first: your files are processed on your own device and never uploaded — so there is nothing on our servers to retain or delete.
  • Metadata-only records: job records contain counts, byte sizes, operation settings, status, and timestamps — never file contents, filenames, extracted text, or image pixels.
  • Every stored item has a lifetime: anything we do store has a defined retention period and a documented deletion path below.

2. Retention schedule

DataRetentionHow deletion happens
Files in local (on-device) jobsNever received by us — nothing to retain.Files and results are held in your browser’s memory while you work and are gone when you close or reload the page. The service worker caches only the app itself (never your files); you can clear it in your browser settings.
Files in cloud jobs (inputs & outputs)Cloud processing is not yet available — no user files are currently uploaded to or stored on our servers. Committed schedule for launch: temporary only; auto-deleted within 24 hours of job completion.Will be enforced by automated lifecycle rules on temporary object storage, monitored with alerting on failure.
Job metadata (product, operation, file counts, input/output bytes, settings, status, timestamps)Kept while your account is active so your job history works; deleted or anonymized when your account is deleted.Deleted as part of account deletion (see Section 4).
Account data (email, name, plan state, saved presets)While your account is active, and deleted within 30 days of a verified deletion request. Billing records are kept longer where tax and accounting law requires (up to 7 years).Self-serve account deletion is being rolled out — until then, email info@geniefolder.com from your account address and we will process the deletion.
Email-verification tokensSingle-use; expire 24 hours after issue. Requesting a new link invalidates earlier ones. Only the SHA-256 hash of each token is stored.Automatic expiry; consumed on first use.
Session tokens (gt_access / gt_refresh)Access tokens live about 15 minutes. Refresh tokens live up to 30 days and are rotated on every use; only their SHA-256 hash is stored. Re-using an old (rotated) token revokes all of your sessions as a compromise precaution.Automatic expiry and rotation; signing out or changing your password revokes them immediately.
Team invitation linksExpire 7 days after issue. Only the SHA-256 hash of the invite token is stored; the invitee’s email address is kept with the invite until it is accepted or expires.Automatic expiry.
Cloud-connector OAuth tokens (Google Drive)Refresh tokens are stored encrypted (AES-256-GCM) only while the connector is linked and are deleted immediately when you disconnect. Short-lived access tokens are held in memory only and never persisted.On disconnect we revoke the grant at Google (best effort) and erase the stored token in the same action. A minimal connection record (provider, account email, timestamps) remains in the security audit log below.
Security audit log (sign-ins, connector and billing events, IP address, user agent, error codes)Up to 12 months, then deleted or anonymized.Automated scrubbing excludes anything resembling a password, token, filename, or file content. Records are deleted or anonymized per the schedule above; the purge is currently an operational process (not yet automated), applied when you delete your account or on the 12-month horizon.
Server logsUp to 30 days, then deleted or anonymized.Log rotation.
Billing records (invoices, subscription status)Card data is held by our payment processor (Square), not by us — our servers never see your full card number. Our billing records (Square customer/subscription identifiers, plan, status) are kept for the period required by tax and accounting law (up to 7 years).Deletion at the end of the statutory period.

3. Files in your own connected storage

Outputs you save to your own Google Drive are governed by your account with Google. Disconnecting the connector in GenieFolder revokes and deletes our access tokens as described above but does not delete files already saved in your Drive — they are yours.

4. Requesting deletion

You can exercise deletion and other data rights at any time by emailing info@geniefolder.com from your account address. We respond within 30 days. See the Privacy Policy (Section 7) for the full list of rights.

5. Changes to this policy

Changes will be posted on this page, and registered users will be notified of material changes as described in the Privacy Policy.