---
isPublished: true
template: "page.peb"
title: "Data Retention Policy"
displayName: "Data Retention Policy"
description: "Public data retention principles for files, generated artifacts, transcripts, knowledge, logs, provider state, and financial records."
category: "trust"
contentType: "policy"
audience: "end-user"
tags: "trust,policy,data-retention,deletion,transcripts"
section: "trust"
effectiveDate: "2026-05-22"
lastReviewed: "2026-05-22"
owner: "Security and Privacy"
contact: "support@idialogue.app"
seoTitle: "iDialogue Data Retention Policy"
seoDescription: "Understand how Pacific Apps distinguishes retention for customer content, provider state, transcripts, knowledge, logs, and financial records."
---

## Data Retention Policy

**Effective date:** May 22, 2026  
**Last reviewed:** May 22, 2026  
**Policy owner:** Security and Privacy  
**Entity:** Pacific Apps, Inc., provider of iDialogue  
**Contact:** [support@idialogue.app](mailto:support@idialogue.app)

<h2 id="purpose">Purpose</h2>

This policy establishes requirements for retaining and deleting data used to provide iDialogue. Retention is determined by data class, product feature, customer agreement, provider configuration, and applicable operational, legal, and financial requirements.

<h2 id="retention-principles">Retention principles</h2>

- Retain data only for a defined service, security, contractual, financial, or legal purpose.
- Determine retention based on the applicable data class, feature, customer agreement, and provider configuration.
- Restrict access to retained data according to role and operational need.
- Support verified customer deletion and export requests within contractual, legal, and technical boundaries.
- Document retention exceptions, including legal holds, security investigations, fraud prevention, disputes, backups, tax, and financial records.

<h2 id="data-classes">Data classes</h2>

| Data class | Retention and lifecycle considerations |
| --- | --- |
| Salesforce request context | Processed for the requested action and may also be recorded in provider state, transcripts, or operational logs depending on the workflow |
| Source files | Retained only when required by the selected workflow for processing, retrieval, Rooms, knowledge, support, or other configured functionality |
| Generated artifacts | Retained while needed for delivery, retrieval, signature, sharing, publication, or contractual obligations |
| Agent transcripts and tool details | Retained for threaded continuity, review, support, usage reconciliation, and other agreed purposes |
| Memory and indexed knowledge | Retained while the relevant feature, source, or customer account remains active, subject to applicable deletion workflows and contract terms |
| Operational and security logs | Retained according to incident response, reliability, fraud-prevention, legal, and provider requirements |
| Billing and credit records | Retained for accounting, tax, dispute, audit, and contractual requirements |
| Provider application state | Governed by the applicable provider endpoint, request setting, provider account, and provider contract |
| Backups | Expire according to the applicable backup lifecycle and recovery design rather than immediate deletion from every backup copy |

<h2 id="openai-retention">OpenAI request state</h2>

Current reviewed iDialogue Responses API workflows use <code>store=true</code> where stored state is required for threaded conversations, background continuation, and file-processing workflows.

OpenAI's current official documentation states that stored Responses application state is retained for at least 30 days. Other OpenAI endpoints and data classes, including uploaded files, conversations, abuse-monitoring logs, fine-tuning data, and optional sharing programs, may have different retention behavior.

This provider retention does not establish a universal iDialogue retention period. A customer-provided OpenAI API key also does not automatically change the request-level <code>store</code> setting.

See OpenAI's official [endpoint-specific data controls](https://developers.openai.com/api/docs/guides/your-data#default-usage-policies-by-endpoint).

<h2 id="customer-lifecycle">Account and service lifecycle</h2>

Retention requirements can change when a feature is disabled, a customer account is terminated, or a verified deletion request is received. Data that is no longer required for an active service purpose is subject to the applicable deletion process.

Legal obligations, security investigations, unresolved disputes, active sharing workflows, provider state, backups, and financial records may require separate treatment.

<h2 id="deletion-process">Deletion process</h2>

A verified deletion request may require coordinated action across:

1. the source Salesforce record or File;
2. iDialogue application or transcript state;
3. generated artifacts, Rooms, memory, or indexed knowledge;
4. provider application state or uploaded files;
5. operational and security logs; and
6. backups and financial records.

Pacific Apps validates the requestor's authorization, identifies in-scope systems and data classes, records applicable exceptions, performs or schedules supported deletion, and communicates material limitations.

Immediate physical removal from every backup is not guaranteed. Deleted data may remain in protected backup media until the applicable backup expires or is overwritten.

<h2 id="review-and-exceptions">Review and exceptions</h2>

New features and processing providers must identify the data classes they create or receive, the processing purpose, expected lifecycle, deletion method, and responsible owner before production use.

Exceptions require documented justification, approval, compensating controls where applicable, and periodic reassessment.

## Related information

- [Security &amp; Data Handling: Data lifecycle](/trust/security-data-handling.html#data-lifecycle)
- [Privacy &amp; Data Protection Policy](/trust/compliance/privacy-data-protection.html)
- [Privacy Policy](/legal/privacy.html)