Data Retention Policy

Data Retention Policy

Effective date: May 22, 2026
Last reviewed: May 22, 2026
Policy owner: Security and Privacy
Entity: Pacific Apps, Inc., provider of iDialogue
Contact: support@idialogue.app

Purpose

This policy establishes requirements for retaining and deleting data used to provide iDialogue. Retention is determined by data class, product feature, customer agreement, provider configuration, and applicable operational, legal, and financial requirements.

Retention principles

  • Retain data only for a defined service, security, contractual, financial, or legal purpose.
  • Determine retention based on the applicable data class, feature, customer agreement, and provider configuration.
  • Restrict access to retained data according to role and operational need.
  • Support verified customer deletion and export requests within contractual, legal, and technical boundaries.
  • Document retention exceptions, including legal holds, security investigations, fraud prevention, disputes, backups, tax, and financial records.

Data classes

Data class Retention and lifecycle considerations
Salesforce request context Processed for the requested action and may also be recorded in provider state, transcripts, or operational logs depending on the workflow
Source files Retained only when required by the selected workflow for processing, retrieval, Rooms, knowledge, support, or other configured functionality
Generated artifacts Retained while needed for delivery, retrieval, signature, sharing, publication, or contractual obligations
Agent transcripts and tool details Retained for threaded continuity, review, support, usage reconciliation, and other agreed purposes
Memory and indexed knowledge Retained while the relevant feature, source, or customer account remains active, subject to applicable deletion workflows and contract terms
Operational and security logs Retained according to incident response, reliability, fraud-prevention, legal, and provider requirements
Billing and credit records Retained for accounting, tax, dispute, audit, and contractual requirements
Provider application state Governed by the applicable provider endpoint, request setting, provider account, and provider contract
Backups Expire according to the applicable backup lifecycle and recovery design rather than immediate deletion from every backup copy

OpenAI request state

Current reviewed iDialogue Responses API workflows use store=true where stored state is required for threaded conversations, background continuation, and file-processing workflows.

OpenAI's current official documentation states that stored Responses application state is retained for at least 30 days. Other OpenAI endpoints and data classes, including uploaded files, conversations, abuse-monitoring logs, fine-tuning data, and optional sharing programs, may have different retention behavior.

This provider retention does not establish a universal iDialogue retention period. A customer-provided OpenAI API key also does not automatically change the request-level store setting.

See OpenAI's official endpoint-specific data controls.

Account and service lifecycle

Retention requirements can change when a feature is disabled, a customer account is terminated, or a verified deletion request is received. Data that is no longer required for an active service purpose is subject to the applicable deletion process.

Legal obligations, security investigations, unresolved disputes, active sharing workflows, provider state, backups, and financial records may require separate treatment.

Deletion process

A verified deletion request may require coordinated action across:

  1. the source Salesforce record or File;
  2. iDialogue application or transcript state;
  3. generated artifacts, Rooms, memory, or indexed knowledge;
  4. provider application state or uploaded files;
  5. operational and security logs; and
  6. backups and financial records.

Pacific Apps validates the requestor's authorization, identifies in-scope systems and data classes, records applicable exceptions, performs or schedules supported deletion, and communicates material limitations.

Immediate physical removal from every backup is not guaranteed. Deleted data may remain in protected backup media until the applicable backup expires or is overwritten.

Review and exceptions

New features and processing providers must identify the data classes they create or receive, the processing purpose, expected lifecycle, deletion method, and responsible owner before production use.

Exceptions require documented justification, approval, compensating controls where applicable, and periodic reassessment.

Related information

Generated 2026-08-11T02:58:43.359063Z
iDialogue Agent

Ask about this page, related knowledge or specific iDialogue product and support features.