Technical disclosure · Retention

Each data class has its own lifecycle.

This table lists product retention that the current service declares and enforces. It does not cover legal records, invoices, support correspondence, fraud evidence, or data that a customer copies to an external destination. Those classes need separate legal retention rules.

Published product retention

Data classRetentionScope
Runtime logs7 daysApplication and platform lines are pruned by timestamp.
Audit entries90 daysOrganization write operations only; successful and failed writes are included.
Raw platform metrics30 daysOne-minute project and database series.
Hourly platform metrics13 monthsHourly aggregates for longer trend queries.
Web analyticsUp to 90 daysReports exclude cookies, raw IP addresses, query strings, fragments, and full referrer URLs.
Speed Insights raw points30 daysThe collector excludes cookies, user IDs, IP fields, full URLs, referrers, fingerprints, and DOM selectors.
Public onboarding observations30 daysClosed event names and bounded properties from installer and CLI flows.
Authoritative onboarding lifecycle evidence180 daysTrusted billing, deployment, and agent-connection lifecycle edges.
Queue payload cleanup ceiling15 daysConfigured queue retention is at most 14 days; the extra day covers abandoned payload cleanup.
Managed database exports7-day normal maximumOrphaned export objects have a 15-day lifecycle cleanup ceiling.

Database backups

Backup retention is policy-driven, not one fixed period. A database declares point-in-time days, daily days, weekly weeks, and monthly months. Manual and regional points can have their own expiry. After database deletion, access is revoked first; managed backups remain until the longest configured retention ends and are then purged by the durable deletion workflow.

Customer-controlled copies

Deleting a Korve export record does not delete a copy already written to a customer-owned destination. The customer controls that destination's access, retention, backup, and deletion policy. A signed URL or one-use download path is a transfer control, not a promise that a downloaded copy will later disappear.

Deletion boundary

Resource deletion and retention expiry are different events. Some active access can end before retained recovery data expires. Runtime logs can remain until their seven-day timestamp prune. Audit history can remain for its 90-day product window. This page does not claim instant erasure or a complete user-account deletion service.