Retention schedule
Retention Schedule
- Version:
- Oct 8, 2026
- Effective:
Canonical URL: /legal/retention-schedule/2026-10-08
This schedule explains how long we keep information and when we delete it. It supports the Privacy Policy and Data Processing Addendum. The DPA and any earlier legal deadline take priority over this schedule.
1. Account closure and deletion
Canceling a paid subscription does not close your account. The table below explains the retention rules for each type of information. Section 6 of the DPA explains the process and deadlines for covered return and deletion requests.
2. Retention by record type
| Information | How long we keep it | When it is deleted or no longer used |
|---|---|---|
| Documents in your browser, Word, device, or storage you or your organization control | Controlled by you, your browser, or your storage provider | Delete these copies through those systems. Closing your Hemingway account does not erase them |
| Text processed by AI generation, analysis, and classification features | For processing the request and returning the result | Provider copies follow section 4 |
| Saved custom style guides and prompt instructions | While your account or organization remains active, unless you delete the saved guide or instructions | Eligible live copies are deleted within 30 calendar days of a valid removal/deletion instruction or the end of the relevant processing, subject to earlier duties and the DPA's return and backup rules |
| Account, organization, membership, identity, usage/credit, and subscription-service records, including relevant WorkOS records | While needed for the account or another disclosed lawful purpose | Eligible live records are deleted within 30 calendar days of a valid deletion instruction or the end of the relevant processing, subject to earlier duties and the DPA's return and backup rules. Separately retained business records follow the rules below |
| Sign-in tokens and credentials, including relevant authentication-provider copies | While the connection or account remains active and the credentials are needed | Revoke promptly when the connection or account ends; delete eligible live token copies within 1 calendar day, under the DPA's credential and backup safeguards |
| Render runtime logs | Up to 14 days | Expire on that cycle. A separately justified incident record follows section 3 |
| Render-managed PostgreSQL recovery and logical backups | Point-in-time recovery covers the previous 7 days. Logical exports retained by Render expire 7 days after creation. | Expire on the applicable backup cycle, measured independently of deletion in the live database. Restored records are subject to section 3 |
| Mixpanel usage events and user profiles | While reasonably needed for the disclosed, permitted analytics purpose; some records may remain after account closure | Delete or properly deidentify when no longer needed; no single account-closure deadline applies to all analytics history |
| Sentry error and issue reports | Error events: 90 days. An issue remains while it has retained associated events; event-data backups expire 90 days after their creation | Individual events expire on their retention cycle, and issues are deleted when all associated events are deleted, without routine per-user deletion |
| Front support and billing correspondence | Indefinitely as business correspondence, including after the case or account closes | No routine account-closure deletion; subject to section 3 |
| Google Workspace business correspondence and associated business records | Indefinitely for support, billing, and relationship history | No routine account-closure deletion; subject to section 3 |
| Transaction and invoice records in Hemingway and Stripe, including invoices and wire-payment records | Retained for accounting and other permitted financial-record purposes | Not routinely deleted on cancellation or account closure. Stripe may separately retain records for its own regulated activities |
| SendGrid delivery and failure activity | Searchable email activity: 3 days. SendGrid generally removes recipient and delivery metadata within 37 days; some pseudonymized event data may remain for up to 1 year for security, fraud and abuse prevention, and network protection | Expires under the provider's applicable rules, without routine erasure or a permanent archive. We may retain limited delivery evidence needed for an active support or billing dispute under section 3, not message bodies or secret sign-in information |
| Marketing contacts and preferences | While their marketing use is permitted | Stop marketing when permission is withdrawn or an applicable opt-out takes effect. Only separately justified correspondence, evidence, or suppression records remain afterward |
| Unsubscribe and suppression records | The minimum address or identifier and preference needed to prevent unwanted contact | Keep while needed to honor the opt-out, not for further marketing or to preserve an unnecessary profile |
| Optional analytics and affiliate preferences | Choices and minimum evidence needed to apply them and honor changes or withdrawal | Update when choices change; retain only evidence still needed for that purpose |
| Rewardful referral cookie | 60 days | Expires at the end of its lifetime, subject to applicable withdrawal and deletion duties |
| Rewardful referral, attribution, affiliate, commission, payout, and accounting records | Retained for permitted referral, commission, and accounting purposes, separately from the cookie's lifetime | Not routinely deleted on account closure. Closure does not automatically deactivate a referral or change future commissions |
| Security and abuse-prevention records | While needed for the relevant security purpose or a specific incident | Delete or properly deidentify when that purpose ends, unless a legal duty requires retention |
| Contract and consent acceptance evidence | While needed to establish the agreement or permission and address applicable claims | No automatic account-closure deletion. Delete or properly deidentify when no longer needed, subject to recordkeeping duties |
| Completed privacy-request records | Limited evidence of the request, verification, and response while needed to demonstrate compliance | No automatic account-closure deletion. Do not retain the deleted dataset or unnecessary identity documents as evidence |
All rows remain subject to section 3, the DPA where applicable, and mandatory privacy and recordkeeping duties. A decision not to erase records routinely does not guarantee that a provider will keep them forever.
3. Exceptions and backups
We may retain information when the law requires it or a permitted need justifies it—for example, an unresolved payment dispute, a specific fraud investigation, or an unsubscribe instruction. We limit the records, access, and retention to that purpose. Records held only for a legal obligation or dispute are not reused for marketing, ordinary analytics, or product development.
The business-record policies above remain subject to applicable privacy requirements. We review whether personal information is still needed and delete or properly deidentify it when its permitted purpose ends. For processing on your behalf, the DPA and applicable law determine whether retention is allowed.
Writing entered into the editor is not automatically retained as correspondence. Correspondence may include text or attachments you send us for support. We retain these as part of the correspondence record, subject to applicable privacy requirements and our obligations under the DPA.
Backups remain access-restricted and expire on the applicable cycle. If a backup is restored, we reapply relevant deletions before the restored information returns to ordinary use. Backups do not provide an exception to mandatory deletion duties.
4. AI-provider copies
The provider directory identifies AI providers we use or may use. Different providers and services have different retention rules; a listing does not mean every provider receives your text. The content-use and confidentiality protections in the Terms, Privacy Policy, and DPA continue to apply.
| Provider copies | Retention rule |
|---|---|
| OpenAI abuse-monitoring logs | Ordinarily up to 30 days. OpenAI may keep them longer when required by law or reasonably needed to protect its services or others from harm. These logs may contain input and output. |
| OpenAI extended prompt caches | For supported services, encrypted cached prompt representations may remain for up to 24 hours, separately from abuse-monitoring logs. |
| Google AI requests | Google may retain AI requests for security, abuse prevention, or legal requirements. It does not publish a single retention period covering all such copies. |
| Anthropic ordinary commercial AI requests | Inputs and outputs are ordinarily deleted within 30 days of receipt or generation, subject to the service, applicable agreement, safety enforcement, and legal exceptions. Some models require 30-day safety retention even where a zero-retention arrangement otherwise applies. |
| Anthropic safety records | Inputs and outputs flagged for potential policy violations may be retained for up to 2 years; associated trust and safety classification scores may be retained for up to 7 years. The seven-year period describes scores, not all submitted writing. |
| Fireworks AI hosted inference and temporary caches | Ordinary hosted open-model inference does not persistently log prompts or outputs by default. Temporary prompt caches may remain in memory for minutes to several hours. Support handling, legally required retention, and services designed to store content have separate rules. |
5. Requests and effective date
Email support@hemingwayapp.com to request deletion, a copy, or an explanation. The Privacy Policy and DPA explain how we handle requests, including applicable provider copies.
This schedule applies from its effective date. It does not mean the same collection or retention practices applied earlier.