How long data stays
2 min read
For every body of data you set a period and what should happen afterwards: delete, anonymise or keep. A nightly run carries it out and leaves a record of what it did.
The areas register themselves
The list does not come from this page but from a register: records, documents, notes, history, tasks, logs, sessions and a good dozen more. When a new body of data comes into being, it appears here by itself. A body of data without a rule would otherwise be exactly the one nobody thinks of.
⚠️ The clock runs from the last change, not from closing
This is the most important line on the page. A record nobody has touched for months is old enough, even if it sits mid-process. Anyone wanting to catch only closed records ticks Only closed records. Without that tick the rule touches everything old enough.
Delete or anonymise
Deleting removes the data. Anonymising removes the field values and leaves the id, timestamps and source so that counts still add up. For records anonymising is usually right: how many enquiries came in last year is a fair question, the name behind them after the period has run is not.
A legal hold beats every period
On a single record you can set a block against deletion, with a reason and a date. While it stands, the run skips that record and counts it as skipped. Meant for the case where a file is needed right now.
Affected today, and what actually ran
Before saving, Affected today says how many records a rule would catch. Afterwards, Recent runs says what actually happened: how many deleted, how many anonymised, how many skipped because of a hold.
Step by step
- Open Settings, Account, the Retention tab.
- Set the period in days per area. 0 means never delete.
- Choose the action: delete, anonymise or keep.
- For records, decide whether only closed ones are touched.
- Read Affected today before you save.
Why were records anonymised that were still open?
Because the clock runs from the last change and Only closed records was not ticked. That is exactly what happened on 2026-09-18, after a migration brought old timestamps along: on the first day the whole stock counted as untouched for months.
Can anonymising be undone?
No. The values are gone, and that is the point. Which is why Affected today stands before saving and not after.
Is there a lower limit?
For some bodies of data yes, and it is shown along with the rule it comes from. Shorter cannot be set.
What does 0 mean?
Never delete. The data stays until someone changes the rule.
When does this run?
At night, once a day. What a rule would catch today is shown during the day under Affected today.