Our approach
Keep information only while there is a reason to keep it.
We use defined deletion controls and windows so customer information does not remain in the Service without an operational, security, or legal need.
1. Scope
This Data Retention Policy explains how Tearleads, LLC (“Tearleads,” “we,” “us,” or “our”) retains and deletes information in the Tearleads websites, applications, and related services (the “Service”). It should be read with our Privacy Policy and Terms of Service.
2. General retention
We retain account, security, organization, and workspace information while it is needed to provide and secure the Service. Information generally remains available while the relevant account or organization is active, unless an authorized user deletes it using an available Service control.
Retention may also continue for a limited period when reasonably necessary to comply with law, resolve disputes, enforce our agreements, prevent fraud or abuse, or protect the Service and its users.
3. Organizations and workspace information
Organization information includes files, inbound messages, business records, audits, financial records, membership records, and other content stored in an organization workspace. We retain this information while the organization is active, subject to feature-specific deletion controls.
When an organization owner marks an organization for deletion, the organization and its information become inaccessible through the Service immediately. The organization becomes eligible for permanent deletion after 30 days. An authorized Tearleads administrator may restore it before permanent deletion.
Permanent organization deletion removes the organization records stored in our active database and the organization objects stored in our active object storage. Deleting an organization does not delete user accounts; users keep their memberships in any other organizations.
4. Inbound email
Moving an inbound email to Trash records when it was deleted and who deleted it. The message and its attachments remain recoverable from Trash and become eligible for permanent deletion after 30 days unless an authorized user restores the message first.
Permanent deletion removes the email record and its stored raw message and attachment objects from active storage.
5. Plaid-connected financial information
Disconnecting a financial institution revokes Tearleads’ ongoing Plaid access and erases the encrypted access credentials used to refresh that connection. Previously imported accounts, transactions, and annotations remain in the organization so authorized users do not unexpectedly lose their records.
After disconnecting, an authorized user can use the separate Delete data control in Finance to permanently delete the imported accounts, transactions, annotations, and connection record from active storage. For more information about the financial information we process, see our Privacy Policy.
6. Security records and recovery copies
We may retain limited authentication, request, diagnostic, audit, and security records for as long as reasonably necessary to operate and secure the Service, investigate abuse, and meet legal obligations.
Information already included in a backup or disaster-recovery copy may remain until that copy expires or is overwritten. We restrict access to recovery copies and do not restore deleted information to active use except when needed for recovery, security, or legal compliance.
7. Exceptions
We may retain information longer when required by law or lawful process, needed to establish or defend legal claims, necessary to investigate fraud or security incidents, or required to protect the rights and safety of users or others. When practical, we limit retained information to what is needed for that purpose.
8. Questions and requests
Use the organization, inbox, and Finance controls in the Service where available. For other retention or deletion requests, email privacy@tearleads.com.