Retention and deletion
Inbox bodies
7 days
R2 lifecycle inbox/ + API TTL + worker sweep
Inbox metadata
7 days
Postgres expires_at + worker
Visual PNGs / baselines
7 days
R2 lifecycle visual/ + cap 32/template
Payload capture
1–30 days (default 7)
Postgres TTL + cap 100/org; AES-256-GCM hashed shapes, not raw values
Webhook outbox
7 days
TTL + 256 pending/endpoint
Key Value
Ephemeral
Cache; not source of truth
Better Stack OTLP
3 days logs/spans; 30 days metrics
Vendor retention
Audit events
No deletion job
Append-only; retention job not implemented
Org deletion
Application cascade
Org/project/env cascade. Not a right-to-erasure SLA yet
Attribution cookies
90 days
httpOnly renply_anon and renply_attr; campaign fields only
Attribution rows
Account lifetime
Postgres user_attribution and org_attribution; cascade on user or org delete
A dated Postgres PITR restore drill has not been recorded. Org deletion cascades application rows; that is not a documented right-to-erasure SLA.