← Back to Home

📋 Data Retention Policy - Ai Lions Platform

Effective Date: January 8, 2026 Last Updated: January 8, 2026 Version: 1.0


1. Overview

This Data Retention Policy outlines how long Ai Lions retains user data and the procedures for data deletion in compliance with GDPR (General Data Protection Regulation) and other applicable data protection laws.


2. Data Categories & Retention Periods

2.1 User Account Data

Data Type Retention Period Deletion Trigger
User Profile (email, name, password hash) Until account deletion User deletes account or admin deletion
Account Metadata (rank, created_at) Until account deletion User deletes account or admin deletion
OAuth Connections (encrypted tokens) Until disconnection or account deletion User disconnects service or deletes account

Legal Basis: GDPR Article 6(1)(b) - Contract performance


2.2 User-Generated Content

Data Type Retention Period Deletion Trigger
Personas (name, role, instructions, avatar) Until persona deletion or account deletion User deletes persona or account
Conversations (chat history, messages) Until conversation deletion or account deletion User deletes conversation or account
Custom Instructions Until persona deletion or account deletion User deletes persona or account

Legal Basis: GDPR Article 6(1)(b) - Contract performance


2.3 Uploaded Files

Data Type Retention Period Deletion Trigger
User Uploaded Files (PDFs, DOCX, XLSX, etc.) Until file deletion or account deletion User deletes file or account
File Metadata (filename, size, upload date) Until file deletion or account deletion User deletes file or account

Legal Basis: GDPR Article 6(1)(b) - Contract performance


2.4 Generated Files

Data Type Retention Period Deletion Trigger
AI-Generated Files (Excel reports, documents) 30 days from creation Automatic deletion after 30 days OR user/account deletion
Generated Media (images, videos) 30 days from creation Automatic deletion after 30 days OR user/account deletion

Legal Basis: GDPR Article 6(1)(b) - Contract performance
Note: Generated files are temporary and automatically deleted after 30 days to minimize data storage.


2.5 System Logs & Security Data

Data Type Retention Period Deletion Trigger
Security Logs (IP blocks, attack attempts) 90 days Automatic deletion after 90 days
Application Logs (errors, warnings) 90 days Automatic deletion after 90 days
Audit Trails (user actions) 1 year Automatic deletion after 1 year

Legal Basis: GDPR Article 6(1)(f) - Legitimate interests (security and fraud prevention)


2.6 Analytics & Cookies

Data Type Retention Period Deletion Trigger
Essential Cookies (session, CSRF) Session duration (max 30 days) Session expiry or logout
Analytics Cookies (Google Analytics) 26 months (Google default) User opt-out or cookie expiry
Marketing Cookies (Facebook Pixel) 90 days User opt-out or cookie expiry

Legal Basis: GDPR Article 6(1)(a) - Consent (for non-essential cookies)


3. Data Deletion Procedures

3.1 User-Initiated Deletion

Users can delete their data through the following methods:

  1. Delete Individual Personas: Dashboard → Delete Persona button
  2. Delete Conversations: Chat interface → Delete conversation
  3. Delete Uploaded Files: File manager → Delete file
  4. Delete Account (Right to be Forgotten): Settings → Delete Account
  5. Scope: Deletes ALL user data including:
    • User profile
    • All personas
    • All conversations
    • All uploaded files
    • All generated files
    • All OAuth connections
  6. Timeframe: Immediate deletion (within 24 hours)

3.2 Automatic Deletion

  • Generated Files: Automatically deleted after 30 days
  • Security Logs: Automatically deleted after 90 days
  • Audit Trails: Automatically deleted after 1 year

3.3 Admin-Initiated Deletion

Administrators can delete user accounts through the Admin Panel: - Scope: Same as user-initiated deletion - Timeframe: Immediate deletion (within 24 hours)


4. Data Backup & Recovery

4.1 Backup Retention

  • Database Backups: Retained for 30 days
  • Backup Frequency: Daily (automated)
  • Backup Location: Secure cloud storage (encrypted)

4.2 Backup Deletion

  • Backups containing deleted user data are overwritten within 30 days
  • Users cannot recover data after deletion (irreversible)

5. GDPR Rights & Data Retention

5.1 Right to Erasure (Article 17)

Users can request complete data deletion at any time through: - Self-Service: Settings → Delete Account - Email Request: [email protected]

Response Time: Within 30 days of request

5.2 Right to Data Portability (Article 20)

Users can export all their data in JSON format: - Self-Service: Settings → Export Data - Data Included: Profile, personas, conversations, files metadata

Response Time: Immediate download

5.3 Right to Restriction (Article 18)

Users can restrict processing by: - Disconnecting OAuth integrations - Opting out of analytics cookies - Deleting specific personas/conversations


6. Exceptions to Retention Periods

Data may be retained longer than specified periods in the following cases:

  1. Legal Obligations: Compliance with legal, tax, or regulatory requirements
  2. Dispute Resolution: Ongoing legal disputes or investigations
  3. Security Incidents: Active security investigations (max 2 years)

Legal Basis: GDPR Article 6(1)(c) - Legal obligation


7. Third-Party Data Retention

7.1 Cloud Service Providers

  • Google (Drive, Gmail): Data retained according to Google's retention policy
  • Microsoft (OneDrive, Outlook): Data retained according to Microsoft's retention policy
  • Box: Data retained according to Box's retention policy

Note: CoPersona does NOT store copies of cloud service data. We only access data via OAuth tokens.

7.2 Analytics Providers

  • Google Analytics: 26 months (configurable)
  • Facebook Pixel: 90 days

8. Contact Information

For questions about data retention or to exercise your GDPR rights:

Email: [email protected] Website: https://copersona.cognitivess.com Data Protection Officer: [email protected]


9. Policy Updates

This policy may be updated periodically. Users will be notified of significant changes via: - Email notification - In-app notification - Website announcement

Last Updated: January 7, 2025


© 2023-2025 Cognitivess - All rights reserved.