{
  "page": "docs/data-handling",
  "title": "Data handling and retention",
  "slug": "data-handling",
  "description": "What we store, for how long, encrypted with what, and how to have it deleted.",
  "section": "Running an org",
  "updated": "2026-09-30",
  "blocks": [
    {
      "type": "p",
      "text": "Your agents send us inputs (names, domains, emails, URLs) and buy results. This page says what we keep, how, for how long, who can see it, and how to have it deleted. The legal version is the [privacy policy](/privacy)."
    },
    {
      "type": "h2",
      "id": "vault",
      "text": "Stored inputs and results"
    },
    {
      "type": "list",
      "items": [
        "Each live purchase's input and result are kept for **7 days**, then deleted. We keep them that long so a [dispute](/docs/disputes) can be checked against what was actually sold, and so the weekly audit can sample them.",
        "An item under dispute is kept until the dispute is decided: at most 48 hours past the 7 days.",
        "They are encrypted with AES-256-GCM using a key unique to your org. That key is itself stored only encrypted, under a master key kept outside the database. A stored item can't be read as, or moved to, another org's.",
        "Test-mode purchases store nothing: the mock providers don't see real data and nothing is kept.",
        "The inputs of a job wait encrypted the same way and are deleted when the job finishes."
      ]
    },
    {
      "type": "h2",
      "id": "what-stays",
      "text": "What stays after deletion"
    },
    {
      "type": "p",
      "text": "The [receipt](/docs/receipts) of each purchase stays, because it is your record of what you paid: the tool, the provider, the price, the outcome, the check version, refunds, and SHA-256 hashes of the input and the result. A hash can confirm a result you still hold; it can't be turned back into the data. We also keep the outcome, timing and a coarse segment of each call (for example the task type and region) to compute [scores](/docs/scores)."
    },
    {
      "type": "h2",
      "id": "deletion",
      "text": "Ask for deletion"
    },
    {
      "type": "p",
      "text": "An owner can ask us to delete the org's stored inputs and results, its private test sets and its storage key, on the Team page of the dashboard or with `POST https://api.arettic.com/v1/orgs/{orgId}/deletion-requests` (optional `note`). It is done within **24 hours**, and we email the owner who asked when it is. Destroying the org's key makes anything encrypted with it unreadable at once. Receipts, invoices and your balance stay: they hold no inputs or results, and invoices are tax records."
    },
    {
      "type": "list",
      "items": [
        "Asking needs an owner signed in; an org key gets `403 forbidden`. One request can be open at a time (`409 conflict`).",
        "`GET https://api.arettic.com/v1/orgs/{orgId}/deletion-requests` (members and org keys) shows each request, `done_by` (the deadline), `completed_at` and how many items were deleted.",
        "If nobody at Arettic gets to it first, it is completed automatically in its last hour, so the 24 hours hold regardless."
      ]
    },
    {
      "type": "code",
      "title": "curl",
      "lang": "bash",
      "code": "curl https://api.arettic.com/v1/orgs/$ORG_ID/deletion-requests \\\n  -H \"Authorization: Bearer $ARETTIC_SESSION\" \\\n  -H \"Content-Type: application/json\" \\\n  -d '{ \"note\": \"End of the pilot\" }'"
    },
    {
      "type": "h2",
      "id": "who-sees-it",
      "text": "Who sees your data"
    },
    {
      "type": "list",
      "items": [
        "**The provider of the tool you run** receives that request's input (with fallback on, the provider of the substitute tool). For `find_email`, the found email may also go to our email verifier. Nobody else receives it.",
        "**No other customer.** Nothing you send or buy is shared with, shown to, or cached for another customer.",
        "**No training.** We never use your inputs or results to train models, and never sell them.",
        "**Arettic staff** open a stored item only to decide a dispute, to review an item flagged by the weekly audit, or to re-check results when a pass rule or the score formula changes. Every look is logged with who and why."
      ]
    },
    {
      "type": "h2",
      "id": "audit",
      "text": "The weekly audit"
    },
    {
      "type": "p",
      "text": "Every week we sample up to 100 recently passed results per task type from the last 3 days and review them, to check that our pass rules pass the right things. The review is automated (rule-based plausibility checks today; an AI reviewer can be switched on later), and anything it is unsure about goes to a person at Arettic. It reads the stored input and result; like every other look, it is logged. Its findings feed the accuracy input of the scores; it never changes what you were charged."
    },
    {
      "type": "h2",
      "id": "acceptable-use",
      "text": "Acceptable use: people lookups"
    },
    {
      "type": "p",
      "text": "To stop bulk collection of one company's staff, an org can make at most **500 people lookups** (`find_email`, `enrich_person`, `verify_email`) **per company domain per day** (UTC). The request that would pass it is declined with `429 aup_limit`, nothing is held or charged, and the incident is recorded for review. Counters are kept by a hash of the domain, so we don't keep a list of the companies you look up. Contact support if you have a legitimate research need."
    },
    {
      "type": "h2",
      "id": "retention",
      "text": "Other data we keep"
    },
    {
      "type": "table",
      "caption": "Retention",
      "head": [
        "Data",
        "Kept for"
      ],
      "rows": [
        [
          "Stored inputs and results",
          "7 days (under dispute: until decided, at most 48 hours more); deleted within 24 hours of a deletion request"
        ],
        [
          "Private benchmark test sets",
          "Until you delete them or ask for deletion"
        ],
        [
          "Receipts, invoices, the ledger",
          "Kept: they are your records and ours, and contain no inputs or results"
        ],
        [
          "API request log (route, status, timing, org and agent IDs, error code; never inputs)",
          "14 days"
        ],
        [
          "Rate-limit counters",
          "1 day"
        ]
      ]
    },
    {
      "type": "h2",
      "id": "where",
      "text": "Where it lives"
    },
    {
      "type": "p",
      "text": "Arettic runs on Railway. The hosting region is being fixed before launch and will be named here and on the [privacy policy](/privacy), with the sub-processors we use. Providers process each request wherever they operate."
    }
  ]
}