Codapult should keep operational data only for the period needed to run the product, investigate failures, and satisfy the deployment's contractual requirements. The table below is a recommended deployment baseline, not an automatic application purge. The operator must configure and verify the actual retention windows for each environment.
Recommended deployment baseline
| Data | Default | Lifecycle |
|---|---|---|
| Sessions and verification tokens | Until expiry | Cleanup jobs remove expired records. |
| AI usage and audit records | While the organization account is active, unless a shorter period is configured | Organization deletion/export controls the account lifecycle. |
| Webhook delivery payloads | 30 days | Configure a cleanup job or database policy; keep status and identifiers longer only when operationally required. Payloads can contain sensitive provider data. |
| Application logs | 30 days | Configure the hosting log drain or platform retention to match this target. |
| Traces and error events | 30 days | Configure OpenTelemetry and Sentry retention separately. |
| Database backups | 30 days | Configure provider retention; it can be longer for legal or disaster-recovery requirements. |
| Object-storage uploads | Until deleted by the owning feature or account workflow | Enable bucket versioning and lifecycle expiration when the product does not require historical versions. |
Deletion and export
Account deletion and GDPR workflows remove or anonymize application records covered by the feature. A restore point, provider log, trace, or object-storage version is a separate copy and follows its provider retention policy; it is not immediately removed by an application transaction. Do not promise erasure from backups until the provider's expiry or purge procedure has completed.
Before launch, record the configured retention and owner for:
- the primary database and point-in-time recovery;
- object storage and versioned objects;
- application logs, traces, and error tracking;
- webhook payloads and admin audit records;
- exports and disaster-recovery copies.
Review the policy when adding a table containing personal or payment data. Keep payload access restricted to the operational roles that need it, and use the existing redaction paths for logs, traces, and error reporting.