The specific retention window for every category of data LADLE stores. Deleted data is deleted from primary storage first, then from backups within 35 days.
UPDATED 2026-08-06
“How long do you keep my data?” is a common question. This is the complete schedule.
User-generated content
Chat messages (yours + model)Retained while your account is active. Deleted 30 days after account closure.
Uploaded filesRetained while attached to a chat or project. Deleted 30 days after removed from all attachments.
Project instructions + knowledgeRetained until you delete the project. Then deleted within 24 hours from primary storage.
Custom instructionsRetained until you update or delete them.
Account data
Email address, name, hashed passwordRetained while account active; deleted 30 days after account closure
OAuth tokens (Google/Apple sign-in)Retained while account active; revoked + deleted at closure
Session tokensRotated every 30 days; deleted on sign-out
Subscription status + tier historyRetained 7 years (financial recordkeeping)
Billing data
Invoices + receipts7 years (tax + SOX requirements)
Card detailsNever stored by LADLE; held by Stripe under PCI-DSS
Aggregate meal-fund totals + partner wire records (partner references populate once the partnership threshold clears)Indefinitely (transparency + audit)
Per-subscriber attribution of meal-fund share12 months (for impact statement generation)
Impact statement PDFs generated for you12 months from generation
Legal + compliance
DSR/DSAR request logs (GDPR/CCPA)3 years (regulatory)
Formal complaints3 years
Legal process (subpoenas, warrants)7 years
CSAM reports to NCMECStatutory (currently 90-day minimum; longer if required)
Tax records7 years
When you delete your account
Account closure kicks off a 30-day soft-delete window. During that window your account is closed to sign-in but your chats + files can be restored on request. After 30 days: primary storage is purged; backups roll off within 35 more days. Retention required by law (billing records, subpoena responses) persists per the schedules above.
One schedule, no exceptions.
See /trust/data-map for the same data mapped to purpose + legal basis.