تخطَّ إلى المحتوى

Data Retention and Deletion

How long each kind of data stays on the platform, what triggers its deletion, and the narrow cases where the law requires us to keep something after you have asked us to remove it.

Effective date: 9 August 2026 · Last updated: 9 August 2026

1. The principle

We keep data for as long as it serves the purpose it was collected for, and no longer. When that purpose ends, the data is deleted — except where a specific legal obligation requires us to keep a defined item for a defined period.

Two things follow from that. We do not keep data indefinitely 'in case it is useful'. And when we do keep something after you have asked us to delete it, we tell you what and why, rather than deleting the record silently and keeping a copy.

2. Retention schedule

  • Account and profileKept while the account is active. Deleted on account closure, subject to the exceptions below.
  • SessionsA session lasts 30 days from sign-in and is removed when it expires, when you sign out, or when you end it from your security settings.
  • Connected account tokensHeld while the connection is active. Deleted immediately when you disconnect the platform or close your account — the encrypted token is erased, not merely marked inactive.
  • Content and generated assetsKept in your workspace until you delete them or close the account. You control this directly.
  • Prompts and AI outputsKept with the workspace item they belong to, and deleted with it.
  • Campaign and performance dataKept while the account is active so you can compare periods; deleted on closure.
  • Billing recordsInvoices, payments and refunds are kept for the period required by tax and commercial law, regardless of account closure.
  • Operational logsKept for a short period for security, fraud prevention and fault diagnosis, then discarded.

3. What happens when you close your account

Closure begins a deletion process, not an instant erasure of every trace. In order: access is revoked immediately; tokens for connected accounts are deleted immediately, which ends our ability to reach those accounts; workspace content and campaign data are deleted; billing records are retained as set out above.

Disconnecting an account inside SAIMA removes our access. It does not delete anything held by that third party — content already published to a social platform remains there, and must be removed on that platform.

4. Backups

Backups exist so that a failure or an attack does not destroy your work. They are taken on a rolling cycle and overwritten as that cycle turns.

This means deleted data can persist in a backup for a short period after deletion from the live system. Backups are encrypted, are not used for day-to-day access, and are never mined for content. Data deleted from the live platform is not restored into it, and disappears from backups as the cycle overwrites them.

5. When we must keep something

We retain specific data past a deletion request only where one of these applies, and only the item concerned:

  • Legal obligationFinancial and tax records that commercial law requires us to preserve for a set period.
  • Dispute or claimMaterial relevant to an active dispute, until it is resolved.
  • Abuse preventionA minimal record of an account terminated for a severe breach, to prevent the same actor from re-registering. This is a record of the enforcement, not a copy of the content.

6. Requesting deletion

You can request deletion of your data at any time. The Data Deletion page explains how, and the Data Subject Request Procedure sets out the timetable and what we do at each step.