Data Retention Policy
Last updated: 2026-09-15
This policy describes Robot Networks Inc.'s standard retention and deletion practices for Boardwalk. It supports our Privacy Policy and Data Processing Addendum. A signed agreement may establish different terms. Legal holds, security investigations, disputes, and legal or accounting duties may require us to preserve particular records longer.
1. Inference content
Our application does not create a prompt or completion history in its metering or receipt database, or a training corpus from API traffic. GPU providers receive inference content and may buffer requests and temporary results in their queues and delivery systems. This is not a guarantee of zero retention across every provider system. Do not include inference content in support messages unless needed; content you send there is retained as a communication. Model artifacts you deploy are stored separately as described below.
2. Active accounts and organizations
We keep account profiles, organization settings, memberships, API-key metadata, active model records, Hugging Face connection metadata, and related configuration while needed to provide an active account or organization. API-key plaintext is displayed once and is not retained; we retain a one-way hash and identifying prefix. Hugging Face OAuth tokens are kept in a dedicated secret store while the connection is active and are removed when the connection is disconnected.
3. Standard retention schedule
- Gateway refusal records: 30 days. These describe a request rejected before it reached a worker and do not contain prompt text.
- Organization audit events: 395 days, approximately 13 months.
- Production operational logs: up to 90 days. Development logs are kept for up to 14 days. Logs may include IP address, route, request identifier, status, timing, and limited error information.
- Status measurements and incidents: up to 400 days. The public status page displays no more than 90 days of history.
- Metering and receipt records: retained with related financial records so completed requests remain auditable. The retention period depends on applicable accounting and tax obligations, the period for payment disputes and legal claims, and whether the record is needed to substantiate a related transaction.
- Ledger, payment, refund, top-up, and dispute records: retained for applicable accounting and tax recordkeeping periods and while needed to resolve payment disputes, fraud investigations, or legal claims. Account deletion does not erase the financial history of an organization.
- Model identity, configuration, qualification, and pricing evidence: while a model is active and afterward for as long as needed to resolve historical receipts, financial records, rights claims, or technical audits.
- Model artifacts in Boardwalk-controlled storage: while referenced by an active model, configuration, pool, or qualification. Once unreferenced, artifacts become eligible for deletion after a one-day safety period. Provider caches and backups may age out on their own rolling schedules.
- Analytics: identifiable events are retained while needed to measure usage across reporting periods, diagnose product issues, and evaluate product changes, subject to valid deletion requests and applicable law. Browser identifier lifetimes in the Cookie Policy do not determine server event retention. We may retain aggregated statistics that cannot reasonably identify a person.
- Support, legal, abuse, and security communications: while needed to address the request, demonstrate its handling, and comply with applicable complaint, withdrawal, and legal-claim periods. Open investigations and legal holds may require longer retention. Withdrawal notices retain their receipt time and confirmation reference.
Acceptance records retain the accepted version and time while needed to demonstrate the agreement and resolve related claims. Pending identity-deletion requests retain the provider identifier until deletion is confirmed; failed requests are retried and flagged for operational attention. Contact us for a retention or erasure request for a particular category; the console export covers your profile and memberships, not every record.
4. Account deletion
You can export your account profile and organization memberships and request account deletion in the console. Before deletion, a sole owner must transfer ownership or delete the organizations they alone own. Account deletion disconnects their Hugging Face account and removes its OAuth credential, removes the user from organizations, revokes API keys the user created in those organizations, deletes their Boardwalk-hosted profile image, queues deletion of their Clerk identity and retries failed provider requests, and replaces their email and identity fields in our database with tombstone values derived from the internal user identifier.
Audit events may remain until their normal expiration with an internal user identifier and historical metadata. Profile scrubbing does not anonymize the retained audit trail. Financial, receipt, fraud-prevention, and legal records remain where needed. Deletion from a provider's backups and logs occurs as those copies age out under the provider's rolling retention schedule; we do not restore deleted customer data except as part of disaster recovery. If deleted records are restored, deletion requests must be reapplied before those records return to ordinary use.
5. Organization and model deletion
Deleting an organization immediately revokes its API keys, retires its models and serving capacity, removes remaining credits from the console balance subject to mandatory refunds, and removes it from normal product views. We retain a tombstoned organization record and the usage, ledger, payment, and configuration records required to preserve financial integrity and historical receipts.
Deleting a model removes or disables it and releases serving capacity. A model that never served may be deleted outright. If it served requests, its identity and configurations are retained in tombstoned form so prior receipts remain verifiable. Unreferenced private model artifacts then become eligible for the deletion process described above.
6. Backups and provider systems
Production data stores use rolling backup or point-in-time recovery systems. Deleted data can remain in encrypted backups until the applicable recovery window expires. Backups are access-controlled, are not used for ordinary product operations, and are restored only for disaster recovery. Third-party providers may retain limited security, billing, or legal records under their own obligations.
7. Legal holds and de-identified data
We may suspend deletion of information relevant to litigation, a regulatory inquiry, valid legal process, fraud, security, an abuse report, or enforcement of our agreements. When the hold ends, the ordinary retention schedule resumes. Holds on Customer Personal Data processed under the DPA are limited by that DPA and applicable transfer clauses; a general interest in defending claims does not override required deletion. We may retain aggregated or de-identified information that cannot reasonably be linked to you for analytics, security, research, pricing, and capacity planning.
8. Requests and contact
Use the console for account export and deletion. For a request not available there, or for a retention question, email legal@boardwalk.cloud.