Retention Policy
How AI Blueprint retains and deletes account, workspace, billing, security, backup, and AI-related data—including dormant-account and top-up credit rules.
Retention principles
We keep data for defined service, security, contractual, legal, accounting, tax, complaint, or dispute purposes. Data is deleted or anonymised when that purpose ends unless a lawful duty or hold applies.
Deletion from active systems is distinct from restricted legal records, disaster-recovery backup cycles, and subprocessor windows. Backups are not intentionally used to reactivate a deleted account.
Verified data schedule
| Category | Examples | Retention rule | End action |
|---|---|---|---|
| Account and profile | Name, email, password hash, locale, preferences, status | While the account remains active and needed for service or security; subject to narrow holds and legal duties | Delete or anonymise after valid deletion and hold review |
| Workspace and Blueprint | Ideas, decisions, documents, drafts, revisions, output, Assistant conversations | While the account or relevant workspace remains active | Delete or anonymise with the content/workspace or account, subject to holds and backup expiry |
| Authentication tokens | Email verification, password reset, session, OAuth state | Email verification 30 minutes; password reset 60 minutes; session maximum 30 days; tokens also end when used or revoked | Remove through use, expiry, revocation, or authentication cleanup |
| AI processing | Minimum prompt/context, output, model, tokens, cost, retries | Customer content follows its project/account. Raw diagnostics 7 days, attempt detail 180 days, logical calls 365 days | Delete temporary payloads; retain only lawful aggregates/audit under their schedule |
| Operational and security logs | Login, IP where collected, user agent, jobs, warnings, errors, audit | Debug/info 30 days; warning 90 days; error/critical 365 days | Delete or anonymise unless a security/legal hold applies |
| Support and disputes | Tickets, email, refunds, complaints, evidence, resolution | 730 days after closure; longer while a dispute/hold is active | Delete or restrict after the period/hold ends |
| Payment, contract, legal acceptance, and credit ledger | Invoice, payment, top-up, refund, chargeback, document acceptance, ledger | Restricted retention under applicable electronic-commerce, contract, accounting, tax, fraud, and dispute duties | Never recreate the account; delete or anonymise when the category duty ends |
| Disaster-recovery backups | Access-restricted database and operational copies | Deleted data may remain temporarily until the ordinary backup cycle ends. Automated dormant deletion is not enabled until the production maximum is verified and published | Never use for reactivation; reapply deletion tombstones after restore |
| Deletion evidence | Pseudonymous hash, policy version, notices, time, categories, cleanup status | Minimum evidence without workspace content; audit minimum 2555 days | Delete or anonymise after the audit/legal need ends |
Dormant Account Policy
We may schedule permanent deletion only after more than 270 consecutive calendar days without a successful login and when no active paid monthly entitlement remains. Exactly 270 days is not eligible.
Any payment retry or grace period must be over; no payment may still be pending; and no refund, chargeback, complaint, dispute, security/fraud review, legal hold, or other lawful hold may remain. Every condition is revalidated before deletion.
For an account that has never signed in, account creation starts the inactivity measurement. Accounts already past the threshold at launch receive a full 30-day notice period and are not deleted immediately.
Advance notices
Each send or valid delivery attempt is recorded. A case reaching its deadline stops for operator review until every deletion gate, subprocessor cleanup path, and production backup cycle is proven.
| Notice | Timing | Minimum content |
|---|---|---|
| First warning | 30 days before | Absolute Asia/Jakarta deadline, reason, plan status, affected data, balance by credit type, export, login, and Support |
| Second warning | 7 days before | Deadline, consequences, top-up balance, login/reactivation, and Support |
| Final warning | 1 day before | Final deadline, permanent-deletion warning, login link, and Support |
| Completion | After active-system deletion | Confirmation, narrow legal records, backup statement, and privacy channel |
Plan, promotional, and top-up credits
Monthly credits follow the period terms shown at purchase. Promotional credits follow their displayed promotion terms. Both end no later than permanent account deletion.
Top-up credits have no expiry date while your AI Blueprint account remains active. Cancelling, not renewing, or failing to pay for a monthly plan does not remove your top-up credits while your account has not been permanently deleted. If the account is permanently deleted—including under the Dormant Account Policy after more than 270 days without a successful login and without an active paid monthly plan—all remaining top-up credits will end with the account and can no longer be used. Advance notice will be provided under the Dormant Account Policy.
Every credit mutation is recorded in the append-only ledger. Remaining top-up balance is derived deterministically from top-up grants and debits; non-top-up credits are consumed first so a plan ending does not erase top-up rights.
How to cancel dormant deletion
Complete a successful login before permanent deletion finishes. Restoring an active paid monthly entitlement also cancels the schedule. You do not have to buy a plan merely to preserve the account and top-up credits; successful login is enough to reset dormancy.
Deletion and limited records
When permanent deletion completes, access ends and profiles, projects, Blueprint documents, drafts, revision history, output, attachments, Assistant conversations, preferences, sessions, tokens, caches, queues, and other product data in active systems are deleted or anonymised.
Not every record ends at the same moment. Minimum records may remain separately under restricted access for legal, accounting, tax, electronic-transaction, fraud, security, audit, complaint, refund, chargeback, or dispute purposes. They are unavailable in the workspace and are not used to reactivate the account.
Subprocessors and backups
Deletion requests are propagated to subprocessors where required and supported. Their provider-specific or abuse-monitoring windows may differ from active-system deletion by CV DNA Konsultan. See the Subprocessor Registry for active integrations and provider disclosures.
Open the Subprocessor Registry →Changes and contact
Material changes—including the dormancy threshold or top-up lifecycle—are communicated by email or in-product notice and may require reacceptance. Privacy questions or requests can be sent to hello@aiblueprint.web.id.
Contact AI Blueprint →