> For the complete documentation index, see [llms.txt](https://trust.memori.ai/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://trust.memori.ai/en/data-and-privacy/data-retention.md).

# Data Retention

How long we keep your data and what happens when we delete it.

Memori adopts data retention policies based on the minimization principle set out in the GDPR. Data is kept only for the time strictly necessary for the purposes for which it was collected. Below is the complete breakdown for each type of data.

### Account and authentication data

| Data type                      | Retention period                         | Notes                                   |
| ------------------------------ | ---------------------------------------- | --------------------------------------- |
| Email, username, date of birth | Until account deletion                   | Provided by the user at registration    |
| Session tokens                 | 30 days of inactivity or browser closure | Generated automatically                 |
| User preferences               | Until account deletion                   | Notification frequency, profile picture |
| Last access history            | Until account deletion                   | Updated automatically                   |

### Agent data and content

| Data type                                                       | Retention period                      | Notes                               |
| --------------------------------------------------------------- | ------------------------------------- | ----------------------------------- |
| Agent configuration (name, description, instructions, settings) | Until Agent deletion                  |                                     |
| Content (copies of conversations/deposits, variants, tags)      | Until manual modification or deletion |                                     |
| Media attached to content (images, videos, PDFs)                | Until Agent deletion                  | Stored on AWS S3                    |
| Imported document name                                          | Until Agent deletion                  |                                     |
| Original text of imported document                              | Until Agent deletion                  | Only if the user chooses to keep it |

### Conversation data

| Data type                                                         | Retention period                                                              | Notes                                      |
| ----------------------------------------------------------------- | ----------------------------------------------------------------------------- | ------------------------------------------ |
| Chat transcript                                                   | Until chat deletion or expiry of the retention period configured by the admin |                                            |
| Session metadata (anonymized IP, user agent, timestamp, page URL) | Until chat deletion                                                           | IP always anonymized                       |
| Documents uploaded in chat                                        | Deleted after processing                                                      | Only the metadata remains permanently      |
| Message translation cache                                         | 7 days                                                                        | Does not include generative AI output      |
| System logs (operational metadata only, not the content)          | Kept until manually deleted                                                   | Does not include the text of conversations |

> **Note for PaaS models:** The conversation retention period is configurable by the tenant administrator through the administration panel. At the end of the configured period, messages are permanently and irreversibly deleted.

### Contextual data and Deep Thinking

| Data type                   | Retention period          | Notes                                         |
| --------------------------- | ------------------------- | --------------------------------------------- |
| Geographic location         | Not retained              | Used only within the session context          |
| Date and time               | Not retained              | Used only for temporal personalization        |
| Known facts (Deep Thinking) | Until deleted by the user | Visible and deletable by the user at any time |
| Interests (Deep Thinking)   | Until deleted by the user |                                               |

### Billing data (SaaS only)

| Data type                                           | Retention period                                          | Notes                                                    |
| --------------------------------------------------- | --------------------------------------------------------- | -------------------------------------------------------- |
| Issued invoices                                     | 10 years from the issue date                              | Italian tax obligation; also kept after account deletion |
| Billing profile (personal details)                  | Until account deletion; then kept only in issued invoices | Tax obligation                                           |
| Payment methods (card brand, last 4 digits, expiry) | Deleted upon account deletion                             | The full card number is never stored by Memori           |
| Consumption and usage                               | Deleted upon account deletion                             |                                                          |

### Account and Agent deletion

**Deleting an Agent:** removes all of the Agent's data (content, conversations, media, configuration). Only anonymous operational metadata (type of operation, not the content) remains in the system log.

**Deleting the account:** removes all of the User's data. All Agents must be deleted manually before proceeding with account deletion. The operation is irreversible.

Memori does not collect, use or transfer users' data to customize or improve its own models or those of third parties. Data is used exclusively to provide the contracted service.
