Legal

Privacy Policy

How long we keep each type of data and how deletion works.

Last updated: 25 March 2026

Why we have this policy

Under GDPR Art. 5(1)(e), CPRA §1798.100(a)(3), and DPDP §8(7), personal data must be kept no longer than necessary for the purposes for which it was collected. This policy specifies how long MSH retains different categories of data and what happens when retention periods end.

Retention schedule

Category What it includes Retention period What happens after
Account identifiers Email, name, company, role, password hash, OAuth identifiers While account is active + 30 days Hard-deleted from primary systems; removed from backups within 60 days
Authentication logs Login timestamps, IP address at login, device info 12 months Hard-deleted
Billing records Invoices, payment history, tax info 7 years from transaction date Retained for tax/accounting law (Indian Income Tax Act, EU VAT Directive); then deleted
Customer content Articles, campaigns, contacts, keywords, plans, uploaded files While account is active; 30 days after account deletion Hard-deleted from primary + backup
Integration data — Search Console / Analytics Queries, positions, clicks, sessions, etc. (when Phase 2 activates) Rolling 24 months of raw data; older aggregated to monthly summaries Raw data beyond 24 months overwritten in place
Plugin telemetry SEO scores, on-page metrics reported by the MSH plugin Rolling 12 months Older data aggregated to weekly averages
Support conversations Chat logs, tickets, emails with hello@ or privacy@ 3 years from last message Hard-deleted
Security logs Access logs, admin queries, audit trail 12 months (extended to 24 if an incident investigation is ongoing) Hard-deleted
Consent records Toggle changes, consent captures, opt-outs Duration of account + 3 years after Retained to defend against complaints about historical processing
Marketing list data Email subscribers to MSH newsletter Until unsubscribe + 30 days Hard-deleted, with unsubscribe flag retained 2 years to honor suppression
Anonymized MSH Intelligence aggregates (Phase 3) Statistical patterns with n≥50 contributors — NOT personal data under GDPR Recital 26 Permanent N/A — anonymized data is not subject to retention limits
Legal hold data Anything subject to active litigation, regulatory request, or legal obligation Until hold is released Retained as required by law

How deletion works

Self-serve account deletion

When you click "Delete my account" in Settings:
1. Account is immediately disabled — logins blocked, API tokens revoked
2. 30-day grace period — you can contact privacy@marketingsohigh.com to restore within this window (once elapsed, deletion is irreversible)
3. Day 30: primary database deletion of all Tier 1 data (account data, content, integration data, plugin telemetry) using DELETE statements
4. Day 60: removed from encrypted backups through normal backup rotation (backups rotate out in 30 days; the grace period + rotation = 60 days total worst-case)
5. Post-deletion: only the following survive:
- Billing records (tax law retention)
- Anonymized MSH Intelligence aggregates (if you contributed, your data is already mathematically unrecoverable since it's mixed with 49+ others)
- Suppression list entry (to prevent accidentally re-emailing after you unsubscribed)
- Consent log for the account (to prove your consent history was properly recorded)

Deletion by MSH action

If MSH terminates your account for Terms violation:
- 14-day grace period to export your data (unless violation involves fraud, spam, or illegal content, in which case immediate)
- Otherwise same process as self-serve

Deletion on inactivity

Free-tier accounts with no login for 24 months receive a 30-day warning email, then are deleted if still inactive. Paid accounts are not subject to inactivity deletion as long as billing is current.

Data minimization

We follow the data minimization principle (GDPR Art. 5(1)(c), DPDP §4(2)):
- Only collect what we need to deliver the Service you're using
- Reduce precision of data we don't need raw (e.g., storing country instead of full IP when possible)
- Purge intermediate processing data (e.g., LLM prompt logs) after 90 days unless needed for debugging
- Never store OAuth refresh tokens of disconnected accounts

Exceptions

We may extend retention beyond the schedule above when:
- Law requires it — e.g., tax records for 7 years, records under criminal investigation
- Legal claims are possible or pending — data relevant to a claim is preserved until resolved + the statutory limitation period
- You ask us to — if you specifically ask us to preserve data longer (e.g., archived campaigns you might want to review)

Your control

You can at any time:
- Export all your data (GDPR Art. 20 / CCPA / DPDP §11): Settings → Privacy → Export
- Delete your account (GDPR Art. 17 / CCPA §1798.105 / DPDP §12): Settings → Account → Delete
- Correct inaccurate data (GDPR Art. 16 / CPRA / DPDP §12): Edit inline, or email privacy@marketingsohigh.com
- Restrict processing in specific situations: email privacy@marketingsohigh.com

Changes to this policy

Material changes will be announced by email to all registered users at least 30 days before they take effect.

Contact

Questions? privacy@marketingsohigh.com.


Change history

Date Version Change
2026-04-16 1.0 Initial policy