How long we keep each type of data and how deletion works.
Last updated: 25 March 2026
Under GDPR Art. 5(1)(e), CPRA §1798.100(a)(3), and DPDP §8(7), personal data must be kept no longer than necessary for the purposes for which it was collected. This policy specifies how long MSH retains different categories of data and what happens when retention periods end.
| Category | What it includes | Retention period | What happens after |
|---|---|---|---|
| Account identifiers | Email, name, company, role, password hash, OAuth identifiers | While account is active + 30 days | Hard-deleted from primary systems; removed from backups within 60 days |
| Authentication logs | Login timestamps, IP address at login, device info | 12 months | Hard-deleted |
| Billing records | Invoices, payment history, tax info | 7 years from transaction date | Retained for tax/accounting law (Indian Income Tax Act, EU VAT Directive); then deleted |
| Customer content | Articles, campaigns, contacts, keywords, plans, uploaded files | While account is active; 30 days after account deletion | Hard-deleted from primary + backup |
| Integration data — Search Console / Analytics | Queries, positions, clicks, sessions, etc. (when Phase 2 activates) | Rolling 24 months of raw data; older aggregated to monthly summaries | Raw data beyond 24 months overwritten in place |
| Plugin telemetry | SEO scores, on-page metrics reported by the MSH plugin | Rolling 12 months | Older data aggregated to weekly averages |
| Support conversations | Chat logs, tickets, emails with hello@ or privacy@ |
3 years from last message | Hard-deleted |
| Security logs | Access logs, admin queries, audit trail | 12 months (extended to 24 if an incident investigation is ongoing) | Hard-deleted |
| Consent records | Toggle changes, consent captures, opt-outs | Duration of account + 3 years after | Retained to defend against complaints about historical processing |
| Marketing list data | Email subscribers to MSH newsletter | Until unsubscribe + 30 days | Hard-deleted, with unsubscribe flag retained 2 years to honor suppression |
| Anonymized MSH Intelligence aggregates (Phase 3) | Statistical patterns with n≥50 contributors — NOT personal data under GDPR Recital 26 | Permanent | N/A — anonymized data is not subject to retention limits |
| Legal hold data | Anything subject to active litigation, regulatory request, or legal obligation | Until hold is released | Retained as required by law |
When you click "Delete my account" in Settings:
1. Account is immediately disabled — logins blocked, API tokens revoked
2. 30-day grace period — you can contact privacy@marketingsohigh.com to restore within this window (once elapsed, deletion is irreversible)
3. Day 30: primary database deletion of all Tier 1 data (account data, content, integration data, plugin telemetry) using DELETE statements
4. Day 60: removed from encrypted backups through normal backup rotation (backups rotate out in 30 days; the grace period + rotation = 60 days total worst-case)
5. Post-deletion: only the following survive:
- Billing records (tax law retention)
- Anonymized MSH Intelligence aggregates (if you contributed, your data is already mathematically unrecoverable since it's mixed with 49+ others)
- Suppression list entry (to prevent accidentally re-emailing after you unsubscribed)
- Consent log for the account (to prove your consent history was properly recorded)
If MSH terminates your account for Terms violation:
- 14-day grace period to export your data (unless violation involves fraud, spam, or illegal content, in which case immediate)
- Otherwise same process as self-serve
Free-tier accounts with no login for 24 months receive a 30-day warning email, then are deleted if still inactive. Paid accounts are not subject to inactivity deletion as long as billing is current.
We follow the data minimization principle (GDPR Art. 5(1)(c), DPDP §4(2)):
- Only collect what we need to deliver the Service you're using
- Reduce precision of data we don't need raw (e.g., storing country instead of full IP when possible)
- Purge intermediate processing data (e.g., LLM prompt logs) after 90 days unless needed for debugging
- Never store OAuth refresh tokens of disconnected accounts
We may extend retention beyond the schedule above when:
- Law requires it — e.g., tax records for 7 years, records under criminal investigation
- Legal claims are possible or pending — data relevant to a claim is preserved until resolved + the statutory limitation period
- You ask us to — if you specifically ask us to preserve data longer (e.g., archived campaigns you might want to review)
You can at any time:
- Export all your data (GDPR Art. 20 / CCPA / DPDP §11): Settings → Privacy → Export
- Delete your account (GDPR Art. 17 / CCPA §1798.105 / DPDP §12): Settings → Account → Delete
- Correct inaccurate data (GDPR Art. 16 / CPRA / DPDP §12): Edit inline, or email privacy@marketingsohigh.com
- Restrict processing in specific situations: email privacy@marketingsohigh.com
Material changes will be announced by email to all registered users at least 30 days before they take effect.
Questions? privacy@marketingsohigh.com.
| Date | Version | Change |
|---|---|---|
| 2026-04-16 | 1.0 | Initial policy |