Skip to content

Data Disposal Policy

The purpose of this policy is to establish guidelines and procedures for the secure disposal of customer data stored in cloud environments, ensuring compliance with data protection regulations and maintaining the confidentiality of customer information.

This policy applies to all customer data stored in cloud environments, specifically:

  • Amazon S3 (Simple Storage Service)
  • Fly.io platform volumes
  • Google Drive

Customer data is exclusively stored in the following cloud environments:

  • Amazon S3 buckets
  • Fly.io platform volumes
  • Google Drive

No customer data is permitted to be stored on employee laptops or any other local devices.

  • We retain customer data for as long as customers maintain an active subscription to our services.
  • Upon request from a customer or user, we will delete their personally identifiable data in accordance with our Data Disposal Procedures.
  • For customers who have churned (cancelled their subscription), we may delete their data after a specified period, typically 90 days after the end of their subscription, unless otherwise specified in their contract or by applicable laws and regulations. This is not required, and data may be retained indefinitely if useful for analytics, or for any other reason.
  • In cases where regulatory requirements or contractual obligations necessitate longer retention periods, we will comply with those requirements.
  1. Data deletion:
  • Use S3’s object deletion API or console to remove individual objects.
  • For bulk deletions, use S3 batch operations or lifecycle policies.
  1. Bucket deletion:
  • Empty the bucket of all objects and delete the bucket itself when no longer needed.
  1. Versioning:
  • If versioning is enabled, ensure all versions of objects are deleted.
  1. Data Deletion:
  • Use Fly.io’s API or CLI to securely delete data from volumes.
  1. Volume Destruction:
  • Destroy volumes that are no longer needed using Fly.io’s volume destruction feature.
  • We do not delete customer data from backups, and instead allow the backup rotation to take care of this for us.

After deletion, verify that data has been successfully removed from all locations.

Maintain logs of all data disposal actions for audit purposes.

  1. Employees are prohibited from storing customer data on local devices, including laptops.
  2. All data access and disposal must be done through secure, authorized cloud interfaces.
  1. Customer Request: Promptly dispose of data upon customer request, subject to legal and contractual obligations.
  2. End of Retention Period: Automatically dispose of data that has reached the end of its defined retention period.
  3. Contract Termination: Dispose of customer data upon termination of services, as per contractual agreements.
  1. Maintain detailed logs of all data disposal activities.
  2. Conduct regular audits to ensure compliance with this policy.
  3. Review and update this policy annually or when significant changes occur in data storage practices.
  1. This policy is designed to comply with relevant data protection regulations, including but not limited to GDPR, CCPA, and other applicable laws.
  2. Any violations of this policy may result in disciplinary action, up to and including termination of employment.
  • This policy will be reviewed annually and updated as necessary to reflect changes in technology, business needs, or regulatory requirements.
  • Last reviewed/updated: 2026-08-25

Internal & Confidential: This page is only available in the internal handbook and contains confidential information.