Data Retention Schedule
Effective 14 September 2026Last updated 14 September 2026retention-2026-09-14
This page lists every class of data ARLogic LLC holds for fixRAgent, the system it lives in, how long it stays there, and the job or the request that removes it. It is the working companion to the Privacy Policy: the policy says what we collect and why, and this schedule says exactly when each thing goes.
The schedule
| what | where it lives | how long | what removes it | privacy policy section |
|---|---|---|---|---|
| a triage card's record (answer, photo hash, versions, role, arm) | Supabase — our database, under a random diagnosis_id | Until you ask us to delete it | Your request to legal@fixragent.com | §8 |
| a kept photo (repair-guidance tool, "Keep this photo" ticked) | Supabase — a private bucket in the United States, named by the file's hash | 30 days | A daily sweep that deletes the file and clears the pointer, and leaves the consent record standing | §3 |
| a photo on the triage card path | Google — the Gemini model service; we keep no bytes of it | 55 days at Google | Google's own 55-day expiry | §3 |
| repair-guidance results under an account | Supabase — our database (diagnoses) | Until you delete the result or the account | Deleting it in the app, or your request | §8 |
| a guest result on our side | Supabase — our database (diy_guest_scans) | Until you ask us to delete it | Your request, using the details held on your device | §8 |
| an email address or phone number on a card | Supabase — our database, next to the version of the consent line you saw | Until you unsubscribe or ask us to delete it | The unsubscribe line in any card email, or your request | §4 |
| unsubscribe records | Supabase — our database (triage_email_optout) | Kept, so that the unsubscribe keeps working | Kept by design | §4 |
| the record that a follow-up was started for a card | Supabase — our database (triage_mail_log), holding a hash of the address rather than the address | Kept with the card, so that no follow-up is started twice | Kept by design | §4 |
| consent records (which text you saw, when) | Supabase — our database, next to the record they belong to | Kept, as the proof that consent was given | Kept by design | §8 |
| outcome answers | Supabase — our database (outcomes), under the card's diagnosis_id | Kept with the card, and de-identified once the card is deleted | Your request, which de-identifies them | §5 |
| feedback | Resend — delivered to us as email; Anthropic — read once to categorise it and draft a reply for us | Until you ask us to delete it | Your request | §8 |
| account, plan and Stripe identifier | Supabase — our database (fixr_users); Stripe — your customer record | Until you delete the account; Stripe keeps its own record of payments | Deleting the account, or your request | §8 |
a thumbs-up or thumbs-down on an answer (diagnosis_votes) | Supabase — our database | Until you ask us to delete it | Your request | §8 |
| properties and assets you register | Supabase — our database (properties, assets) | Until you delete them or the account | Deleting them in the app, or your request | §8 |
| payment records | Supabase — our database (payment_logs); Stripe — its own invoice record | Kept, as the record of what was paid | Kept by design, as financial record-keeping requires | §8 |
| tenant, manager and roof-inspection photos, and the intake records around them (accounts, properties, units, tickets, intake codes and their scan log) | Supabase — private buckets and our database | Until the account holder or the contractor deletes them or asks us to; the intake rate-limit record for 24 hours | The account holder deleting them, or your request | §8 |
| a tenant's email address on a ticket | Supabase — our database (pm_tickets) | Until the account holder deletes the ticket or the tenant asks us to | Deleting the ticket, or your request | §8 |
| our outreach and prospect records (section 2.9) | Supabase — our database | Until the person asks to be removed | Your request | §8 |
| product analytics events at Google Analytics, PostHog and Vercel Web Analytics | Google Analytics, PostHog and Vercel | Each tool's own period, set out in the processor rows below | Deleting a person and their events in each tool, on your request | §8 |
our own event store (fixr_events: device id, events, city, region, country, browser type) | Supabase — our database | For as long as we operate the service | Your request for your device's rows, with the fixr_did value from your browser's storage | §8 |
the QR scan log (qr_scans: time, network address, browser, referring page, city, country, device type) | Supabase — our database | For as long as the link exists | Retiring the link, or your request for the rows for your address | §8 |
| the contractor list and its send record | Supabase — our database | Until the contractor asks to be removed | Your request | §8 |
| error reports and hosting logs | Sentry — error reports; Vercel — request logs | Each provider's own period, set out in the processor rows below | Each provider's own expiry | §8 |
| the prompt, the photo and the answer at the model service | Google — the Gemini API | 55 days | Google's own expiry | §6 |
| our database, our file storage and sign-in | Supabase — United States (US East) | A live row stays until it is deleted here; Supabase's daily backups hold the last 7 days on our plan, and Storage objects sit outside those database backups | Deleting the row here, then the backup window passing | §6 |
| our web hosting, server functions and request logs, and the page views and page-load timings its analytics report | Vercel | 1 day of runtime logs, and 30 days with the observability add-on | Vercel's own expiry | §6 |
| email delivery | Resend | 30 days for email and log data, and its backups persist for 7 days | Resend's own expiry | §6 |
| payments and card details | Stripe | For as long as Stripe provides the service, and afterwards for the periods its legal, tax and fraud-prevention duties set | Stripe's own schedule | §6 |
| page views and interactions | Google Analytics | Up to 14 months for the data behind explorations; standard aggregated reports are unaffected by that setting | Deleting a person's data in the property, on your request | §6 |
| product analytics events | PostHog | 1 year on the free plan and 7 years on a paid plan | Deleting a person together with their events and recordings, on your request | §6 |
| the request that loads the typeface and the database client library | Google Fonts and esm.sh | Each host's own request-log period | Each host's own expiry | §6 |
| the request that loads the stylesheet on most site pages | Tailwind Labs (cdn.tailwindcss.com) | Its own request-log period | Its own expiry | §6 |
| the request that loads script libraries on seven site pages | Cloudflare — cdnjs | The period Cloudflare's stated business purposes and legal duties set | Cloudflare's own schedule | §6 |
| the request that loads a library on the QR admin page | unpkg | Its own request-log period | Its own expiry | §6 |
| a property address, when a roof-size estimate is run | Google Maps and Google Solar | Google's own schedule; Google anonymises advertising data in server logs by removing part of the address after 9 months | Google's own expiry | §6 |
| error reports from our servers, and from your browser on the tenant-intake pages | Sentry | 90 days for errors and 30 days for logs | Sentry's own expiry | §6 |
| the text of feedback you send us | Anthropic — Claude | Inputs and outputs are deleted within 30 days | Anthropic's own expiry | §6 |
| a video embedded in some repair guidance | YouTube | Google's own schedule | Google's own expiry | §6 |
| your visit, when you follow a link to a parts or trades site | Amazon, The Home Depot, Lowe's, Angi and Thumbtack | We send them nothing, so we hold nothing to remove; each site keeps its own record of the visit under its own policy | Each site's own schedule | §6 |
| our own encrypted backups of the database and the code | Hetzner — our own server; each set is encrypted before it is written | The last five sets of each kind, which reaches about five weeks | A nightly job that prunes to the last five sets | §8 |
| the off-site copy of that nightly set | Cloudflare — R2 object storage in the European Union, encrypted | 14 days | A nightly job that deletes sets older than 14 days | §8 |
| server snapshots | Hetzner — rolling images of the whole server | 7 daily snapshots | A daily job that keeps 7 and removes the rest | §8 |
| our permanent archive of consented outcome photos and results | Hetzner — a content-addressed store on our own server | Kept, as the record of what each repair turned out to be; a photo reaches it only where you ticked consent | Your request to legal@fixragent.com | §7 |
| our evaluation exports (a photo, the verdict and the human signal, under file names that are hashes) | Hetzner — a working folder on our own server | Kept while the engine is being measured | Your request to legal@fixragent.com | §7 |
How to ask
Email legal@fixragent.com, or use the feedback form in the app. Write from the address you used, or give us the diagnosis_id printed on the card, so that we can find the right records. We act within 30 days and tell you when it is done, as §9 of the Privacy Policy sets out.
A deletion request reaches every copy of the database within about five weeks: the live row goes at once, the off-site copy ages out after 14 days, the server snapshots after 7 days, and our own encrypted sets once the last five have rolled forward.
Sources
Each period above that belongs to another company was read from that company's own published page on the date shown.
- Google — Gemini API additional usage policies, read 14 September 2026
- Supabase — Database backups, read 14 September 2026
- Vercel — Runtime logs, read 14 September 2026
- Resend — GDPR and data protection, read 14 September 2026
- Stripe — Privacy policy, read 14 September 2026
- Google Analytics — Data retention, read 14 September 2026
- PostHog — Events retention, read 14 September 2026
- Sentry — Data retention periods, read 14 September 2026
- Anthropic — How long do you store my organization's data, read 14 September 2026
- Cloudflare — Privacy policy, read 14 September 2026
- Hetzner — Privacy policy, read 14 September 2026
- Google Fonts — Google data retention, read 14 September 2026
- Google Maps and Google Solar — Google data retention, read 14 September 2026
- YouTube — Google data retention, read 14 September 2026