Active workspaces
We keep workspace records, provider account records, hashed API keys, endpoint routes, runtime records, billing events, and audit logs while a workspace is active or canceling.
Billing suspension
When a recurring payment fails, hosted service remains online for a 24-hour grace period. If billing is not restored, we remove the workspace VMs and disable their routes, but keep the workspace record, provider account identity, and encrypted provider credentials. This retained connection data allows automatic redeployment after successful payment. API keys may be revoked as part of suspension or deletion.
Cancellation at period end
When an owner cancels at period end, access continues until the paid-through date. The owner can remove that cancellation before cleanup begins. At the effective date, a retryable lifecycle worker confirms billing state, destroys runtime resources, revokes API keys, disables endpoint routes, expires onboarding sessions, and marks hosted records deleted. The encrypted provider credentials and provider identity metadata are retained so an authorized support restore does not require reconnecting the provider account.
Immediate deletion
When an owner deletes immediately, access is disabled and deletion is queued. A retryable lifecycle worker cancels managed billing, destroys runtime resources, revokes API keys, disables routes, marks provider accounts deleted, and completes the deletion request. Provider credentials are retained in the configured secret store for an authorized restore; they are not returned through lifecycle or support APIs.
Provider and infrastructure limits
Some cloud resources, provider-side data, backups, logs, and cached telemetry may require asynchronous cleanup or provider support. This policy does not promise real-resource lifecycle work beyond what the deployed runtime provider and background jobs currently support.
Login account deletion
Users must wait until every owned workspace is fully deleted. Current code then anonymizes the user profile, removes tenant memberships, and records the completed deletion request. Scheduling a workspace for future deletion is not sufficient.
Audit and operational records
We may retain billing, security, audit, and operational records for legal, dispute, abuse-prevention, and financial reporting needs, with customer identifiers minimized where deletion workflows support it.