Data Retention & Deletion Policy
Last updated: July 11, 2026
Vivus keeps personal data only as long as needed to run the service, meet legal requirements, maintain security, preserve consent evidence, and handle support or disputes. The canonical retention schedule is part of the Privacy Policy.
- Account and workspace data — kept as long as your account is active, unless you ask us to delete it sooner.
- Financial records — royalty statements, transactions, and related data may be kept longer when required for tax or legal compliance.
- Bank connections — when you disconnect a linked bank account, we remove the connection credentials immediately.
- Pre-account waitlist signups — waitlist rows may include your email address plus optional artist context such as a Spotify artist URL or Instagram handle. Pending unconverted rows are pruned after 24 months without new interaction; approved unprovisioned rows after 12 months; converted rows after 30 days; and closed, rejected, expired, or unsubscribed rows after 90 days. Verified deletion requests remove the waitlist row, including those optional profile fields, subject to legal holds and backup rotation.
- Persistent Google OAuth connections — Google Calendar, YouTube, and Google Ads access and refresh tokens are encrypted and retained for active connections. When you disconnect one of these integrations or an authenticated self-service account-deletion request is accepted, we immediately remove the active credentials from use and send a revocation request to Google. During a transient Google outage, one or more encrypted tokens may be retained only to retry revocation; they are never used to access Google data and are deleted after Google acknowledges revocation. If you reactivate your account, you must reconnect those integrations. Disconnecting Google Calendar also deletes the stored identifier for the app-created calendar, but it does not delete that calendar from Google Calendar. While YouTube remains connected, scheduled provider reads refresh current authorized data; caches not refreshed for 30 days and historical YouTube API data older than 30 days are deleted or cleared from active stores. Persistent provider failures clear cached channel identity at the 30-day mark. Disconnecting YouTube also deletes cached YouTube channel, video, analytics, comment, and commenter data from active Release Ledger stores. It does not delete videos or replies already stored by YouTube. You can also revoke Google access from your Google Account connections.
- Google Drive picker — the picker access token is transient browser-memory data and is not stored by Release Ledger. A selected file reference remains in your Asset Library until you delete it or the workspace is deleted. Deleting a reference hides it from active use immediately and marks it eligible for permanent deletion after a 30-day recovery period. It does not delete the source file in Drive.
- Other connected social platforms — when you disconnect a social account or delete your Release Ledger account, we delete its stored tokens and attempt to revoke the provider grant where the provider supports revocation.
- Security logs — retained on a rolling basis depending on how critical they are, then automatically purged.
When you request deletion, Vivus verifies your identity, checks for any legal holds, then permanently removes or anonymizes your data. Some deleted data may remain in encrypted backups until those backups naturally rotate out.
Vivus responds to verified deletion requests without undue delay, within 30 days where GDPR applies and within 45 days where California privacy law applies, unless a permitted extension or legal exception applies. If we need more time where the law allows it, we will notify you within the initial response period and explain the reason. Account closure starts a 30-day reactivation window. After that period, eligible account data is purged or anonymized, while limited records may be retained where required for legal obligations, tax or accounting records, security, fraud prevention, dispute resolution, regulatory obligations, legal claims, or backup rotation.
To request deletion, email contact@releaseledger.com.