Data retention and deletion

This page states how long SupaMail retains each data category and how deletion begins. Some controls are automatic. Mailbox disconnection and full account deletion currently require support.

Current retention schedule

DataCurrent retentionHow deletion starts
User, Tenant, and mailbox configurationRetained while the service is active. Trial expiry or subscription cancellation pauses access but does not automatically erase the Tenant.Support-assisted account or mailbox deletion request
Mailbox credentials and provider tokensRetained in encrypted form until the mailbox or target is disconnected or deleted.Support-assisted disconnection or account deletion request
Message metadata, parsed bodies, and Managed search dataRetained while mirrored. Provider-deleted messages are removed from hosted body Storage and search after the mirror accepts the deletion.Provider deletion sync or support-assisted deletion request
Attachment bytesNot durably stored by SupaMail. Incoming files are fetched from the mailbox on request; unsent outbound uploads expire within one hour.Successful send or automatic expiry for outbound uploads
Sync events90 days under the current hosted runtime setting.Automatic bounded daily pruning
Webhook delivery records30 days after delivery reaches a terminal delivered or dead state.Automatic garbage collection
Send operation recordsRetained until the related mailbox or Tenant is deleted.Support-assisted Mailbox Account or Tenant deletion request
Message TagsRetained until an authorized User or agent deletes the Tag or its message is deleted. Tag reads exclude missing and provider-deleted messages. A daily bounded check deletes those stored Tag rows. Tenant deletion deletes all Tags.Settings, an authorized API or MCP client, or automatic lifecycle cleanup
Billing, legal acceptance, security, and support recordsRetained only as needed for payment records, fraud prevention, legal obligations, security, and dispute resolution.Reviewed as part of an account or privacy request
Supabase service logs1 day.Automatic provider expiry
Vercel runtime logs1 hour. No log drain is configured.Automatic provider expiry
Fly runtime logsAbout 7 days. Fly publishes this as an approximate window. No external log drain is configured.Automatic provider expiry
Database, body Storage, and search backupsNo daily recovery backup or point-in-time recovery is configured. SupaMail has not configured a separate body Storage or search backup.No SupaMail-configured backup copy to erase
Other provider recordsProvider-controlled. SupaMail has not verified one exact maximum for Stripe, Rackspace, GitHub, Google Fonts, or provider-internal security records.Handled under supplier terms and applicable law

Available controls

Revoke AI and API access

Revoke the smk_ token in Settings and remove SupaMail from the AI client. SupaMail-side OAuth revocation currently requires a manual request.

Review or delete Message Tags

Review Tags, remove one Tag, or delete all Tenant Tags in Settings.

Disconnect a mailbox

Self-service mailbox disconnection is not available yet. Email hi@supamail.dev from the sign-in address and identify the mailbox. Do not send the mailbox password. Support stops synchronization and removes the stored credential.

Delete an account and synchronized data

Email hi@supamail.dev from the sign-in address and state whether the request covers a mailbox, Tenant, or User. After ownership is verified, the request covers control-plane records, credentials, mirror state, body objects, search data, caches, and active tokens.