Skip to content
FAIRMIND
What it doesEvidence graphCapability truthResearch
Sign inRequest access
Menu
What it doesEvidence graphCapability truthResearchDocsSign inRequest access
Back to FairMind

FairMind legal

Data retention policy

Last updated
1 August 2026
Reading time
7 minutes
Version
1.0

Maximum retention by website data category, with deletion, backup, and exception rules stated plainly.

1. Policy rule

FairMind keeps public-website information for the shortest period reasonably needed for the stated purpose, subject to the maximums below. A maximum is not a promise to keep information for the entire period. Data may be deleted or aggregated sooner.

2. Retention schedule

CategoryMaximum active retentionStart pointReason
Anonymous web and product analytics events12 monthsEvent timestampJourney and content analysis across meaningful periods
Session replays30 daysRecorded session endShort-lived interaction and usability diagnosis
Web performance, heatmap, dead-click, rage-click, media, and client-error events12 monthsEvent timestampRegression comparison and incident diagnosis
Contact and access-request submissions24 monthsLast substantive interactionReply, qualification, and relationship context
Hosting, delivery, and abuse-prevention logs under FairMind's control90 daysRequest or security eventAvailability, investigation, and abuse prevention
Deletion-request and consent-response audit records received by FairMind3 yearsRequest closure or superseded choiceDemonstrate that the request was handled

3. Consent-manager records

The external consent manager owns the durable preference record and its configured retention. FairMind's website bridge receives only the current analytics decision, source, and policy version in memory. When the manager is selected and configured, its published retention must not exceed the period reasonably required to demonstrate consent and withdrawal.

4. Deletion and withdrawal

Analytics withdrawal stops future capture and session replay; it does not rewrite events that were lawfully collected before withdrawal. A verified deletion request is removed from active systems within 30 days unless an exception applies. Where a provider exposes separate deletion queues, FairMind initiates the corresponding provider deletion as part of the same request.

5. Backups

Deleted information may remain in encrypted, access-restricted backups until the backup expires, for no more than 90 additional days. Backups are not restored to avoid a completed deletion. If restoration is required for disaster recovery, deletion records are reapplied before ordinary use.

6. Aggregation and de-identification

FairMind may retain statistical or aggregated information longer when it no longer identifies or can reasonably be linked to an individual or device. Removing a direct field while keeping a linkable identifier is not treated as de-identification.

7. Exceptions

FairMind may retain limited information beyond a scheduled period when required by law, a legal hold, fraud or security investigation, dispute, contractual record duty, or a request from the person to preserve it. Access is restricted to the exception purpose, and deletion resumes when the exception ends.

8. Configuration accountability

Service settings, exports, and deletion jobs must match this schedule before a data category is enabled. A policy page is not a retention control by itself. FairMind reviews the schedule when a provider, purpose, or legal requirement changes and updates the version and date shown above.

The short version

Most anonymous analytics lasts at most 12 months. Replay lasts 30 days. Website forms last at most 24 months after the conversation ends. Routine logs under FairMind's control last 90 days.

Why the dates differ

A replay is useful for a short debugging window. A business conversation needs enough context for a follow-up. A deletion record may need to outlive both so FairMind can prove the deletion happened. Giving every table row “forever” would be simpler and indefensible.

What deletion means

Active copies are removed within 30 days after verification, provider queues are included, and encrypted backups age out within 90 additional days. Legal holds and security investigations are narrow exceptions, not a second retention policy hiding in a trench coat.

Retention lifecycle

StageControlDeadlineEvidence
CollectPurpose and consent gateBefore data enters a providerConfigured category and policy version
UseAccess restricted to the stated purposeDuring active retentionProvider and access configuration
ExpireProvider retention or deletion jobCategory maximumDeletion setting, job, or provider record
Delete on requestVerify, remove active copies, queue providersWithin 30 days unless an exception appliesRequest closure record
Age out backupsRestricted backup lifecycleWithin 90 additional daysBackup schedule

For questions or a verified deletion request, use the contact page and identify the relevant submission without sending credentials or production AI data.

Exact terms control. Plain-language notes explain; they do not replace them.

Ask a precise question

AI evaluation · safety · governance

Turn test results into evidence a decision can survive.

Bind the exact subject, evaluator, threshold, artifact, limitation, finding, remediation, retest, and human review in one defensible chain.
Start with a real evidence path.

No inflated readiness score. No automatic compliance claim. We begin with what was actually tested.

Request accessRead the evidence model
EvaluatePreserveReviewRemediateRe-testGovern
FAIRMIND

AI assurance evidence, not another compliance theatre dashboard.

Vendor-neutral evaluation, safety, and governance infrastructure.

Product

What FairMind doesEvaluation and assurance featuresUse casesEvidence-chain walkthroughWhy it is different

Evidence

Assurance graphCapability truthResearch and limitationsRecovery roadmapDocumentationSource repository

Company

About FairMindResearch notesAsk a precise questionRequest access

Legal, plainly

Privacy without fogTracking data pathRetention with datesTerms without interpretive dance

Product truth: missing evidence never becomes a pass, a mapping never accepts itself, and FairMind does not certify AI systems.

© 2026 FairMind