| Customer-facing dashboard decision records | Signal source, decision outcome, policy flags, response code, timestamps | Retention targets: Developer 30 days, Pro 1 year, Enterprise negotiated. Records are purged by an operator-scheduled retention job (purge_gpc_signals_before); until that schedule is configured for an environment, records are retained — see the retention note below. |
| Compliance audit records | Decision evidence retained for compliance support and service operation | May differ from dashboard availability; governed by Privacy Policy or signed agreement |
| Account and site configuration | Company name, user email, domains, DPA status, API key metadata | Retained while the account is active, then deleted subject to legal and operational requirements |
| Billing records | Plan, Stripe customer ID, subscription status, invoices handled by Stripe | Retained as needed for billing, tax, accounting, dispute, and legal obligations |