Data Retention & Deletion Policy
CircleRoll LLC / SpendBeaver · Last reviewed: July 22, 2026 · Next review: January 22, 2027
What we retain
Account data (identity, auth) and Plaid-retrieved financial data (transactions, balances, and where applicable identity/liability data), while the account is active, to provide product features.
Retention period
Retained for the life of the account. On account deletion, consumer data is removed from production systems within 30days, except a limited subset required for legal/tax/regulatory obligations, kept only as long as required then deleted. Backups purge on the hosting provider's standard cycle.
User rights
Export (CSV/PDF/JSON) available anytime, free, regardless of subscription status. Deletion available in-app, honored promptly. A lapsed subscription does not trigger deletion — data stays viewable and exportable.
Plaid lifecycle
On disconnect or account deletion, the Plaid Item is removed via /item/remove and data pulls stop. For lapsed accounts, we pause sync on lapse, notify approximately 3 days before disconnection (email and in-app), then remove the Plaid Item so data isn't retrieved for inactive non-paying users indefinitely. Your ledger remains viewable and exportable.
Compliance
Intended to comply with applicable US data privacy laws; reviewed at least every 6 months.