How long Gloss keeps data
Written for the privacy policy to copy. Plain English. Each line says what the data is, where Gloss keeps it, how long, what deletes it, and where in the code that happens. Line numbers are as of mission G9 (October 2026).
Two rules apply to everything below:
- Deleting your account deletes all of it. Every row with your account id is deleted at once, and your personal encryption key is destroyed, so anything encrypted with it (including in old backups) can no longer be read. If a step fails, the deletion is retried every hour until it finishes. Proof:
api/src/accounts/data-rights.ts:126-153(the deletion),:156andapi/src/accounts/index.ts:43(the hourly retry),api/src/accounts/routes-me.ts:278-280(it starts the moment you ask). - The clocks run every hour. The "deleted after" periods below are checked by hourly jobs:
workers/src/main.ts:61(notifications),:62(email),:65(everything else inapi/src/privacy/retention.ts).
The table
| Data | Where it is stored | How long it is kept | What deletes it | Proof |
|---|---|---|---|---|
| Account: login email, backup and school email, first name, adult confirmation | Gloss database, users | Until you delete your account | Account deletion | api/src/accounts/data-rights.ts:126-153 |
| Email subject and body | Gloss database, email_messages, encrypted with your personal key | 30 days after Gloss downloads the email | Hourly email purge | workers/src/email/sync.ts:18,61 (30 days), :191-198 (purge), workers/src/main.ts:62 |
| Email sender name and address, and the AI's one-line summary of the email | Gloss database, email_messages, encrypted with your personal key | 30 days after download, the same as subject and body | Hourly email purge | encrypted: workers/src/email/sync.ts:57, workers/src/ai/pipeline.ts:274; purge: workers/src/email/sync.ts:194 |
| What is left of an email after 30 days: when it arrived, its flags (important, event, sensitive, phishing) and which deadlines it created. No words from the email | Gloss database, email_messages | Until you disconnect that mailbox or delete your account | Disconnect (rows deleted with the mailbox) or account deletion | api/src/intake/migrations/0003_email.sql:32 |
| Mailbox sign-in tokens (Google, Microsoft) | Gloss database, email_connections, encrypted with your personal key | Until you disconnect or delete your account | Disconnect or account deletion; the token is first revoked at Google or Microsoft | api/src/privacy/index.ts:23-37 |
| Deadlines and events (items), including ones found in email, and their change history | Gloss database, items and related tables | Until the source removes them, you delete them, or you delete your account. Items that came only from a mailbox are deleted when you disconnect it | Your action, disconnect, or account deletion | api/src/intake/email/service.ts:228-243 |
| What an item keeps from an email | items | Only what you need on screen: title, date, place, course. No copy of the email's summary and never the sender's name: "changed by" says "your instructor's email" or the instructor's name from your own class schedule | — | workers/src/ai/pipeline.ts:120-125; old rows cleaned by api/src/intake/migrations/0008_email_sealed_envelope.sql |
| Course site calendar link | Gloss database, feeds, encrypted with Gloss's system key | Until you remove it or delete your account | Your action (its events go with it) or account deletion | api/src/intake/feeds/service.ts:33, api/src/intake/routes/feeds.ts:71 |
| Class schedule screenshots and PDFs | Never stored | — | Read once, not saved | api/src/imports/index.ts:186 |
| Syllabus files and pasted syllabus text | Gloss server disk, encrypted with your personal key | Until you remove it or delete your account | Your action or account deletion | api/src/imports/index.ts:270,277 |
| Study library files | Gloss server disk, encrypted with your personal key | Until you remove them or delete your account. An upload that never arrived is cleared after 1 day | Your action, the 1 day cleanup, or account deletion | api/src/smart/library.ts:298-300 |
| Lecture recordings (audio) | Gloss server disk | Deleted right after transcription, whether it works or not, and if you withdraw permission for Groq | Automatic | api/src/smart/library.ts:245-248,276,305-310 |
| Lecture transcripts, tutor chats | Gloss database, encrypted with your personal key | Until you delete them or your account | Your action or account deletion | material_chunks.text_sealed, tutor_messages.text_sealed |
| Push notifications sent to your phone | Gloss database, push_outbox | 7 days after sent | Hourly notification purge | api/src/notifications/push.ts:218-224, workers/src/main.ts:61 |
| Reminders that already fired (or were skipped or cancelled) | Gloss database, reminders | 7 days | Hourly notification purge | workers/src/reminders/engine.ts:442-457 |
| Device push tokens | Gloss database, devices | Until you delete your account | Account deletion | api/src/accounts/data-rights.ts:126-153 |
| Sessions | Gloss database, stored only as hashes; a sign-in lasts at most 60 days | Until you delete your account | Account deletion | api/src/accounts/sessions.ts:18 |
| Sign-in codes (the 6 digit codes) | Gloss database, stored only as hashes; valid 10 minutes | 1 day | Hourly retention job | api/src/privacy/retention.ts:13,52 |
| Sign-in safety counters (too many tries) | Gloss database, hashes only | 1 day | Hourly retention job | api/src/privacy/retention.ts:54-55 |
| "Link this sign-in to your account" requests | Gloss database, pending_links | 1 day | Hourly retention job | api/src/privacy/retention.ts:53 |
| Mailbox connection requests (OAuth states) | Gloss database, oauth_states; valid 10 minutes | 1 day | Hourly retention job | api/src/privacy/retention.ts:58 |
| Claude / ChatGPT connection requests and codes | Gloss database, oauth_requests, oauth_codes (codes as hashes), connector_preapprovals | 1 day | Hourly retention job | api/src/privacy/retention.ts:59-61 |
| Claude / ChatGPT access | Gloss database, tokens stored only as hashes. Access token 1 hour, refresh token 30 days | Until you disconnect the app or delete your account | Your action or account deletion (revoked) | api/src/connector/oauth.ts:22-23 |
| Payments and plan | Gloss database, entitlements, payments. No card numbers, ever | Until you delete your account | Account deletion | api/src/payments/migrations/0000_init.sql:29 |
| Your customer record at Stripe (computer purchases) | Stripe | Until you delete your account | Account deletion deletes it at Stripe (this also stops any Stripe subscription) | api/src/payments/customer-deletion.ts:13-27, called from api/src/accounts/data-rights.ts:137-140. Shown working: reports/g9/stripe-delete-live.txt |
| Your customer record at RevenueCat (iPhone purchases) | RevenueCat | Until you delete your account | Account deletion deletes it at RevenueCat once Gloss's RevenueCat key is set (until then the deletion records that it was skipped). Apple keeps its own purchase records; cancel an App Store subscription in your Apple account | api/src/payments/revenuecat.ts:191-197, called from api/src/accounts/data-rights.ts:140 |
| Messages you send to support (email, name, school, message) | Gloss database, support_requests. Not linked to your account | 180 days | Hourly retention job | api/src/privacy/retention.ts:9,28 |
| Classmates' date and room corrections (counts, your opaque reporter code, the proposed date or room, and the item's official date, date only) | Gloss database, correction_tallies, correction_voters, correction_votes. Not linked to your name; no email text | 30 days after the item's official date passes | Hourly retention job | api/src/privacy/retention.ts:11,33-46; the date is saved at api/src/smart/corrections.ts (report) |
| Correction safety counters (reports per day, false reports) | Gloss database, correction_reporter_stats, opaque code only | Deleted once none of your corrections is left and you reported nothing for 30 days | Hourly retention job | api/src/privacy/retention.ts:47-49 |
| Audit log (security events) | Gloss database, IP addresses stored only as hashes | Until you delete your account; then one "account deleted" line remains with an unreadable code instead of your id | Account deletion | api/src/accounts/data-rights.ts:152 |
| Website early access list (email) | Cloudflare | Until you unsubscribe (deleted at once) or we remove it | Unsubscribe link | site/functions/api/unsubscribe.js:1-3 |
| On your iPhone | Your phone: secrets in the Keychain (this device only), screens cached up to 7 days | Until you sign out (wiped) | Sign out | app/src/lib/storage.ts:22-27, app/src/data/query.tsx:21,25 |
| On your computer | Your computer: secrets encrypted by the operating system | Until you sign out (wiped) | Sign out | desktop/src/secureStore.ts |
| Server logs | Gloss server. Never contain email content | System journal 30 days (500 MB cap); log files 14 days; web server access logs are off | Automatic | ops/prod/files/journald-gloss.conf:3-4, ops/prod/files/logrotate-gloss:3 |
| Backups | Cloudflare R2, encrypted, nightly. Database and personal keys; uploaded files are not backed up | 30 days (3 days on the server) | Automatic | ops/prod/backup.sh:31-32 |
What this means after you delete your account
- At Gloss: everything above that belongs to you is deleted right away, and your personal key is destroyed.
- At Stripe and RevenueCat: your customer record is deleted as part of the same deletion.
- At Google, Microsoft and Apple: the sign-in tokens Gloss held are revoked.
- In backups: backups made before the deletion still hold a copy of your data (and of your old personal key) for up to 30 days, then they are deleted.
- Support messages and classmates' corrections are not linked to your account, so they follow their own clocks above (180 days; 30 days after the class date).