Technical update: 11 September 2026
Data retention (technical draft)
Current engineering defaults are centrally configured and bounded. Legal retention decisions may require reviewed overrides.
Exports
Private archives expire after 24 hours by default; export history is retained for 30 days.
Deletion
The default cancellation grace period is 7 days. A minimal deleted-account tombstone is retained for 30 days to prevent accidental resurrection, then new onboarding may be allowed.
Events and sessions
Security and product analytics events default to 90 days. Device sessions default to 90 days and are revoked immediately when deletion is requested.
Ephemeral records
OAuth artifacts, share tokens, public/inline tokens and upload intents are cleaned in bounded batches after expiry; the default operational window is 24 hours.
Exceptions
Payment reconciliation and legally required records need a human legal retention decision. Postlyra cannot erase messages already delivered to Telegram.