Temporary public-resource handoffs
When you explicitly continue a free-resource result into PlyOps, approved result fields are usable in that browser tab for up to two hours so you can review them after sign-in. They are not put in the URL or anonymous measurement event. An open resource or review screen clears the handoff at expiry. If full-page sign-in or provider navigation replaced that screen, PlyOps rejects and removes the expired values on the next continuation check; closing the tab also clears them. They become workspace data only if you explicitly save them in a PlyOps record.
Account and workspace data
Kept while the account is active and then removed or de-identified through the account-deletion process, except when a longer period is required for legal, security, fraud, tax, or transaction records.
Cloud access after a paid plan ends
The Cloud workspace becomes read-only and self-service recovery remains available to the owner for 30 days. PlyOps queues email notices when the window opens, seven days before it closes, and one day before it closes. The owner can download eligible complete records and original files or move the verified copy into one browser for Free Local use. After the deadline, the retained Cloud copy is not automatically deleted; reactivation, account-specific support, and whole-account deletion remain available.
Marketplace order and shipment records
Privacy-minimized order records and protected shipment-review history, including carrier and tracking values you submitted, remain with the connected workspace until you delete that marketplace's cached data, delete the account, or a verified provider privacy request requires removal. A provider-supplied shipment recipient display name is shown and retained for no more than 90 days from the order date, then hidden and cleared while the non-identifying order history remains. Disconnect stops future access but does not by itself erase the seller's retained order and action history.
Support conversations
Support cases and messages are scheduled for deletion after 180 days. Private support screenshots are scheduled for deletion after 30 days unless a shorter operational need applies.
Feature requests
Original submissions remain private. A moderated public title and summary may remain on the roadmap after the author's account is deleted, without the deleted account attached.
Content-free product usage
Controlled action categories and count ranges are retained for up to 90 days. Daily aggregate service metrics may remain because they do not contain product content or identify an individual product.
Anonymous public resource progress
Controlled resource, completion, and continuation categories are retained for up to 90 days. They are not linked to an account or workspace. Daily aggregate counts may remain because they contain no tool inputs, results, product content, or visitor profile.
Optional PostHog analytics
Controlled analytics events are retained for up to 90 days. Privacy-limited public-page recordings, when separately enabled, use the configured PostHog replay retention period. Private workspace, account, product, order, marketplace, file, support, and public-tool input or result regions are excluded from replay.
Security and rate limiting
Short-lived HMAC digests derived from request identifiers are kept only for the applicable policy window, generally no more than 24 hours. Hosting and infrastructure providers may keep security logs under their own retention schedules.
Billing and legal records
PlyOps and Stripe may retain transaction, invoice, subscription, tax, fraud, dispute, and legal records for periods required by law or legitimate business recordkeeping.