Data Deletion Policy
Last updated: August 11, 2026
This policy describes how Ruligent deletes customer data — both automatically through retention windows and on request. It supplements the Privacy Policy and, where applicable, the Data Processing Addendum.
1. What data Ruligent holds
- Agent activity data: tool-call metadata (agent ID, tool, action, decision, reason, risk level, cost, timestamps) and bounded payload summaries. Raw payloads are never stored.
- Governance records: policies, approvals (including resolver identity and notes), spend counters, kill-switch state, and webhook delivery logs.
- Account data: organization name, member emails, hashed passwords, hashed API keys, and billing profile.
2. Automatic deletion (retention windows)
Audit events and payload summaries are purged automatically at the end of your plan's retention window — 7 days on Free, 30 days on Founder, 180 days on Operator, and 1 year on Business — with no action required from you.
3. Requesting deletion
An organization admin can request deletion of specific records or the entire organization by emailing www.ruligent.com/contact from the admin account's email address. We verify the requester is an organization admin before acting.
4. Timelines
- Acknowledgement: within 3 business days of a verified request.
- Deletion from production systems: within 30 days of verification. This covers agent activity data, governance records, and account data.
- Backup expiry: database backups roll off automatically; deleted data leaves all backups within 30 days after production deletion. Backups are never used to restore data that was deleted on request.
- Billing records: invoices and payment records are retained as required by tax and accounting law, then deleted.
5. Subprocessors
Deletion requests propagate to our subprocessors: error events in Sentry and analytics events in PostHog age out under their retention settings, and deletion requests are forwarded where an identifier is deletable. Stripe retains billing records per its legal obligations.
6. Termination
When a subscription ends, retention-window purging continues to run, and account deletion can be requested at any time as described above. On confirmed organization deletion, API keys are revoked immediately.
Contact
Questions about this policy: www.ruligent.com/contact.