BOARDWALKBeta
How it worksDocsBlogPricing
7Log in
Legal/Data Retention Policy

Data Retention Policy

Last updated: June 21, 2026

This policy describes how long Boardwalk retains different categories of data, how account deletion works, and how deletion interacts with backups and recovery systems. It supports our Privacy Policy and our Data Processing Addendum; if any of those documents specify a shorter or contractually agreed retention period, that one controls.

1. Active accounts

While your account is active we retain your account profile, organization configuration, workflows, and stored secrets so we can deliver the Service. Run history and artifacts are kept only for the limited windows described in Section 3 and are then deleted automatically; where the Service exposes deletion controls, you can also delete workflows, runs, artifacts, and secrets yourself. For deletion requests that are not available in-product, contact us at privacy@boardwalk.sh.

2. Account deletion

You can delete your account or organization from your account settings, or contact us at privacy@boardwalk.sh. We mark the account for deletion, stop using it for Service operations beyond what's needed to wind down, and permanently delete the account and its Customer Content from primary production systems within 30 days. This is final.

For organizations, removal of a member follows the organization's own configuration. Deleting one organization does not delete other organizations or the personal accounts of its members.

3. Retention schedule

The table below describes the targets we operate to. "Time to scrub" is the period after which a category is removed from primary production systems; backups age out separately (Section 5).

  • Account profile and organization records: retained while active; deleted within 30 days of a deletion request.
  • Workflows: retained while the owning account is active; you can delete a workflow yourself at any time, and all workflows are deleted within 30 days of an account deletion request.
  • Runs, run logs and events, agent transcripts: retained for your organization's run-retention window (90 days by default, configurable per organization), after which a daily reaper deletes them. You can also delete a run yourself where the Service exposes that control.
  • Artifacts: retained for the time-to-live set when each artifact is created (a short default, extendable per artifact). A daily reaper deletes artifacts once their TTL has passed, and a deleted run's artifacts are expired first.
  • Secrets: stored encrypted while in use; destroyed when you remove them, and within 30 days of an account deletion request.
  • User-requested data exports: generated on demand and held in object storage with a 7-day lifecycle, after which the export expires and is deleted.
  • Audit logs (Team and Enterprise plans): retained for the contractual period in your Order Form, or 13 months by default.
  • Operational and security logs: request logs, error traces, run telemetry, security signals, and rate-limit events. Retained up to 90 days for debugging, abuse prevention, and incident investigation, then aggregated or deleted.
  • Usage and billing records: usage events and invoices, payment records, and tax documents (held by us and by Stripe) are retained for at least 7 years to satisfy tax, accounting, and audit obligations.
  • Support records: emails to support@boardwalk.sh, abuse@boardwalk.sh, and similar inboxes are retained up to 24 months unless required for an open matter.
  • Legal hold. When data is subject to a legal hold, court order, regulatory request, or active dispute, we suspend deletion until the matter is resolved.

4. Customer-controlled retention (Enterprise)

Enterprise customers can negotiate custom retention windows for specific data categories (for example, shorter run-history or log retention) as part of their Order Form. Where an Enterprise Order Form specifies a custom retention period, it supersedes the defaults in Section 3 for that data.

5. Backups

The production database uses point-in-time recovery, which preserves a rolling restore window. Object storage and other production stores follow comparable rolling-backup rules. Deleted data may persist in a rolling backup window until it ages out. We do not restore individual customer records out of backups except in response to a verified disaster-recovery incident affecting the Service. Backups inherit the same encryption and access controls as primary data.

6. Anonymized and aggregated data

We may retain anonymized or aggregated information that cannot reasonably be used to identify you (for example, counts of how many runs executed in a given month) for analytics, capacity planning, and product development without time limit.

7. Updates

We may refine this policy as the product matures. Material changes will be posted here with a revised "Last updated" date.

8. Contact

Retention questions, privacy questions, or deletion requests: privacy@boardwalk.sh.

BOARDWALK

Open source software for AI.

ProductGet startedPricingModelsLog inStatus
DevelopersDocsGitHubCLISDKExamples
CompanyAboutBlogChangelogHelpContact
LegalTermsPrivacyAcceptable useSubprocessorsAll policies
© 2026 Robot Networks Inc.Open source under Apache-2.0 + MIT