Scope
This policy describes the standard retention, export, and deletion practices for hosted Runtrace Business. An Enterprise order form may define different periods or a private deployment boundary.
Runtrace does not retain source code, file contents, secret values, shell history, screenshots, clipboard contents, or arbitrary command output because the agent does not upload those data categories.
Standard retention
Active organization operational data
Devices, current telemetry snapshots, findings, vulnerability groups, finding workflow state, allowlists, remote scan requests, pilot and lifecycle acceptance receipts, policies, reports, users, members, and billing state.
- Retention: Kept while the organization is active so admins can track remediation, trends, audit history, and billing status.
- Deletion: Removed by guarded organization deletion after billing is canceled or the account is free/local; a minimal deletion receipt remains.
- Exportable: Yes
Audit and workflow evidence
Billing changes, remote scan queue/claim/fail/cancel events, report generation/delivery, package-bound pilot and lifecycle acceptance records, finding workflow notes, allowlist changes, enrollment-token changes, and deletion receipts.
- Retention: Kept with the active organization and included in export/audit CSV so security and billing actions remain reviewable.
- Deletion: Tenant audit events are removed by organization deletion; the deletion receipt keeps the deletion actor, time, reason, billing state, and removed-record counts.
- Exportable: Yes
Billing and subscription metadata
Plan, status, seat limit, billing period, Revolut customer/subscription identifiers, cancellation requester/reason/time, webhook event IDs, and signup request metadata.
- Retention: Kept while needed to operate checkout, subscriptions, support, accounting, cancellation, and fraud/error investigation.
- Deletion: Operational billing state and organization-scoped webhooks are removed by organization deletion when billing permits deletion; deletion receipt remains for legal/accounting evidence.
- Exportable: Yes
Admin sessions and access records
Server-side session IDs, OIDC subject/email/name/roles, allowed organization claims, membership records, and session expiry timestamps.
- Retention: Sessions expire automatically by timestamp; user/member records are updated on login and retained while organization access exists.
- Deletion: Organization deletion removes scoped sessions, memberships, and users that no longer belong to another organization.
- Exportable: Yes
Raw secrets and source contents
Secret values, private-key contents, API token values, source files, document contents, screenshots, clipboard contents, shell history, terminal output, and arbitrary command output.
- Retention: Not uploaded by design; telemetry ingestion rejects obvious raw private-key and API-token patterns before storing snapshots.
- Deletion: No product retention applies because these contents should not enter the fleet store.
- Exportable: No
Customer controls
- Authorized administrators can export organization data before account deletion.
- Devices can be deactivated immediately to stop authentication and release an active seat.
- Audit history and reports can be downloaded during the subscription.
- Account deletion requires an authorized administrator and confirmation of the organization.
Backups and deletion
Deletion removes active customer records from the application. Backup copies expire through the normal backup-retention cycle and are used only for disaster recovery. Runtrace may retain minimal billing, legal, security, and deletion records where required by law or necessary to establish, exercise, or defend legal claims.