> ## Documentation Index
> Fetch the complete documentation index at: https://docs.usetero.com/llms.txt
> Use this file to discover all available pages before exploring further.

# Data Retention

> Retention periods and deletion behavior for core hosted data classes.

export const securityEmail = "security@usetero.com";

<Badge>Last reviewed: March 5, 2026</Badge>
<Badge>Owner: Security + Engineering</Badge>
<Badge>Review cadence: Quarterly</Badge>
<Badge color="green">Status: Implemented</Badge>

This policy defines baseline retention windows and deletion behavior for core hosted data classes.

## What this policy answers

* Which hosted data classes are retained and for how long
* How deletion is enforced in active systems and backups
* How retention ownership differs in self-hosted deployments

## Implementation status (March 5, 2026)

Retention and deletion controls described on this page are active in the hosted deployment model.

## Retention schedule (hosted default)

| Data type                                 | Retention                 |
| ----------------------------------------- | ------------------------- |
| Account and workspace records             | While active              |
| Telemetry metadata required for operation | While workspace is active |
| Backups                                   | 30 days                   |

## Deletion behavior

* On account or workspace deletion, Tero removes data from active systems within 30 days.
* Backup copies expire with their retention windows.

## Hosted vs self-hosted scope

| Area                                         | Tero-hosted           | Self-hosted       |
| -------------------------------------------- | --------------------- | ----------------- |
| Retention enforcement                        | Tero-operated         | Customer-operated |
| Backup lifecycle controls                    | Tero-operated         | Customer-operated |
| Infrastructure-level retention configuration | Tero-defined baseline | Customer-defined  |

## Exceptions and governance

Retention exceptions require documented risk acceptance, approval, and time-bound remediation.

Questions: [{securityEmail}](mailto:\{securityEmail})
