Penny

Retention and Deletion Policy

Version 1.0 · effective September 25, 2026

1. Principles

  1. Penny keeps what your team connects for as long as your team keeps it. A complete memory is what Penny is for, so nothing your team connected is deleted on a timer: it stays until a member deletes it (a source, a mailbox, or the whole team).
  2. When a source goes away (disconnected in Penny, uninstalled on the platform, token revoked, bot removed), its content is deleted immediately. There is no grace period and no undo.
  3. Deletion covers everything derived from the content: facts, entities, summaries, embeddings, search indexes, files, code checkouts, and stored answers and digests to the extent they quote it.
  4. Backups are not restored to bring deleted data back, except to recover from a disaster; if that happens, the deletion log (section 5) is replayed before the service reopens.
  5. Records Mintry must keep by law (billing, tax, legal holds) are kept apart from content, with the minimum data.

2. What "immediately" means

StepWhenHow
Capture stopsat once, in the request or webhook that reports the eventthe source is disabled; webhooks for it are dropped
Credentials destroyedat onceSecret Manager versions destroyed
Content deleted from the live database and object storagea deletion job starts at the event; normally complete within 1 hour, at the latest within 24 hours (large sources are deleted in batches)an idempotent, resumable background job; members see "Deleting…" then "Deleted"
Search indexes and embeddingssame jobvectors deleted with their rows
Object-storage soft-deleted copieswithin 7 daysGoogle Cloud Storage soft delete
Database backupsage out within 7 daysCloud SQL automated backups and point-in-time recovery, 7 days each
Workflow historieswithin the workflow namespace's retentionTemporal Cloud
Confirmationwhen the job completesan event in the console, for example "Deleted 1,204 messages and 37 files from #design"

In short: deleted within 24 hours, and from backups within 7 days after that.

Because deletion is immediate and irreversible, Penny says so before a member disconnects a source, and explains that a Slack workspace admin or a Telegram group admin can trigger it by removing Penny.

3. Retention schedule

DataWhereKept
Messages, mail, files, facts, entities, embeddings of a connected sourceCloud SQL, Cloud Storagewhile the source is connected; deleted at once when it goes away (section 4.1)
Questions and answers, stored digestsCloud SQLwhile the team exists; citations and quoted text of a deleted source are removed with it
Held ("hidden") mail threadsCloud SQLwhile the mailbox is connected
Code checkoutscode service diskwhile the repository is connected
Connector credentialsSecret Managerwhile connected; destroyed at once on any source end
Messages of a Telegram chat no team has claimed yetCloud SQL7 days, then deleted unless a team claims the chat
Telegram export awaiting the 48-hour notice periodCloud Storageuntil imported, or deleted if the uploader cancels or the bot is removed first
Export staging files after importCloud Storagedeleted when the import completes
Webhook deliveries awaiting routingCloud SQL, system-only table24 hours once processed; 7 days if processing failed
Opt-out markers (/forgetme)Cloud SQLwhile the source exists, so the person's messages keep being left out
Account (email, name, sign-in method)Cloud SQLuntil the account is deleted
Acceptance records (Terms, Privacy Policy, DPA, connect-step checkboxes)Cloud SQLwhile the account exists, and as long as needed to establish or defend legal claims
Sign-in linksCloud SQLvalid 15 minutes, single use
Session cookieyour browser14 days
Billing ledger, billing profileCloud SQLwhile the team exists; on team deletion a content-free billing archive is kept for the statutory period
Invoices, payments, card dataStripeper Stripe and the statutory period for tax records
Emails sent (sign-in links, notices, digests)Resendper Resend's retention
Application logs (no message content)Cloud Logging30 days
Cloud audit logs (no message content)Cloud Logging400 days (fixed by Google)
Database backupsCloud SQL7 days, plus 7 days of point-in-time recovery
AI provider copiesOpenRouter and model providersnone (zero data retention)
Deletion log (ids, counts and times; no content)Cloud SQL3 years

4. Events and what happens

4.1 Source disconnected, uninstalled, revoked, or bot removed

All of these trigger the same immediate deletion (section 2):

EventWhat is deleted
A member clicks "Disconnect" on a sourceeverything from that source
Penny's Slack app is uninstalled, or its tokens revokedeverything from that Slack workspace
The Penny bot leaves or is removed from a Slack channel, or the channel is deletedeverything from that channel (archiving a channel is not removal)
The Penny bot leaves or is removed from a Telegram chateverything from that chat
A member disconnects Gmaileverything from that mailbox
A member disconnects Google Calendar, or unticks a calendarevery event and attendee row of those calendars, and the meetings projected from them
The GitHub App is uninstalled, or a repository is removed from itthat repository's checkouts and everything derived from its code
A database is disconnectedits data dictionary and cached query results

If Google reports that a mailbox's or calendar's access has lapsed (for example after a password change), Penny marks it as needing to be reconnected; its data stays until a member reconnects or disconnects it. A calendar that has needed reconnecting for more than 24 hours is left out of digests and Today.

Data that references several sources (a fact supported by messages from two chats) loses the deleted evidence; a fact whose only evidence came from the deleted source is deleted.

4.2 Team deletion

The team's owner can have the team deleted by writing to support@ipenny.app from the owner's email address (self-service deletion in Settings is planned), or it follows termination of the Terms.

  1. Mintry confirms the request with the owner, and all members are told.
  2. Workflows are cancelled, credentials destroyed, files and code checkouts deleted, and every database row of the team deleted. A content-free billing archive is kept for the statutory period.
  3. Penny is removed from connected platforms where their APIs allow it.
  4. Within 24 hours; from backups within 7 more days. The Terms say "within 30 days", for margin.
  5. A certificate of deletion is available on request.

4.3 Member removed or leaves

The membership is deleted at once. Content the member contributed stays with the team. The owner cannot be removed and must transfer the role before leaving.

4.4 A person's deletion request or opt-out

/forgetme in a Telegram chat, or /penny forgetme in Slack: capture of that person's messages in that chat stops at once; what was stored from them there (records, files, vectors, facts attributed to them) is deleted within 24 hours, and at the latest within 30 days. Requests by email go to privacy@ipenny.app (see the Privacy Policy, section 4.4).

An opt-out by email address (a Gmail correspondent, or a meeting attendee in a connected Google Calendar, asking through privacy@ipenny.app): Penny stops storing that address for the team, deletes the attendee rows it has for it and the mail it holds from it, within the same 24 hours (30 days at the latest). The meetings themselves stay in the calendars of the members who shared them, without that attendee.

4.5 Messages deleted at the source

When Slack reports that a message or file was deleted, Penny deletes the record, its file and the facts derived from it. Telegram's Bot API does not report deletions in groups; the join notice points people to /forgetme.

Every deletion is written to a deletion log (ids, counts and times; no content), so that deletions can be replayed if a backup ever has to be restored after a disaster.

If Mintry receives a preservation order, a litigation hold, or a law-enforcement request that it is legally obliged to honour, it may suspend deletion of the specific data concerned for as long as the obligation lasts. Mintry records the hold (scope, legal basis, start, review date), tells the customer unless the law forbids it, reviews it at least every 90 days, and does not use held data for any other purpose. A hold is the only exception to immediate deletion.