Enji Guard Enji Guard Back to home

Legal

Privacy Policy Terms of Service Billing & Credits Refund Policy Legal Entities & Contact AI Data Use Data Retention & Deletion Subprocessors Data Processing Agreement Cookie Policy GitHub App Permissions GitLab Access Authorized Testing Security & Trust Vulnerability Disclosure Accessibility
All legal pages

Data Retention & Deletion

Effective date: 15 September 2026

This page explains how long Enji Guard keeps different kinds of data, how to delete data or offboard, and what may remain afterwards. Specific deployments and signed agreements may set different retention terms.

Retention principles

We retain data only as long as needed to provide, secure, and support the Service, meet legal obligations, resolve disputes, and maintain auditability. Retention is purpose-based rather than a single fixed timer.

Product reports, findings, and task and activity history are retained as product records for as long as your account exists, and are deleted with it. Revoking access or unlinking a repository stops future use but does not automatically delete historical reports or history.

Where a period can be given, it is given below, and the same periods appear in Privacy Policy §11.

Financial records are the exception, and they are not ours. Invoices, payment and tax records are held by Paddle as the seller, under its own statutory periods — see the category below.

By data category

  • Account and product data — retained while your account and projects are active, and deleted when you delete the account, subject to the backup, log, and legal or security exceptions described below.
  • GitLab connection data and access token — the token you issue is stored encrypted and used only for the projects you connect. Our copy is deleted when you disconnect. It is the only long-lived credential of yours we hold, which is why it has its own line here — see GitLab Access.
  • GitHub installation data — tied to your installation; stops being used when you revoke or uninstall the GitHub App.
  • Execution workspaces — ephemeral; removed after each task, so the cloned repository code does not persist in the workspace.
  • Reports, findings, and audit history — retained as product records while the account exists, and deleted with it.
  • Credit balance and usage records — your balance, each purchase with the credits granted and the amount paid, expiries, and the credits reserved and spent on each run. Kept while the account exists and deleted with it. Paddle holds the record of the sale itself; ours is only the ledger behind the balance.
  • Payment, invoice and tax records — held by Paddle as the seller of record, under its own retention obligations. We do not keep them. Paddle is the party with the statutory duty here, because Paddle made the sale; our own accounts show settlement from Paddle, not purchases by you. We cannot delete Paddle’s records for you — approach Paddle directly. On our side, the credit ledger that tracks your balance lives while the account does, and goes when you delete it.
  • Auto-pentest consent records — kept for 3 years after a consent stops being valid. The record is the evidence that someone authorised probing a live system.
  • Auto-pentest reports — kept while your account exists and deleted with it. Access while we hold them is restricted to one named person — see DPA Annex 2, Who can see what.
  • Technical data — IP address, request and device metadata: up to 12 months, then deleted or aggregated beyond re-identification.
  • Security and access logs — including the record of our team’s access to customer content: up to 24 months.
  • Support and other communications — up to 24 months after the exchange closes.
  • Analytics data — website and product, each only with the matching consent: held by Google under the retention period configured on our Google Analytics properties. Ask us and we will tell you the current setting. What is stored in your browser, and for how long, is in the Cookie Policy.
  • Marketing and attribution storage — up to 90 days, per the Cookie Policy.

Deletion controls

You can delete projects, repositories, and sites, disable schedules and jobs, and revoke the GitHub App; this stops future use, while retained records are handled as described below.

You can delete your account yourself, together with its data and audit results. A service administrator can also do it at your request. Deletion is permanent — there is no recovery window and no undo.

Export what you want to keep before you delete. You can export your reports and audit history at any time while the account is open. Afterwards there is nothing to export from.

Deleting your account does not by itself refund anything. Purchases from the last 30 days are refundable under Terms §10 and older ones are not — deleting the account does not change that either way. If you want a refund, ask for it before you delete, because afterwards there is no account to refund to. Paddle’s record of the sale survives under its own retention obligations; our credit ledger does not.

Published links

If you have made a project view or a repository summary public, making it private, revoking it, or deleting the report ends access through our link and nothing more. Copies taken while it was live are outside our reach, and no deletion request to us can recall them. See Terms of Service section 13.

Deletion effects

After deletion, copies may remain in backups for up to 7 days until they are overwritten on their ordinary cycle, and in logs or audit records where required for legal or security purposes, within the periods above.

Payment and tax records are Paddle’s, held under Paddle’s own statutory periods. They are not on our side to keep or to delete — see above.

Data already sent to third-party providers is subject to their own retention terms.

We'd like to use Google Analytics and campaign attribution to see whether our marketing works. Cookie policy