How Long Does CipherDrive Keep My Data?

CipherDriveâ„¢ does not use one universal retention period for every type of information.

Ackaia retains information for as long as reasonably necessary for the relevant purpose, such as providing the service, maintaining security, operating billing, preventing abuse, resolving disputes, enforcing agreements, complying with law, or preserving evidence.

Account information

Account information may be retained while your account is active and for a reasonable period after closure. Some information can be retained longer when required or permitted for security, fraud prevention, abuse prevention, accounting, disputes, or legal obligations.

Billing information

Invoices, payment metadata, transaction records, and tax-related information may need to be retained for accounting, tax, financial, or legal periods that continue after a subscription ends.

Storage metadata

Storage metadata may remain while objects are:

Encrypted file blobs

Encrypted file blobs may remain while you keep them in CipherDrive and may also remain temporarily in trash, backup, suspension, dispute, abuse-investigation, deletion, or legal-retention states.

The fact that an encrypted blob remains for a period does not mean Ackaia possesses the key required to decrypt it.

Guest and quota records

Guest identifiers, transfer counters, pseudonymous network identifiers, reset records, and limit-exceeded events may be retained long enough to administer the relevant transfer period, reconcile usage, resolve disputes, prevent evasion, and protect the service.

Transfer and preview records

Transfer authorizations, byte-accounting records, preview events, recipient identifiers, timestamps, and operational status may outlive the immediate session, Public Link, object, or account when retention remains necessary for billing, quota administration, security, abuse prevention, disputes, enforcement, or legal compliance.

Copy-provenance records

Limited records connecting source and destination accounts, objects, shares, and user-directed copies may remain after the source object, destination object, share, or account is deleted when needed for operational integrity, investigations, disputes, enforcement, legal claims, compliance, or evidence preservation.

Retention of provenance metadata does not necessarily mean the associated encrypted file blob is still stored.

Trust, safety, and investigation records

Flags, case reasons, severity, status, snapshots of relevant identifiers, alerts, review history, enforcement actions, and related audit records may be retained while a matter is active and for a reasonable period afterward.

They may be kept longer when needed to identify repeated abuse, preserve evidence, protect users or victims, comply with law, or defend legal claims.

Risk Assessment Engine records

Risk signals, hash matches, blocked-upload records, CSAM-related indicators, enforcement records, and related logs may be retained for longer periods where necessary for child safety, abuse prevention, evidence preservation, enforcement, legal compliance, or cooperation with appropriate authorities.

Backups and disaster recovery

Deletion from active systems may not immediately remove information from encrypted backups, disaster-recovery systems, immutable security records, or legally required archives. Those systems follow their own lifecycle schedules.

Do not treat retention as a recovery feature. A file remaining temporarily in a backup does not mean Ackaia can restore it on request or decrypt it without your keys.

Why doesn't the policy give one number?

Different information serves different purposes and is subject to different operational and legal requirements. A fixed universal period would be misleading.