Purpose
What Proofavo keeps, for how long, and what happens when you stop using it.
Every statement here describes behaviour that exists in the product today, or is written in the conditional because it does not. Where something is a limit we place on ourselves rather than an action we take, it says so — a policy that promises deletion nothing performs is worse than one that admits it keeps things.
The two kinds of thing we hold
Your work — the artwork you upload, the proofs you create, the comments your customers leave. This is yours; we hold it so the product can show it to the person you sent it to.
The record — who approved which version, when, and the fingerprint of the exact file they approved. This exists to settle a disagreement between a print shop and its customer months after the job is done, which is the reason the product exists at all.
They are retained differently, and deliberately.
While your account is active
| What | Kept |
|---|---|
| Proofs, versions and uploaded artwork | until you delete them or close the account |
| Comments and change requests | with the proof |
| Approval records | indefinitely — see below |
| Review links | until revoked, replaced, or expired |
| Email delivery status | with the proof it belongs to |
| Support assistant conversations | 90 days. What you typed and what the assistant answered — never the workspace data it read to answer, which is recomputed each time rather than stored |
| Application logs and error reports | 30 days |
| Usage measurement of our own pages | held by PostHog for as long as our plan retains it — currently up to seven years. Longer than anything else here, and the reason it can be: the daily value used to count visitors is destroyed at the end of that day and no IP address is stored on the events, so what survives identifies nobody. Nothing is stored in your browser for it either |
If you are only on the waitlist
You have no account and we keep almost nothing. Your address is held by Resend until you unsubscribe. Our own database holds one row — a one-way fingerprint of the address and the time you joined, so that "early-access pricing for the first hundred" can be counted — and unsubscribing deletes it. Rejoining later creates a new row, at the end of the list.
Review links expire
A review link stops working 60 days after your customer last opened it. The window is measured from the last open, not from when you created it, so a proof somebody is still looking at does not die under them.
Two exceptions:
- A link to an approved proof does not expire. After approval, that link is your customer's only way back to what they agreed to, and taking it away would punish the person the record exists to protect.
- Archiving a proof closes its link immediately, approved or not. Archiving is you saying the job is done.
Approval records are kept indefinitely — with one part that ages out
An approval record holds the reviewer's name and email address, the version they approved, that file's SHA-256 fingerprint, the time, and any message they left. All of it is kept for as long as the workspace exists. That is the evidence, and it is the point of the product.
At the moment of approval we also record the reviewer's IP address and browser user-agent string. Those are deleted — set to empty — twelve months after the approval, automatically. The approval itself is untouched: years later it still names the person and the exact artwork, it simply no longer says which network they were on.
We do this because that network trace is the weakest part of the evidence and the most sensitive part of the record. The reviewer is usually not our customer: they are a print shop's customer, who received a link and never signed up for anything.
If you cancel
Nothing is deleted when you cancel. Your workspace stops being able to start new work past the free limits; everything already there stays readable, and every review link your customers hold keeps working.
Beyond that, two different promises, because the two cost very different things:
- Approval records are kept indefinitely. They are a handful of rows. If a dispute surfaces two years after you left, the record is still there.
- Uploaded artwork is kept for at least twelve months after the subscription ends. After that we may remove the stored files to reclaim space — and never without 30 days' notice to the account owner, sent to the address on the account.
We do not promise to delete those files on a schedule, and we do not promise to keep them for ever. What we promise is the floor and the notice.
Deletion on request
Self-service deletion does not exist in the product yet. Deletion is handled by a person.
Write to support@proofavo.com and say what should be deleted. We will confirm within 72 hours and tell you what was removed and what was kept.
Two things worth knowing before you ask:
- A request can come from your customer, not only from you. Somebody who approved a proof can ask us to remove their name, email and message from the record. We will do it — and we will tell you, because it changes a record you may be relying on.
- What we cannot remove without destroying the record's meaning is the fact that a version was approved, when, and its fingerprint. If a full removal is required, the approval goes with it, and the proof stops being evidence of anything.
Backups
The database is backed up daily and kept for seven days, by Supabase on the Pro plan: your proofs, comments, approvals and everything else recorded about them. It is disaster recovery, not an undo button — we cannot restore one deleted proof from it without rolling the whole database back, which we will not do to everyone else's work.
Uploaded artwork is backed up separately, because our database provider's backups deliberately exclude stored files — they hold only the record of them. Every original is copied to a second provider, in the European Union, in a different account, and each copy is read back and checked against the fingerprint recorded when it was uploaded. A copy nobody has read is not a backup, so we do not count one until it has been.
Previews are not copied: they are generated from the original and can be generated again.
None of this replaces your own copies of work you cannot re-create, which is what the Terms ask of you during the beta.
A deletion we perform disappears from live data immediately and ages out of the backups within those seven days. It is not possible to reach into a backup and remove a single row, which is why "deleted" means "gone from the live system now, and gone entirely within a week".
What we do not keep
- Payment card details. These never touch our systems. Our payment provider holds them; we hold an identifier and a subscription status.
- Session recordings. Error reporting is configured with screen recording switched off, request bodies excluded, and review tokens, signed URLs and keys scrubbed before anything leaves our servers.
- Anything about a reviewer beyond what they typed and the approval trace described above. No analytics profile, no cross-site tracking. The usage measurement is not merely switched off on a review link — the code for it is never sent to a reviewer's browser.
Changes
Material changes to this policy are announced to account owners before they take effect. The version and date at the top of this document are what identify it.