Trust Center

Data Retention & Deletion Policy

Last updated: 24 August 2026

How long Securely keeps each type of data, what gets deleted when you close your account, and how to exercise your UK GDPR rights.

UK GDPR alignedTLS in transit · provider encryption at restUK-builtPlain-English policies

1. Principles

We retain data only as long as needed to deliver the service, support our users, meet legal obligations, and improve detection. We apply data minimisation, encryption in transit and at rest, and role-based access. The periods below are our retention targets: some are enforced automatically, others by periodic review, and all of the data listed as tied to your account is deleted when your account is deleted. You can delete most items yourself from your dashboard at any time.

2. Retention by data type

Data typeDefault retention
Scan history (message, link, voice, scam checkers)Life of account; user-deletable any time
OCR text extracted from screenshotsSame as the associated scan
Uploaded screenshots, photos & evidence documentsKept in encrypted file storage until you delete them; erased automatically when your account is deleted
Generated PDF reportsLife of account or until user deletes
Shared report links (expiring / password-protected)Until expiry or revocation; access logs kept 24 months
Investigation cases (personal & family)Life of account / family plan
Family alertsTarget retention 24 months; removed on periodic review and always deleted with the account
Family activity timelineTarget retention 24 months; removed on periodic review and always deleted with the account
Family monthly reports24 months in the archive
Emergency cases & emergency timelinesLife of family plan
Guardian assignments & trusted contactsUntil removed by organiser
Account profile & authentication dataUntil account deletion
Legal acceptance record (incl. IP address at acceptance)Life of account; deleted with the account
Billing & invoice records7 years (UK accounting requirements)
Security & abuse logs12 months
Email delivery & unsubscribe logs24 months
In-app notificationsTarget retention 12 months; removed on periodic review and always deleted with the account
Academy progress, bookmarks & reading historyLife of account
Support messages & feedbackLife of account; deleted with the account
Account deletion audit record24 months after deletion
Encrypted infrastructure backupsUp to 30 days, then overwritten

2a. Uploaded screenshots, photos and evidence files

Several Securely features let you upload a file: screenshots attached to the Message Scanner and to the Marketplace, Ticket, Identity Verification, Rental, Job and Romance checkers, property photos in the Rental checker, and evidence files attached to an investigation case. Because these are your own images and documents, we set out their handling separately.

  • Where they are stored: in a private file-storage bucket operated by our hosting provider, in a folder keyed to your user account. Access is controlled at the storage layer, and the app reads a file only through a short-lived signed link generated for you. Files are not publicly browsable and have no guessable public URL.
  • What is stored alongside them: a database record holding the file’s storage path, dimensions, size, content type, your optional tag or note, and any scan or case it is linked to, plus an access log entry each time the file is uploaded, viewed or deleted.
  • How long they are kept: there is no automatic expiry. An uploaded file is retained for as long as you keep it — in practice, for the life of your account unless you delete it.
  • Deleting a single file: removing a file from the evidence view of a scan or case deletes both the database record and the underlying file from storage immediately.
  • Important — deleting a scan or case does not automatically delete its files: uploaded files are stored independently of the scan or case they are attached to, so they survive deletion of that scan or case and remain in your evidence library. To remove an image or document, delete the file itself.
  • Closing your account: deleting your account automatically and permanently erases every file you uploaded. Before any account data is removed, the deletion routine sweeps your private folder in each storage bucket — both the files recorded in the database and any orphaned uploads — and deletes the underlying objects, then removes the matching database records. The sweep is restricted to files stored under your own user folder, so it cannot reach another user’s data. No manual step by us is involved, and no request to us is required.
  • Backups: encrypted infrastructure backups may retain a copy of a deleted file for up to 30 days before being overwritten.
  • Third-party processing: when you submit an upload for analysis, its contents are transmitted over TLS to OpenAI so the image or document can be read and assessed. OpenAI does not receive your account details. See our Subprocessors page.

Uploading is always optional. Every scanner works with pasted text alone, and we recommend redacting anything you do not need analysed — particularly bank card numbers, passwords and one-time codes — before uploading an image.

3. Deleting your data

  • You can delete individual scans, screenshots, reports, and cases from your dashboard at any time. Deleting an uploaded file removes it from storage immediately; deleting a scan or case does not remove files attached to it — see section 2a.
  • You can close your account from Account Settings; see our Account Deletion Policy for what gets deleted.
  • When you close your account, your active subscription is cancelled automatically.
  • Backups may retain copies for up to 30 days before being overwritten.
  • Billing records and limited security logs are retained where required by law even after account closure.
  • Your legal acceptance record — including the IP address captured when you accepted our Terms and Privacy Policy — is held on your profile and is deleted with your account.
  • Uploaded screenshots, photos and evidence documents are erased automatically from secure storage as part of the account deletion routine, together with their database records.

4. Family-shared data

Family alerts, shared cases, monthly reports, and the family activity timeline are part of the family plan record. If you leave a family or are removed, your future activity is no longer family-visible, but historical family-level events remain in the family record for the retention periods above. Removing the underlying scan from your personal history does not retroactively remove a derived family alert or a case contribution. If the organiser deletes their account, the family plan and its shared records are deleted with it.

5. Your UK GDPR rights

  • Access — request a copy of your personal data.
  • Export / portability — request your data in a machine-readable format.
  • Correction — ask us to fix inaccurate data.
  • Deletion — ask us to delete your data ("right to be forgotten").
  • Restriction — ask us to stop using your data while a query is resolved.
  • Objection — object to processing based on legitimate interests.
  • Complaint — lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

6. Exercising your rights

Email privacy@securelyapp.co.uk from the address linked to your account. We respond within one month and may request reasonable proof of identity before disclosing or deleting data.