Trust Center

Data Retention & Deletion Policy

Last updated: 22 June 2026

How long Securely keeps each type of data, what gets deleted when you close your account, and how to exercise your UK GDPR rights.

UK GDPR alignedEncrypted in transit & at restUK-builtPlain-English policies

1. Principles

We retain data only as long as needed to deliver the service, support our users, meet legal obligations, and improve detection. We apply data minimisation, encryption in transit and at rest, and role-based access. Retention applies to all data described below unless you delete it sooner from your dashboard.

2. Retention by data type

Data typeDefault retention
Scan history (message, link, voice, scam checkers)Life of account; user-deletable any time
OCR text extracted from screenshotsSame as the associated scan
Uploaded screenshots & documentsSame as the associated scan; deleted from storage on scan deletion
Generated PDF reportsLife of account or until user deletes
Shared report links (expiring / password-protected)Until expiry or revocation; access logs kept 24 months
Investigation cases (personal & family)Life of account / family plan
Family alerts24 months, then automatically purged
Family activity timeline24 months, then automatically purged
Family monthly reports24 months in the archive
Emergency cases & emergency timelinesLife of family plan
Guardian assignments & trusted contactsUntil removed by organiser
Account profile & authentication dataUntil account deletion
Billing & invoice records7 years (UK accounting requirements)
Security & abuse logs12 months
Email delivery & unsubscribe logs24 months

3. Deleting your data

  • You can delete individual scans, screenshots, reports, and cases from your dashboard at any time.
  • You can close your account from Account Settings; see our Account Deletion Policy for what gets deleted.
  • When you close your account, your active subscription is cancelled automatically.
  • Backups may retain copies for up to 30 days before being overwritten.
  • Billing records and limited security logs are retained where required by law even after account closure.

4. Family-shared data

Family alerts, shared cases, monthly reports, and the family activity timeline are part of the family plan record. If you leave a family or are removed, your future activity is no longer family-visible, but historical family-level events remain in the family record for the retention periods above. Removing the underlying scan from your personal history does not retroactively remove a derived family alert or a case contribution.

5. Your UK GDPR rights

  • Access — request a copy of your personal data.
  • Export / portability — request your data in a machine-readable format.
  • Correction — ask us to fix inaccurate data.
  • Deletion — ask us to delete your data ("right to be forgotten").
  • Restriction — ask us to stop using your data while a query is resolved.
  • Objection — object to processing based on legitimate interests.
  • Complaint — lodge a complaint with the UK Information Commissioner's Office (ICO) at ico.org.uk.

6. Exercising your rights

Email privacy@securelyapp.co.uk from the address linked to your account. We respond within one month and may request reasonable proof of identity before disclosing or deleting data.