Balance Widget Retention

Data Retention & Deletion Policy

Effective
25 July 2026
Review
Annually, or on material change

This policy defines how long Balance Widget keeps user data and how it gets deleted. It exists to satisfy the data-minimisation principles in the CCPA and GDPR and Plaid's data-handling requirements — and, more usefully, so that you can find out exactly what happens to your data without asking.

1What we keep, and for how long

Data Where it lives Retention
Account and authentication data Supabase Auth Kept while the account is active. Deleted within 30 days of a deletion request.
Plaid access tokens Supabase Postgres, encrypted Revoked immediately on disconnection or account deletion, then deleted.
Account and balance data from Plaid Supabase Postgres Kept only while needed to render your widgets. Deleted within 30 days of account deletion or disconnection.
Subscription state Supabase Postgres Kept while the subscription is active, then as long as needed for tax and accounting records.
Usage analytics PostHog Cloud Up to 12 months, then purged or anonymised.
Crash and error reports Sentry Up to 90 days.
Support correspondence Email Up to 24 months, for continuity if you write again.

2How deletion works

Two different actions, with two different effects:

Disconnecting an account

Available in the app at any time. We revoke the Plaid access token immediately, which ends our ability to retrieve anything further from that institution. The cached balances for that account are removed, and any widget showing them stops updating. Your Balance Widget account stays.

Deleting your account

Email support@lavafactory.com from the address on the account. We revoke every Plaid access token immediately, then delete your account, authentication record, and all stored balance data within 30 days. Analytics events are deleted or anonymised so they can no longer be tied to you.

Two things survive, and only these: records we're required to keep for tax and accounting purposes relating to a paid subscription, and support correspondence within the window above. Any backup copies age out on the providers' own backup schedules.

3Manual today, automated soon

Stated plainly: retention is currently enforced by hand. A scheduled job to purge data past its retention window is planned but not yet built. Until it exists, deletion requests are carried out manually, within the 30-day commitment above — and that commitment holds regardless of whether the automation exists.

4Legal basis

The periods above are set to the shortest span that still lets the product work, in line with the data-minimisation and storage-limitation principles in the GDPR and the CCPA, and with Plaid's developer data-handling requirements. We do not retain financial data longer than the service needs it, and we do not keep it "in case it's useful later".

5Review

This policy is reviewed at least annually, and sooner if our data handling, infrastructure, or the applicable law changes. The effective date at the top reflects the last review.

Related: the privacy policy covers what we collect and why; the security overview covers how it's protected.