How long we keep things
Applicants’ photographs are not ours to keep indefinitely. These are the periods we hold data for, what starts each clock, and what removes it.
| What | Kept for | From |
|---|---|---|
| Photos as uploaded, and anything staged from a capture link | 30 days | the upload |
| Processed exports — the print-ready file, the preview, the copies a job froze | 90 days | the attempt that produced them |
| The case itself: applicant name, your reference, notes, attempt and delivery history | 365 days | the last activity on the case |
If you delete a case
We stop new photos reaching it, cancel any capture links you sent, and remove every attempt, every processed file and the applicant’s details. We keep a billing record that a photo was processed — an order number and an amount, with nothing about the applicant on it.
If you stop paying
Processing stops, and your history stays readable and exportable for 30 days. Cancelling does not extend anything’s expiry: a photo already 30 days old is already gone.
Backups
Database backups are kept for 35 days. Photographs are not stored inside them. Every deletion is written to a register that no cleanup ever removes, so if we restore a backup taken before one, the deletion is reapplied before anything is served — a deleted case does not come back.
Removal is not instant
Access stops on the dates above. The files themselves are swept shortly afterwards, which can take up to a day.