Orvica · Legal
Data Retention Policy
Effective 2026-05-30 · Version 0.1-draft
Orvica retains data for as long as needed to provide the service plus what's required by law, accounting, or fraud-prevention obligations. This page summarizes typical retention windows by category.
Account data
- Active accounts: retained for the life of the account.
- Deleted accounts: profile data is removed within the deletion grace window described in the Account Deletion Policy. Audit logs are retained per the schedule below.
Product data
- LedgerOne: bills, subscriptions, goals, expenses, Smart Splits, and related receipts — retained for the life of the account; removed on deletion.
- Helix: patients, medications, refills, appointments, care notes, documents — retained for the life of the workspace; removed when the workspace is deleted. Audit logs scoped to a workspace are retained per the audit schedule.
- Volt: merchant profile + saved Volt-side metadata removed on account deletion. Stripe-side transaction records are governed by Stripe's retention policy.
Communications
- Email + SMS delivery logs: 90 days, then deleted. Includes recipient address, status, and any error reason.
- OTP sessions: consumed or expired within minutes; retained for at most 7 days for security investigation.
Security + audit
- Audit logs: retained at least 1 year and up to 7 years for investigation, dispute resolution, and applicable accounting and tax obligations. Personal identifiers are minimized after the active investigation window.
- Login events: 90 days.
- Webhook events (Stripe): 365 days.
Analytics
Aggregated, non-identifying counts (e.g. "X users created their first Smart Split this month") are retained indefinitely. Per-event identifying data follows PostHog's defaults and the user's "Do Not Track" or analytics opt-out signal.
Legal hold
When data is subject to legal process or active dispute, retention is extended for the duration of the matter regardless of the schedule above.
Questions or corrections? Email legal@orvica.co. Security reports: see responsible disclosure.