Data Retention
Last updated: 2026-10-07
Invite-only private beta. Not legal advice. This note describes how long Vajra Astra keeps different kinds of data, and what happens when an account is deleted.
1. Purpose
This document answers practical questions:
- what data is stored?
- how long might it remain?
- what is removed when an account is deleted?
- how to delete an account?
2. Categories and intended retention
Account and sign-in
Includes email, password hash, invite details, sessions, and password-reset details.
- While the account is active: kept so you can sign in.
- Password-reset records: short-lived. Submitting a request does not email you a link right away. After someone reviews the request, we send you a link with the reset token. That link expires after you use it, or after a short time if you do not.
- After deletion: sign-in details for that account are removed.
Portfolios and watchlists
Includes portfolios, holdings, open and closed positions, import history used for charts, watchlists, and notes.
- While the account is active: kept so the product can show your holdings and history.
- After deletion: removed with the account.
Analysis you run
Includes Idea Copilot history, position audits, debate runs, and Research Desk reports.
- While the account is active: kept so you can reopen prior analysis.
- After deletion: removed with the account.
API keys
Encrypted provider keys you save in Settings.
- While saved: kept only to run your workflows.
- After deletion: removed with the account.
Activity log
The activity log is there so you can see what the product is doing and spot errors.
- While you use the account: kept so you can review that activity. It is not cleared on a short schedule.
- After deletion: entries may remain, but they are no longer tied to you. They are not used to rebuild your portfolios.
Study session
Includes which research-session link you opened, the arm you were assigned, and an operator-chosen posting location name when that link was labeled.
- While the account is active: kept so operators can count recruitment by posting location.
- After deletion: the session row for that account is removed. Anonymous click and assignment events on a visitor cookie may remain, and they are not tied to your email.
Sign-in and security records
Records of sign-in, password reset, invites, and similar security events.
- While needed for security: kept.
- After deletion: some of these records may remain, but they are no longer tied to you. They are not used to rebuild your portfolios.
Application logs
Logs the hosted service uses to diagnose problems.
- On the hosted service, application logs are kept for 30 days.
3. How deletion works
- In Settings → Account, choose Delete Account and confirm.
- Access ends immediately. You are signed out and cannot sign in again, including with a password reset.
- Your login details, portfolio information, and any stored API keys are deleted the next time the delete job is run.
- Activity-log entries and sign-in records may remain, no longer tied to the account.
4. What deletion does not undo
- Data already sent to a model or market-data provider follows that provider’s policy.
- Hosted database backups are kept for 7 days. A deleted account can remain in a backup until that backup ages out.
5. Export
A self-serve export of everything is not available in the private beta. Before you delete the account, email hello@vajrastra.co if you want a snapshot of holdings or reports. It may be sent when that is practical.
6. What you can do about your data
During private beta you can:
- open Terms, Privacy, and Data Retention from the product
- delete your account from Settings → Account
7. Changes
This note may be updated as the private beta changes. The dated version in the product is the one that applies.
8. Contact
For a question about retention, email hello@vajrastra.co.