Legal
Data Retention and Deletion
This policy describes how long Dino keeps your data and how deletion works. It forms part of our Privacy Policy and our Data Processing Agreement.
How long we keep data
| Category | What it includes | Retention |
|---|---|---|
| Account and identity | User email, name, organization membership | Kept for the life of the account, then deleted within 30 days of account closure |
| Configuration | APIs, environments, auth profiles, and the encrypted credentials they hold | Kept for the life of the workspace, removed when the resource or workspace is deleted |
| Scan data | Scans, results, findings, and replay artifacts | Kept for the duration of your subscription, removed when the workspace is deleted |
| Audit logs | Security and administrative events | Kept for the duration of your subscription. Enterprise customers can arrange extended retention. |
| Billing | Subscription and invoice records | Kept as required for tax and accounting purposes, held by our billing sub-processor |
| Operational analytics | Tenant-anonymous product events | Kept by our analytics sub-processor. These carry no tenant identifier, no credential, and no target data. |
Deletion when you act
- Deleting an API, environment, or auth profile removes that resource and its associated data, including the encrypted credential for an auth profile.
- Deleting a workspace performs a soft delete followed by a background purge of the workspace's data. A deleted workspace can no longer be used, and a confirmation step is required before deletion.
- Deleting a resource frees the associated plan quota.
Deletion on offboarding
When you terminate your subscription or close your account, Dino deletes or returns your data, as set out in our Data Processing Agreement, within 30 days, except where retention is required by law, such as for billing records.
User deprovisioning
For customers using SCIM, deprovisioning a user removes that user's access to the workspace.
Export
You can export your workspace data before deletion. Contact support@usedino.dev if you need an export.
Backups
Deleted data may persist in encrypted, access-controlled backups for a limited period until those backups cycle out. Residual copies are not restored into the live service except as part of a documented disaster-recovery event.
Legal hold
Dino may retain data where required to comply with a legal obligation, resolve a dispute, or enforce its agreements.
Contact
privacy@usedino.dev
For general questions, visit our Contact page.