← Back to Legal

Legal

Data Retention and Deletion

Last updated: June 19, 2026

This policy describes how long Dino keeps your data and how deletion works. It forms part of our Privacy Policy and our Data Processing Agreement.

How long we keep data

CategoryWhat it includesRetention
Account and identityUser email, name, organization membershipKept for the life of the account, then deleted within 30 days of account closure
ConfigurationAPIs, environments, auth profiles, and the encrypted credentials they holdKept for the life of the workspace, removed when the resource or workspace is deleted
Scan dataScans, results, findings, and replay artifactsKept for the duration of your subscription, removed when the workspace is deleted
Audit logsSecurity and administrative eventsKept for the duration of your subscription. Enterprise customers can arrange extended retention.
BillingSubscription and invoice recordsKept as required for tax and accounting purposes, held by our billing sub-processor
Operational analyticsTenant-anonymous product eventsKept by our analytics sub-processor. These carry no tenant identifier, no credential, and no target data.

Deletion when you act

  • Deleting an API, environment, or auth profile removes that resource and its associated data, including the encrypted credential for an auth profile.
  • Deleting a workspace performs a soft delete followed by a background purge of the workspace's data. A deleted workspace can no longer be used, and a confirmation step is required before deletion.
  • Deleting a resource frees the associated plan quota.

Deletion on offboarding

When you terminate your subscription or close your account, Dino deletes or returns your data, as set out in our Data Processing Agreement, within 30 days, except where retention is required by law, such as for billing records.

User deprovisioning

For customers using SCIM, deprovisioning a user removes that user's access to the workspace.

Export

You can export your workspace data before deletion. Contact support@usedino.dev if you need an export.

Backups

Deleted data may persist in encrypted, access-controlled backups for a limited period until those backups cycle out. Residual copies are not restored into the live service except as part of a documented disaster-recovery event.

Legal hold

Dino may retain data where required to comply with a legal obligation, resolve a dispute, or enforce its agreements.

Contact

privacy@usedino.dev

For general questions, visit our Contact page.