Data retention & GDPR tools
Settings → Data storage & privacy
The page has three parts: retention periods, information and deletion of individual visitors, and export for evidence documentation.
Retention policies
A separate period for each data type:
- Conversations
- Visitor sessions
- Page views
- Messages
- Read notifications
- Unread notifications
For each type: set Retention days and turn on Automatic deletion. Without the switch, nothing happens.
⚠️ If automatic deletion is off, data is stored indefinitely. The page explicitly warns about this because it may violate Art. 5 GDPR (storage limitation). An unlimited period cannot be set here — the maximum duration is limited.
Notifications are the special case: Even without their own policy, they are deleted after a preset period. You only need the policy if you want a different period.
⚠️ When deleting conversations, all file attachments are also permanently removed from storage. This is intentional — it does no good to delete the conversation and keep the screenshot.
Information (Art. 15)
Export visitor data provides all stored data for a visitor ID — as JSON for download or copying.
You can find the visitor ID in the visitor view or in the conversation. If someone asks by email, it's your job to match it: We only know the ID, not the person behind it.
Deletion (Art. 17)
Delete visitor data removes everything for a visitor ID permanently. To confirm, you must type DELETE.
This is a real deletion, not a trash can — there is no way back and no restoration from a backup that deserves the name.
Evidence
Audit log export outputs all retention and GDPR events as JSON or CSV. This is the proof that the periods have actually been applied — during an audit, the setting does not count, but the evidence.