> For the complete documentation index, see [llms.txt](https://docs.gallabox.com/llms.txt). Markdown versions of documentation pages are available by appending `.md` to page URLs; this page is available as [Markdown](https://docs.gallabox.com/account-security-features/data-retention-and-privacy.md).

# Data Retention and Privacy

## Data Retention and Privacy

> **Who can use this?**
>
> * Only the **Account Owner** can view and modify the Data Retention configuration.
> * This setting is not visible to agents, admins, or any other roles.

### Plan Availability

Available on all Gallabox plans.

### What is Data Retention?

Data Retention lets you decide how long messages and media files stay in your Gallabox account before they are automatically and permanently deleted. If your organization has a data minimization policy, or you operate under regulations that require you not to hold customer conversations indefinitely, this setting enforces that rule for you — every night, without manual cleanup.

By default, every account is set to **Forever**: nothing is ever deleted unless you explicitly choose a retention period.

{% hint style="info" %}
Deletion under a retention policy is **permanent and irreversible**. Gallabox cannot restore messages or media once the cleanup has removed them — there is no recycle bin or recovery window.
{% endhint %}

### Retention Period Options

| Option                | What gets deleted                      |
| --------------------- | -------------------------------------- |
| **3 Months**          | Messages and media older than 90 days  |
| **6 Months**          | Messages and media older than 180 days |
| **1 Year**            | Messages and media older than 365 days |
| **Forever** (default) | Nothing is ever deleted                |

### What Gets Deleted

When a retention period is active, the daily cleanup permanently removes everything older than the configured period, across **all channels connected to your account** — WhatsApp (all providers), Instagram, Live Chat (web).

Deletion covers messages from every feature that sends or receives them:

| Source               | Examples                                                                                                       |
| -------------------- | -------------------------------------------------------------------------------------------------------------- |
| Inbox conversations  | Agent replies, customer messages                                                                               |
| Broadcasts           | All broadcast messages sent to contacts                                                                        |
| Bot conversations    | Messages handled by any bot or AI agent flow                                                                   |
| Sequences            | Drip and sequence messages                                                                                     |
| Automations          | Auto-replies, welcome messages, away messages, re-engagement messages                                          |
| API and integrations | Messages triggered via Shopify, WooCommerce, Zoho, HubSpot, Razorpay, Zapier, and other connected integrations |
| Comment automations  | Instagram comment-triggered messages                                                                           |

**Media files deleted:**

* Images, documents, audio, and video received in WhatsApp and Instagram messages
* Media files sent in conversation messages (files reused in a newer message are kept until that message also ages out)

**What is NOT deleted:**

* **Contact records** — your contact list and contact attributes are untouched
* **Conversation thread view** — the conversation view itself remains visible in your Inbox; only the individual messages inside it are removed
* **Non-conversation files** — WhatsApp template media, canned response attachments, contact files, attachment media linked to a broadcast, bot flow configuration files, and account or profile uploads are never deleted by this setting

### How Deletion Works

* Deletion runs automatically **once daily** during a scheduled maintenance window. No action is needed from you after saving the setting.
* The first time you enable a retention period, any messages already older than the limit are deleted starting from the next run. Large backlogs are processed in batches, so cleanup may continue over several consecutive nights until complete.
* Once data is deleted, it **cannot be recovered**.

### How to Configure Data Retention

1. Go to **Settings** in the left navigation of Gallabox.
2. Open **Data & Privacy**.
3. Under **Data Retention Configuration**, select a retention period from the dropdown.
4. Click **Save Changes**.
5. If you selected **3 Months**, **6 Months**, or **1 Year**, a confirmation dialog appears. Read the warning, check the acknowledgement box, and confirm. This step cannot be skipped.

Switching back to **Forever** saves immediately with no confirmation — it is the safest state, as no data will be deleted.

{% hint style="success" %}
**Pro tip:** Before enabling a retention period for the first time, export any conversation data you need for audits, disputes, or training records. Once the nightly cleanup starts working through your backlog, those messages are gone permanently — there is no way to pull a report on deleted conversations afterwards.
{% endhint %}

### Changing or Removing a Retention Period

You can update the retention period at any time from the same settings page:

* **Increasing the period** (e.g., from 3 Months to 1 Year) — messages that were previously due for deletion but now fall within the new, longer window are retained going forward.
* **Switching to Forever** — stops all future deletions immediately. Data already removed in earlier nightly runs cannot be recovered.

### Important Considerations

* **This action is irreversible.** Messages and media deleted under a retention policy cannot be restored by you or by Gallabox support.
* **Plan before enabling.** If you have years of existing data, the first cleanup runs over multiple times. Export anything you need first.
* **Compliance is your responsibility.** Make sure the retention period you choose aligns with your organization's data governance and legal requirements before saving.

### FAQs

<details>

<summary>Can I recover messages that were deleted by the retention policy?</summary>

No. Deletion under a retention policy is permanent. There is no recycle bin, recovery window, or backup that Gallabox support can restore from. If you need historical data, export it before enabling a retention period.

</details>

<details>

<summary>Does this delete my bot and broadcast messages too?</summary>

Yes. All messages across all channels are covered — bot conversations, broadcasts, sequences, automations, and messages sent through integrations or the API are all deleted once they're older than the configured period.

</details>

<details>

<summary>Will my contacts be deleted?</summary>

No. Contact records and their attributes are not affected. Only messages and their media files are deleted. Conversation threads also remain visible — just without the deleted messages inside them.

</details>

<details>

<summary>I enabled retention but my old messages are still there — is it broken?</summary>

Deletion runs once per night during a maintenance window, not instantly when you save. If you have a large backlog, it is processed in batches over several consecutive nights. Check again after a few nights; no action is needed from you.

</details>

<details>

<summary>Why can't I see the Data Retention setting in my account?</summary>

Only the Account Owner can view or change this setting. If you're an agent or admin, the **Data & Privacy** section won't show the retention configuration. Ask your Account Owner to review or change it.

</details>

<details>

<summary>Are my WhatsApp template media and uploaded files deleted too?</summary>

No. Only conversation messages and their media are deleted. Template media, canned response attachments, contact import files, broadcast list files, and bot flow files are not touched by this setting.

</details>
