Data Retention Policy
FinOps Beacon is operated by Bryan Wrinkle, an individual based in Fentress County, Tennessee, United States. This policy describes our current operational retention practices. We keep information only for as long as it supports the service, security, recovery, or a legal obligation.
Active accounts
Account, team, Azure configuration, inventory, cost, recommendation, scan, audit, budget, schedule, and notification information is retained while the organization remains active. This lets the product provide historical analysis and auditability. Administrators can remove team members, disconnect Azure, or delete the organization when that history is no longer required.
Connection credentials
Azure application secrets and Microsoft refresh credentials are retained only while the relevant connection is active. They are encrypted in the database and are removed from active storage when the connection or organization is deleted. Microsoft access can also be revoked through Microsoft.
Operational logs
Cloudflare and application logs are retained according to the active hosting configuration and are used for security, rate limiting, availability, and troubleshooting. Retention is based on operational and security need and provider limits. Sensitive credential values are not intentionally written to application logs.
Backups
The production Supabase database uses automatic daily physical backups. The current project plan maintains a rolling provider backup window; data deleted from the live database can remain in encrypted backups until the relevant backup expires. Backups are used only for disaster recovery. Storage objects, if introduced later, require separate recovery because Supabase database backups include their metadata but not the stored files themselves.
After deletion
Live application records are removed when deletion completes. Residual copies expire with the backup window. Security, fraud-prevention, transaction, dispute, or legal records may be retained when reasonably necessary, and anonymized information that no longer identifies a person or organization may be retained.
Exports and requests
Administrators can download an organization summary from Settings before deletion. For access, correction, or deletion that cannot be completed in the product, email support@finopsbeacon.com from the address associated with the account so ownership can be verified.