Data Retention Policy
This policy describes the operational retention targets for FinOps Beacon.
Active accounts
Account, configuration, Azure inventory, cost, recommendation, scan, audit, schedule, and notification information is retained while the organization remains active so historical analysis continues to work.
Operational logs
Cloudflare and application logs are retained for the period configured with those hosting services and are used for security, availability, and troubleshooting. Sensitive credential values are not intentionally written to application logs.
Backups
The production Supabase database uses automatic daily backups with the retention available on the active project plan. Data deleted from the live database can remain in encrypted backups until the backup expires or is overwritten. Backups are used only for disaster recovery.
After deletion
Live application records are removed when deletion completes. Security, billing, or legal records may be retained only where reasonably necessary for fraud prevention, dispute resolution, compliance, or enforcing agreements. Anonymized aggregate information that no longer identifies an organization may be retained.
Exports and requests
Administrators can download an organization summary from Settings before deletion. Questions or access requests can be submitted through the support page.