Effective September 4, 2026

Data Retention Policy

This policy describes the operational retention targets for FinOps Beacon.

Active accounts

Account, configuration, Azure inventory, cost, recommendation, scan, audit, schedule, and notification information is retained while the organization remains active so historical analysis continues to work.

Operational logs

Cloudflare and application logs are retained for the period configured with those hosting services and are used for security, availability, and troubleshooting. Sensitive credential values are not intentionally written to application logs.

Backups

The production Supabase database uses automatic daily backups with the retention available on the active project plan. Data deleted from the live database can remain in encrypted backups until the backup expires or is overwritten. Backups are used only for disaster recovery.

After deletion

Live application records are removed when deletion completes. Security, billing, or legal records may be retained only where reasonably necessary for fraud prevention, dispute resolution, compliance, or enforcing agreements. Anonymized aggregate information that no longer identifies an organization may be retained.

Exports and requests

Administrators can download an organization summary from Settings before deletion. Questions or access requests can be submitted through the support page.