Retention and deletion
Updated September 7, 2026
How long each category of data is kept, how to have a tenant erased, and what remains in backups afterwards. The fields these retention periods apply to are listed on the data page.
Retention by category
| Category | Retained |
|---|---|
| Credential inventory | Refreshed on every sync. A credential deleted in Entra stops being reported once the next sync no longer sees it. |
| Tenant, users and configuration | Held for the life of the account, then removed on a deletion request. |
| Audit log and monitoring reports | 180 days, then aged out. A deletion request removes them immediately regardless of age. Audit logging. |
| Webhook delivery records | Held for the life of the account, then removed on a deletion request. |
| Application logs | No more than 90 days, for security and debugging. See the privacy policy. |
| Database backups | Automated point-in-time-restore backups, kept for the length of the restore window. |
Deleting a tenant
Email contact@aztokenwatch.com and your tenant is deleted from the database within 7 business days. The deletion covers applications, credentials, users, reports, the audit log, webhook and Azure DevOps configuration, delivery records and the billing record, removed in a single transaction. No soft-delete flag is set and no orphaned rows are left behind.
Backups
The database has automated point-in-time-restore backups. A deleted tenant is gone from the live database immediately, and copies persist inside those backups until they age out of the restore window. Backups are not queryable as part of the running service, and no request reads from them except a restore of the whole database.
Related
- What data Token Watch holds — the fields these periods apply to.
- Revoking access — stopping the integration, which is a separate step.
- Privacy policy — the legal statement covering the same ground.
Token Watch