Skip to main content
Legal

Data Retention & Incident Response

Last updated: August 10, 2026

Retention Scope

ClearSplit retains case data, audit logs, and account information according to the following schedule:

Active Cases

Purchased cases remain fully active for 36 months from the date of purchase. During this period, all case data, documents, and features are available without restriction. Data is available for export at any time through the built-in PDF, CSV, and JSON export tools.

Archived Cases

After the applicable active period, a case may transition to read-only archive status. Archive is a product-access state: data remains viewable and exportable, but editing and new uploads are disabled. Archiving a case is not a deletion request and does not start the deletion schedule below.

After Account Deletion

After we verify an account or case deletion request, a 90-day recovery window begins. By day 90, the affected case records are removed from active systems and the per-case key material is destroyed in our live systems (crypto-erasure). From that point the encrypted documents cannot be read using anything in our live systems.

We want to be precise about one limit rather than overstate it. Our infrastructure backups include the database, and the database is where per-case key material lives. A backup taken before your deletion therefore still contains that material for as long as we retain that backup. During that window, restoring such a backup could make the affected content readable again. Once every backup predating your deletion has aged out of its retention period, that is no longer possible. We do not restore backups to recover deleted case content, and doing so would create an audit record.

Audit Logs

Audit trail records (who changed what, when, and the before/after values) are retained for 7 years from creation, independent of case or account status. This extended retention supports compliance requirements, dispute resolution, and legal discovery obligations common in family-law matters.

Account Information

Operational account and membership records follow the deletion process above. We may retain the minimum billing, fraud-prevention, security, or legal records required by law or needed to establish compliance; those records are restricted to those purposes.

Login and Security Logs

We target deletion of login-attempt and rate-limiting records after 90 days through the operational retention process. This is a retention target, not a claim that an automated purge job is currently active.

Data Deletion Requests

Account holders may request deletion of specific cases or their entire account by contacting us. A case's read-only archive control does not submit this request. After identity and authority are verified:

  • A 90-day recovery window begins, during which the request may be verified and any authorized final export completed
  • By day 90, active case records are removed and per-case key material is destroyed in our live systems, so encrypted documents cannot be read using anything in those systems
  • Audit and minimum legal/security records are retained only under the applicable schedule and access restrictions
  • Account credentials are immediately deactivated
  • Object-Lock ciphertext may persist through its configured retention period and is unreadable using live key material after crypto-erasure
  • Backups taken before the deletion still contain the key material until those backups age out of retention

We recommend exporting all needed data before requesting deletion, as deletion is permanent and cannot be reversed.

Incident Response

In the event of a security incident that may affect your data:

Notification

We will notify affected account holders within 72 hours of confirmed unauthorized access to case data. Notification will include the nature of the incident, data potentially affected, and remediation steps taken.

Investigation

Our incident response process includes immediate containment, forensic analysis, root cause identification, and implementation of preventive measures. We maintain detailed incident logs for post-incident review.

Reporting

Where required by applicable data protection laws, we will file appropriate notifications with regulatory authorities within mandated timeframes.

Backup and Recovery

We use encrypted infrastructure backups and encrypted cloud object storage as configured for the service. Recovery capability and retention windows may vary by system. Deletion requests are applied to active systems and to live key material under the 90-day process above. Object ciphertext that outlives that process is unreadable using live key material. Backups predating a deletion are the exception described above: they retain the key material until they age out.

Contact

Data retention, deletion requests, and incident reports: security@clearsplit.com

© 2026 ClearSplit — Divorce Asset Division Tool

ClearSplit is not a law firm and does not provide legal advice. It is a self-service tool and is not a substitute for a licensed attorney.

Privacy • Terms • Retention & Incident Response