Moneli Assistant

Data retention & deletion

Last updated: 2026-08-07 · Version 0.1 · Status: Draft for legal review — not yet in force

What is kept, for how long, and what deleting actually deletes. Written from the scheduled job that does the deleting, not from an intention. Where the software keeps something after you have asked it not to, that is stated here rather than left for you to discover.

1. The automatic purge

A scheduled job runs daily and permanently deletes:

WhatAfter
Call records — the transcript, caller number, timings, the generated summary, sentiment and action items 6 months
Operational diagnostic events — including, for a file, a line naming the member of staff it was sent to and the file's name (never its contents) 90 days
Files your assistant made for you and sent into the chat — the document itself and its contents 7 days

Those first two rows are deliberately different lengths, and the difference matters if a filename is itself sensitive. The document is destroyed after seven days. The one-line diagnostic record that a file was delivered — who to, what it was called, how large it was — is kept for ninety, because a run of refused or unexpected deliveries is how we would notice an assistant sending something it should not. So a document called redundancies-final.pdf is gone in a week, but the fact that a file of that name went to that person is visible to us for three months.

This is a hard delete, not an archive or a flag. Once the job has run, the row is gone and we cannot produce it again — including for you.

2. What the purge does not touch

This is the section a template would omit. It is the one worth reading.

Review note — remove before publishing. The shared, unpurgeable assistant memory is the most significant gap between what a customer will assume and what the software does. It should be resolved in the product — by scoping memory per user, or by building a purge path — rather than only disclosed. Until then this page must keep saying so, and no contract should promise deletion we cannot perform.

3. Asking us to delete something

If you are a business using the service, you can clear your saved business information from your own settings page at any time. For anything else — a specific call record, a customer's data, or your whole account — write to info@moneliautomation.com.

If you telephoned a business and want your information removed, ask that business: they decide what is collected and we act on their instructions. The call recording and AI disclosure page explains this.

We will tell you plainly which parts we can delete and which we cannot, including the assistant memory described above.

4. When an account closes

Before anything is destroyed, we make and retain a complete final export for the business. The export includes the business records in this application, files the assistant generated, chat transcripts available from its dedicated machine, its learned memory, and its accounting files. If a complete export cannot be made, deletion stops. The only exception is when the customer explicitly declines the export with a separate confirmation.

The closure workflow then permanently deletes the tenant and its users, configuration, credentials, calls, contacts, chat records, generated files, integrations, scheduled work, email and repository activity records, usage records held by the application. The customer's dedicated assistant machine is destroyed, not selectively wiped, so its memory, accounting journal and files leave with its disk. Operator-held disaster-recovery archives and the box credential are removed separately.

We keep an operator deletion report with the time, operator, row counts and a separate result for the application, dedicated machine, operator archives and database backups. If a machine, archive directory or provider could not be checked, the report says not checked; it does not call the source empty or the deletion complete. Application database backups can retain deleted rows for seven days after the application deletion. Account deletion is not marked complete until that period has ended and an operator has verified the expiry.

This is not legal advice. This document was drafted from what the software actually does, by the people who built it, and it has not been reviewed by a lawyer. It must be reviewed by Canadian privacy counsel — and, where a customer is a health information custodian or a law firm, by counsel familiar with PHIPA, the Alberta Health Information Act, Quebec's Law 25 and professional obligations of confidentiality — before it is published or relied on by anyone. Highlighted [LIKE THIS] are facts we have deliberately not invented; they must be filled in before publication.