How long things are kept
What OMAI keeps while your account is active, what deleting one item actually removes, what happens step by step when you request deletion of the account, and the records that are kept afterwards because the law requires it.
- Who
- Owners and admins
- Plan
- All plans
- Role
- Only the Owner can request deletion of the account
Before you start
- Download the data export before requesting deletion
OMAI keeps your business data for as long as you have an account, and removes it when you ask. This article gives the real periods where a period exists, describes what deletion does store by store, and names the records that survive a deletion request because a law requires them.
While the account is active
Nothing ages out on its own. A conversation from a year ago is still in the inbox, and a document you uploaded and never touched again is still in the knowledge base. Data leaves when you delete it, or when the account is deleted.
| Category | Kept | What ends it |
|---|---|---|
| Conversations, messages and attachment records | For as long as the account exists | Deletion of the account. There is no per-conversation delete. |
| Contacts and leads | For as long as the account exists | Deletion of the account. |
| Knowledge sources and their extracted passages | Until you delete the source, or the account is deleted | The Delete action on the source row. |
| Superseded versions of a knowledge source | Kept alongside the active version | Deletion of the source or of the account. |
| AI processing records (technical metadata only) | For as long as the account exists | Deletion of the account. |
| Usage counts and cost records | For as long as the account exists — they support billing | Deletion of the account, except where they underpin an invoice. |
| Audit log entries | For as long as the account exists | Deletion of the account clears their detail and IP but keeps the rows. |
| Invoices, charges and tax documents | The period Israeli tax law requires | Nothing. These survive a deletion request. |
Deleting a single item
The one thing you can delete on its own is a knowledge source. Selecting Delete on its row takes it out of the assistant’s search immediately, then a background job works through every place a copy could exist: the search index, the extracted passages, the uploaded file in storage, any queued or failed indexing work, and the database records. The job records an outcome per store and will not report success while one of them failed; after five failed attempts the source is flagged for manual review.
When every store reports success, the source finishes in a state that says the copies in backups will expire on the retention schedule below — not that every trace is gone the same second. Managing your knowledge base covers the buttons; this is what happens behind them.
Conversations, contacts and leads have no delete button. Removing one customer’s data is a written request to support.
Sessions, links and cookies
| Item | Lifetime |
|---|---|
| A signed-in session | 30 days, and it ends immediately when the password is reset |
| A password reset link | 30 minutes, single use |
| An email verification link | 24 hours, single use |
| The interface-language cookie | 365 days |
| The privacy-choices cookie behind the consent banner | Until you change your choice from Cookie preferences |
Requesting deletion of the account
The control is on Dashboard → Settings → Account & privacy, under Delete account. Only the Owner can use it: an admin who tries sees *Only the account owner can request deletion.* You confirm by typing DELETE, then select Request account deletion.
What happens after you request it
Step 1 The request is recorded and the organization is frozen the same moment.
You should see: Processing stops: inbound WhatsApp messages are no longer taken in, no replies are generated, nothing is sent out, and no knowledge is indexed. The screen shows Deletion request received. We’ll contact you to complete the process.
Step 2 Wait out the 24-hour window before destruction begins.
You should see: Nothing is destroyed during this period. It exists so a request made in error can still be stopped.
Step 3 A background sweep picks the request up and re-checks who asked.
- The sweep runs about once an hour, so destruction starts shortly after the 24 hours are up, not at the exact minute.
You should see: The requester must still be a member and still an Owner, and no legal hold may be in place. If any of that fails, the deletion is held and the reason recorded.
Step 4 The deletion tasks run, then a verification step counts what is left.
You should see: Messages, contacts, conversations, knowledge sources, knowledge passages, AI records, stored files and the search index are counted. Any non-zero count fails the verification and keeps the request out of a finished state.
Step 5 The request waits for the backup horizon to pass.
You should see: Only after that can it be reported as finished — see Backups below.
What is kept even after a deletion request
A deletion request cannot be used to erase the evidence that the business existed, paid, agreed to terms, or that the deletion itself was lawful. These records stay:
| Record | Why it stays |
|---|---|
| Invoices, charges and the subscription record | Financial and tax obligations under Israeli law. |
| Acceptances of the Terms and other legal documents | Evidence of what was agreed, by whom and when. |
| Consent records | Evidence that a consent decision was made and honoured. |
| Audit log rows | Evidence that the deletion was requested by an authorised person and carried out. Their detail fields and the stored IP address are cleared; the rows themselves are kept. |
| The organization record itself | It is kept as an empty shell so the records above still have a parent. The name becomes Deleted organization, and legal name, industry, website and phone are cleared. |
What is destroyed
Everything that is not on the list above, including: messages and their attachment records, conversations, contacts, leads, AI processing records, handoff events, internal notes, knowledge sources, versions and passages, entries in the search index, every file stored under your organization, imported history, business hours and closures, services, FAQs, policies, message templates, the business profile, the assistant settings, and every team membership.
Provider credentials are removed too, and in that order: the secret in the vault first, then the record that pointed at it.
Backups
Deleted data can still exist in routine backups until those backups age out. The longest chain in OMAI’s current setup is 35 days, so a deletion is only reported as finished once that period has passed. Backups are not searched or restored to answer a deletion request; they simply expire.
The timeline we work to
The published Data Deletion instructions state the commitment: we aim to acknowledge a request within 72 hours and to remove your data from our active systems within 30 days of verifying it. Deletion requests are handled by our team, and we confirm in writing to the address on the account once the removal is complete.
A legal hold pauses everything. If a hold applies to some of the data — for example because of a dispute or an investigation — the deletion stops until the hold is released, and the request is reported as paused rather than finished.
Can I delete my personal login without deleting the business?
No. The product deletes an organization, not an individual login. To leave a business, ask an owner to remove you from Dashboard → Team; that ends your access to it.
Does disconnecting my WhatsApp number delete anything?
No. It stops messages arriving and the assistant answering on that number. Stored conversations, contacts and knowledge stay exactly where they were.
How do I get a copy before deleting?
Use Export data (JSON) on the same Account & privacy card. The export is described in what OMAI stores, and where.
Will I get an automatic email confirming the deletion?
No automated confirmation is sent. Our team confirms in writing to the address on the account once the removal is complete.
