Data retention
Last updated: 14/09/2026 · Periods below are Eveil's own policy, not a third-party standard
1. Default periods
2. Enforcement
Erasing one specific person, whether from their own reply of "STOP" or from a direct request to us, takes effect immediately and does not wait for a schedule: see section 3. That part of this page is already true of every lead in the system today.
The time-based sweep that applies the 6-month, 3-year, and 90-day windows above to everything else is Eveil's committed retention policy. Eveil is an early-stage, actively developed product, in the spirit of the "Status" note on its own README: if the scheduled job that enforces this sweep automatically has not shipped yet on the version you are running, these periods are the ceiling we are building toward, not yet a background process you can observe. Check the project's GitHub issues for its current state before relying on it as fact rather than policy.
3. Erasure and the hash
Erasing a lead clears their name, email address, job title, LinkedIn URL, and source page, and blanks the subject and body of every message sent to or received from them. The row itself is not deleted: what remains is a one-way hash of their email address and the date they were erased, kept specifically so that person can never be re-added and re-contacted, even by a later CSV import or a fresh discovery run turning up the same page. The hash cannot be reversed back into an address.
Erasure is scoped to the one person: it never deletes or hides the company they belonged to, or any other contact at that company, since one person asking to be forgotten is not their employer asking to be removed from consideration.
4. Suppression layers
An opt-out is enforced at one of three layers, depending on what triggered it: a "STOP" reply suppresses that address for the project it was sent to; a hard bounce suppresses it for the mailbox that sent it, since the address is what failed to deliver, not the project; and an address flagged as a spam trap or otherwise toxic is suppressed instance-wide, fed only by public signals never by anything a customer's prospect did.
Two situations escalate suppression further: a spam complaint suppresses the address across the whole organization, not just the one project it complained about, and the same address replying "STOP" to two different projects inside one organization does the same. In both cases the wider suppression is permanent and is never undone by a later import.
5. Operator tuning
On a self-hosted instance, these periods are not yet adjustable from a settings screen: there is no operator-tuning control for them today. If you need different values, they are fixed in the application's source rather than the database, so changing them means changing the code that reads them until a tuning screen ships.