Mizan

Data Retention

Last updated: August 2026

This page explains how long Mizan keeps each category of data, and how to delete it. It is part of our Privacy Policy.

The principle

We retain data only for as long as it serves a clear purpose: powering the dashboards, billing you accurately, securing the service, or meeting legal obligations. When a purpose no longer applies, we delete or anonymize the data. We do not keep data “just in case” beyond the windows below.

Retention schedule

DataRetained for
Usage records (daily aggregates of tokens, cost, model, provider)Life of the account — required to power the dashboards and forecasts.
Gateway request logs (metadata: model, tokens, cost, latency, status; no prompt/completion content)Life of the account — required for wallet billing, audit logs, and support. Kept even after a key is revoked, so historical spend stays attributable.
Wallet transactions & payment intent referencesLife of the account, then as long as required by tax and accounting law (typically 6–7 years).
Provider credentials (API keys) & email connection credentialsUntil you delete the connection or close the account. Always encrypted at rest; never returned.
Receipts (including scanned email content)While you keep them; deleted when you delete the receipt or close the account. Raw scanned content is truncated at ingestion.
Khabir conversationsUntil you delete the conversation in the product or close the account.
Budget rules, alerts, cost centers, projects, subscriptionsLife of the account; deleted when you delete them or close the account.
Account & profile informationWhile your account is active, plus a short period after closure to handle outstanding billing and disputes.
Aggregated, de-identified statistics (e.g. platform-wide usage)Indefinitely, in a form that cannot identify you.

Prompts & completions

Gateway prompts and completions are never stored, so there is nothing to retain. They are forwarded to the provider you selected, returned to you, and discarded. The only per-request record we keep is the metadata described in the schedule above. If you route through your own connected account (BYOK), retention of content is governed by that provider's policies, not ours.

Deleting data

Most data can be deleted directly in the product: connections (which removes their credentials and usage records), projects, keys, cost centers, budget rules, subscriptions, receipts, and Khabir conversations. Deletion is permanent and cannot be undone. Usage records that are part of an active billing history (wallet debits) are removed when you delete the underlying key or close the account, subject to the tax/accounting hold below.

Deleting your account

To delete your account, email naim@app-mizan.com from the address on the account. We'll confirm and then permanently delete your profile, connections, credentials, conversations, and usage data within 30 days. We retain wallet transactions and payment records only for as long as required by tax and accounting law (typically 6–7 years), after which they too are deleted. Aggregated, de-identified statistics may be kept indefinitely.

Backups

Our database host (Neon) maintains short-term backups for disaster recovery. Deleted rows may persist in these backups for a brief window before they are recycled, and are not restored to serve the service. Encrypted provider credentials are never recoverable without the encryption key, which is stored separately and never with the data.

Questions?

Contact naim@app-mizan.com and we'll tell you exactly what we hold and how to remove it.