Data retention

Retention follows configured expiry, not indefinite storage.

Your secrets are not read, profiled, trained on, indexed, or retained beyond configured expiry. Support can help with billing cancellation, but cannot restore lost secrets or lost access.

01

Secret retention

Secret objects, files, request submissions, and encrypted chat messages are removed by TTL, view count, manual burn, request reveal, room expiry, quota expiry, or scheduled cleanup. Cleanup is designed to be prompt, but scheduled jobs are not an exact real-time deletion clock.

  • TTL expiry
  • View-limit burn
  • Manual burn and scheduled cleanup

02

Metadata retention

Operational metadata is retained for audit, abuse, billing, and service reliability. It excludes plaintext, passphrases, OTP codes, ciphertext bodies, and full share links.

  • Audit metadata
  • Abuse actor hashes
  • Billing references

03

Free account cleanup

Anonymous free accounts are local-token accounts. Inactive free accounts may be cleaned after the configured free-account retention window, while active paid accounts retain account metadata needed for billing and account security.

  • Anonymous token accounts
  • Inactive free cleanup
  • Paid billing records retained as needed

04

Support and cancellation records

Support records can be used to cancel billing after validation. They must not be used to restore access or reconstruct secrets.

  • Billing cancellation only
  • No account restoration without credentials
  • No secret reconstruction

FAQ

Does Shhhs process secrets with AI?

No. There is no AI processing on secret content.

Can Shhhs recover a secret?

No. Secret recovery would weaken the privacy model.

What can support recover?

Support can help cancel billing after billing validation, but cannot restore account access or secret content.