Skip to content

Data Retention

This page explains how long data is kept in ‘the Site’ services, and who decides.

Two different things happen on the same platform, and the answer to “how long is this kept?” depends on which one you mean.

Content you put into your account — surveys, forms, responses, contacts, inbox conversations, live chat and attachments — belongs to you. You decide how long it is kept, and you have controls in your account to delete it at the account, project, question and response level. We store it on your behalf and delete it when you tell us to, or when a rule you configured tells us to. Where we apply an automatic rule of our own to this content, it is set out below so you know what it is.

Information we hold to run the service — your account and login details, billing records, conversations you have with our support team, and security and abuse records — is ours to decide about. Those periods are set out in “Information we control” below, and in our Privacy Policy.

If you are a respondent who answered somebody’s survey, or a visitor who used a chat widget on somebody’s website, see “If you responded to somebody else’s project” at the end.

You can delete surveys and data from within your account at any time. Once deleted, you may not be able to restore it.

Type of dataCan it be restored?
QuestionsQuestions can’t be restored.
ResponsesResponses can’t be restored.
SurveysThe survey and its content move to the ‘Deleted’ folder, where it stays for 30 days. After 30 days it is marked for permanent deletion, and we retain the data for a further 14 days. After that period the survey and all its data are deleted from the live service. You can also mark a survey for permanent deletion from inside the ‘Deleted’ folder: if it has already been there 14 days or more it is deleted that day, otherwise we retain it until those 14 days are up.

When an account is downgraded, surveys and responses stay in the account. Restrictions on the free plan may make some data — such as results past the plan’s time and storage limits — inaccessible until the account is upgraded again.

Conversations that arrive in your team inbox — by email, WhatsApp, Facebook Messenger, Instagram or your live chat widget — are stored in your account as tickets, together with the contact record and any files attached to them.

What happensWhen
A conversation nobody from your team replied to is deleted automatically30 days after it arrived
Anything deleted — by you, by an inbox rule, or automatically — is erased from the live service, including attached files30 days after deletion
Conversations your team replied to are kept until you delete themNo time limit by default

You can set time-based auto-delete rules on each inbox if you want replied conversations removed on a schedule. We recommend setting one. Without it, conversation content is kept indefinitely — and people write freely in conversations, so it often contains more personal information than you asked for.

For live chat you can also set a retention period for unidentified visitors on each chat channel. Where you enable it, conversations from visitors who never gave you any contact details are deleted along with their contact record once all their conversations are closed and have been idle for the number of days you choose. This setting is off by default. We call these visitors unidentified rather than anonymous because the widget stores a random identifier in their browser so a conversation can continue across page loads — that identifier does not name anyone, but it is not anonymous data either.

Deleting a conversation does not delete the contact it came from, and inbox rules act on conversations rather than contacts. A contact carrying an email address or a messaging account is a record in your CRM in its own right, and it stays there while your account is active until you delete it.

The exception is the unidentified-visitor setting above: where you enable it, contacts created by live chat visitors who never gave you any contact details are removed together with their conversations.

These are periods we set, for data we hold to operate the service.

WhatHow long
Your account and login detailsKept while the account is open. See “Closing your account” and “Inactive accounts” below
Billing and invoicing records10 years, as required by EU tax law
Conversations with our support teamConversations nobody on our team replied to are deleted after 30 days. Conversations we replied to are deleted 180 days after our last reply, once the conversation is marked done
Application and security logs14 days searchable, and up to 180 days in an archive
Error and crash reports90 days
Public API request logs30 days
Webhook delivery records90 days

Our own support conversations are separate from the inbox in your account. If you contacted Shout support, that conversation is covered by this section and by our Privacy Policy — not by the inbox rules you configure in your own account.

You can delete your account at any time. It is disabled immediately, and the account and its data are removed from our system within 90 days. Once deleted, an account cannot be restored. You can also ask us to delete it straight away by contacting the support team.

If you belong to an Organization (Team) and the admin account is deleted, you lose the account features that admin shared with you, and your own account reverts to the free plan.

We consider an account inactive if you haven’t signed in for 17 months. Accounts with a current paid subscription are never considered inactive.

If you are part of an Organization (Team), recent activity or a current paid subscription anywhere in that team keeps every account in it active.

Before anything is deleted we email you a warning, followed by a second reminder. Signing in during that notice period keeps the account active and nothing is removed. Once the notice period passes, the account and its survey data are deleted.

To keep your account active, simply sign in from time to time.

In limited circumstances we retain account information:

  • To enforce our agreements where applicable.
  • To prevent potentially illegal activities.
  • To screen for, and prevent, undesirable or abusive activity.
  • To respond to legal requests or prevent fraud.

Where data is kept for any of these purposes it is used only to resolve that purpose. Once resolved, the associated account data is deleted.

Encrypted database backups are kept for 120 days and are then deleted automatically. Allowing for the short recovery window our storage provider applies to deleted files, a copy of your data can persist in backup for up to around 135 days after it is removed from the live service.

This is why the sections above say data is deleted from the live service. Backups are only ever used to restore the service after a failure — deleted data is never reinstated from them into the live system.

If you responded to somebody else’s project

Section titled “If you responded to somebody else’s project”

If you answered a survey, form, quiz or poll, the Creator of that project decides how long your responses are kept. Contact them to find out — we store the responses on their behalf and cannot make that decision for them.

If you used a live chat widget on somebody else’s website, that business controls the conversation and decides how long it is kept. You should contact them rather than us. Nothing is recorded until you send a message — opening a page carrying the widget creates no record and stores nothing in your browser.