Account
Privacy & data retention
Control how long Quincer keeps personal data, and respond to data‑subject requests — export or delete everything Quincer holds about one person. Settings live under Settings → Privacy.
Set data retention
Chat conversations follow your plan’s retention window automatically. Each plan keeps conversation history for a set period, counted from the conversation’s last activity (an active thread is never deleted just because it started long ago). A daily sweep deletes anything older — message content and the matching attachment files in storage — with no setup on your part:
| Plan | Conversation history kept |
|---|---|
| Free | 30 days from last activity |
| Starter | 90 days from last activity |
| Growth | 365 days from last activity |
| Website + Widget | 365 days from last activity |
| Scale | Unlimited |
Your own retention policy can shorten that window — set Delete after 30 days on a Growth plan and 30 days wins — but it can never extend past the plan’s window. Every other data type (memory, voice, leads, surveys, inbox email) defaults to keep forever until you turn on a window for it; Quincer then deletes anything older than that window once a day, and removes the matching files (recordings, attachments) from storage too.
In the Data retention card below, each data type is its own row with a dropdown that’s either Keep forever (Plan default on the conversations row) or Delete after 30 / 90 / 180 / 365 days. The Visitor memory (inactivity) row also carries the Enable automatic deletion of inactive visitor memory checkbox — its dropdown stays locked until you tick it. Toggles like Delete call audio after transcription → Enabled keep the searchable transcript but drop the recording. When you’re done, Save retention settings commits the windows, or Apply call-center preset fills the form with short windows for high-volume phone lines (you still review and Save).
Automatically delete personal data after a set period. Conversations are deleted after your plan’s window by default (30/90/365 days by plan, anchored on last activity); every other data type defaults to keep forever until you turn on a window. Runs daily.
The Data retention card — a per-type dropdown (Keep forever or a delete-after window) with the memory-inactivity and audio-after-transcription toggles.
- Open Settings → Privacy.
- For each data type, choose Keep forever or a window (e.g. Delete after 90 days).
- Save. The daily sweep starts applying your windows automatically.
Except for conversations — which always follow your plan’s window — windows are opt‑in: anything left on Keep forever is never auto‑deleted, so turning on retention won't unexpectedly remove data you still need (for example, captured leads).
What you can set a window on
- Visitor memory — a returning visitor's remembered profile, deleted after a period of inactivity.
- Chat conversations & transcripts — message content and attachments. Your plan's window applies by default; your own setting can only shorten it.
- Voice calls & transcripts — voice session records and transcripts.
- Voicemail recordings — audio and transcriptions (a short window is recommended).
- Leads — captured contact details (often kept for the sales relationship — choose deliberately).
- Survey responses — CSAT and survey submissions.
- Inbox email — messages ingested by the email‑inbox automation.
Visitor memory
When visitor memory is on, enabling “automatic deletion of inactive visitor memory” removes both a visitor's learned profile and their identity record after the chosen period with no activity — not just individual remembered facts.
Export or delete one person's data
To handle a data‑subject request (right of access / right to be forgotten), use the Data subject requests tool in Settings → Privacy. It works across all stores — memory, leads, conversations, voice, voicemail, surveys, and inbox email.
In the card below you type the person’s identifier into the Email, phone, or visitor ID field, then choose one of three actions: Look up shows how much matches by type, Export downloads a JSON file of everything held, and Erase — the destructive one — asks you to confirm before it permanently deletes. Results appear in the panel underneath the buttons.
Look up, export, or erase everything held about one person across memory, leads, conversations, voice, voicemail, surveys, and inbox email. Erasure is permanent. Every action is logged.
The Data subject requests tool — one identifier, three actions: Look up, Export, and the permanent Erase.
- Enter the person's email, phone number, or visitor ID.
- Look up to see how much data matches, by type.
- Export downloads everything held about them as a JSON file.
- Erase permanently deletes everything held about them. This can't be undone.
Every retention deletion and data‑subject request is written to an append‑only audit log (counts, type, and timestamp) for your compliance records.
Consent notice
You can show visitors a short consent notice when memory or recording is active — enable it and set the wording under Settings → Privacy → Consent notice.
How conversations are protected
Alongside the retention controls, a platform-wide security hardening pass (July 2026) tightened how conversation data is reached in the first place. Nothing here needs configuring — it’s live on every account:
- Visitor-bound conversation tokens — every conversation is cryptographically bound to the visitor it belongs to. A per-conversation secret is minted when the thread is created and returned only to that visitor’s browser; reading or continuing the thread (polling, resuming, file uploads) requires it. Your public embed key alone can’t read or write anyone’s conversation.
- Authenticated voice media — every voice media connection must present a signed, per-call credential before any audio flows. An unauthenticated party can’t open a media stream against your account.
- Payment-confirmed subscription changes — subscription status changes only take effect on confirmed payment. A checkout that never completes payment can’t activate paid features on an account.
A note on compliance
These controls — configurable retention, deletion on request, export, consent, and an audit trail — are the building blocks for GDPR, PIPEDA, and SOC 2 programs. They don't by themselves constitute certification; pair them with your organization's written retention policy and data‑processing agreement.