Data Retention Policy
Effective date: 4 July 2026 Last updated: 4 July 2026
This is the English-language version, which is the authoritative version.
This Data Retention Policy explains how long Open Tools at open-tools.app (the
"Service"), operated by NM Technology Services & Solutions (Grupo NMTSS), NUIT 112059725,
keeps the data it processes, and when it is deleted. It supplements the
Privacy Policy.
Our principle is data minimisation: we keep data only as long as needed for the purpose it was collected, then delete it. Uploaded files in particular are auto-deleted on a short schedule — the Service is not file storage or backup.
1. Retention schedule
| Data | Retention | Notes |
|---|---|---|
| Uploaded files — anonymous | ~15 minutes | Deleted automatically after processing. Browser-only tools upload nothing. |
| Uploaded files — signed-in | ~24 hours (flat) | A single window today, regardless of account — no per-plan differences. |
| Published QR-site files | Until the owner deletes the site | Kept for as long as the QR site is published. |
| Job history rows | Anonymous none · Free 7 days · Pro 90 days | Kept only for signed-in users; retention depends on your plan. |
Sessions (tlmk_sid, IP, User-Agent) | 7 days | Only a SHA-256 hash of the session id is stored. |
| Email-verification / password-reset tokens | Minutes to 24 hours; single-use | Expire on use or on timeout, whichever is first. |
| Usage events | ~180 days | Minimal internal events (e.g. signup, login, job submitted), tied to user id or anonymised IP. |
| Error logs | ~30–90 days | Self-hosted (Bugsink/Sentry). Application errors only — not file contents. |
| Account data (email, scrypt password hash, verified flag) | While the account is active | On deletion, permanently removed within 30 days, including from backups. |
| API keys | While the key is active | Stored as a hash; the key is shown once at creation. |
| Support & chat records (contact-form messages, live-chat transcripts, associated email) | Kept up to 6 months after your request is resolved, then deleted | Stored in self-hosted Chatwoot on our own infrastructure. |
| Subscription records (status, PayPal subscription id) | None today — paid plans not yet available | Will apply once paid plans launch: kept while the subscription is active, then only as required for tax/accounting. Card/bank details never stored — held by PayPal. |
The tiers in operation today are anonymous, Free, and Pro. Paid plans are coming soon; when they launch, they may extend some of these windows (for example, file retention or job-history retention), and any such changes will be described at that time.
2. Uploaded files
Files you upload for server-side processing are deleted automatically on the schedule above. Anonymous uploads are removed after about 15 minutes; signed-in uploads after about 24 hours. This is a single flat window today — there are currently no per-plan differences in file retention. Files that are part of a published QR site are kept until you delete that site. Tools that run entirely in your browser never upload your file, so there is nothing to retain.
3. Job history
Job history is kept only for signed-in users; anonymous use leaves no job-history rows. For signed-in users, these rows are retained for 7 days (Free) or 90 days (Pro), and are removed once they exceed your plan's window. If your plan changes, the window for your current plan applies going forward.
4. Sessions and tokens
Sessions last 7 days, after which they expire and the associated session record (its hash, IP, and User-Agent) is removed. Email-verification and password-reset tokens are short-lived (minutes up to 24 hours) and single-use — they cannot be reused once consumed or expired.
5. Usage events and error logs
Usage events are minimal internal records used for rate-limiting, abuse prevention, and product metrics, retained about 180 days and then deleted. They are not shared with any third-party analytics. Error logs from our self-hosted monitoring are retained about 30–90 days and capture application errors only — never the contents of your files.
6. Account data and deletion
Your account data is kept while your account is active. When you delete your account (from account settings, or by asking us at legal@open-tools.app), we permanently remove it — the account, sessions, API keys, entitlements, and your files (and, once paid plans launch, any subscription records, cancelling any active subscription). Removal completes within 30 days, including from backups. You can also use Export my data first to keep a copy.
7. Legal holds and exceptions
We may retain limited data beyond the periods above where the law requires it (for example, tax or accounting records), or where reasonably necessary to resolve disputes, prevent abuse, or enforce our agreements. Any such data is kept only for as long as that purpose requires, then deleted.
8. Changes
We may update this policy from time to time, for example if retention windows or plans change. The "Last updated" date reflects the latest version.
9. Contact
NM Technology Services & Solutions (Grupo NMTSS), registered in Mozambique, NUIT 112059725. Registered address: Av. Capitão Pereira do Lago, nº 1837, 7º Bairro Matacuane, Beira, Sofala, CP 2300, Moçambique. Privacy contact: legal@open-tools.app.