Skip to main content
Cedros

Setting data-retention periods

Choose retention periods, understand what cleanup removes, and check saved settings before deleting old records.

Use Settings → Site → Data retention to choose how long Cedros keeps form responses, analytics, audit history, assistant conversations, and other stored records.

Changes save automatically. Shortening a retention period can make existing records eligible for deletion at the next cleanup. Increasing it later does not restore records already removed.

Review what you need to keep

Before shortening a period, consider how far back your team needs to investigate problems, answer customer questions, review activity, or compare reports. Save any records you need to retain before changing the setting.

Choose a period for each category rather than assuming one window suits everything. For example, a short-lived contact-import file may serve a different purpose from the form response that started a customer relationship.

Where a dropdown offers Keep forever, Cedros skips age-based retention cleanup for that category. This does not create a backup or protect records from other deletion actions. Categories without this option require a bounded period.

Retention settings also do not update the wording of your Privacy Policy or Terms of Service. Review those separately when your data-handling practices change.

Understand the main categories

Form submissions → Submission field values. Controls how long stored form responses are retained. Cleanup can delete the old submission records, not just hide their answers. Check any responses your team still needs in form submissions first.

Audit logs → Audit entries. Controls the history of administrative actions. A shorter period leaves less history available when investigating changes.

Analytics → Events and Visitors. Events include page views and conversions; Visitors covers visitor identity records. These are separate settings. Visitor cleanup uses the last-seen time, while event cleanup uses the event time. Shorter periods can reduce the history available for reporting and investigation. Some built-in report-run history also follows the Events period.

Assistant chat → Conversations and Action audit. Conversations covers admin-assistant transcripts, with inactivity measured from their last update. Action audit covers recorded write actions performed by the assistant. Keeping one does not automatically retain the other.

Email marketing → Import files, Import rows + errors, and Recipient exports. These control contact-import source files, per-row results and errors, and generated downloadable CSVs. They are not a mailbox retention setting. Download an import report or export you still need before it expires.

Review operational history and access settings

Operational history contains separate periods for security, automation, fleet, and revision history. Match the setting to the records you mean to change:

  • Allowed security events and Security incidents distinguish routine allowed traffic from requests that triggered extra protection. Security summaries can remain after raw events expire; see lockouts and blocked traffic for interpreting the report.
  • Skipped automation ticks covers scheduler checks that did no work. Terminal automation runs covers completed successes and failures; the latest result for each job remains.
  • Fleet health samples, Fleet heartbeats, and Other fleet requests cover site-management history. The latest health sample for each site and check type remains.
  • Runtime revisions limits older restorable versions of runtime objects. The latest revision per object remains, but a shorter period reduces the older versions available for recovery.

Local admin sessions → Session lifetime limits how long a local admin login session remains valid. Shortening it can require administrators to sign in again. This is an access setting, so do not assume its effect waits for the hourly cleanup.

MCP tokens shows Default TTL and Maximum TTL, where TTL means token lifetime. These apply to task-scoped tokens, not the personal API keys used to connect coding clients. The maximum cannot be lower than the default; check both saved values together if you change them. These controls do not enable additional assistant features.

Backups → Daily backup sets is a count of recent daily backups, not a number of days. Older backup points selected for the approximately two-week and one-month retention tiers are handled separately. Lowering the count can change which restore points are listed, and surplus sets are pruned by the backup process. Review the backup points you need before reducing it; Run cleanup now is not a backup-pruning button.

Change a retention period

  1. Open Settings → Site → Data retention and wait for the saved settings to load.
  2. Find the category and read its description. Check whether the dropdown represents a time period or a backup count.
  3. Select the new value. The change saves automatically; there is no separate Save button.
  4. Wait for Retention settings saved. before making another change or leaving the page.
  5. Reopen the page to confirm the stored value, especially after a failed save or interrupted connection.

Age-based record cleanup normally runs hourly. A shorter window applies to existing eligible records, not only records created after the change. A large backlog may take more than one cleanup cycle to remove.

If the save fails, the selected value alone is not proof that the change was stored. Read the error, reload the settings, and confirm the saved value before retrying or running cleanup.

Run cleanup only when you intend to delete data

Run cleanup now immediately applies the saved cleanup rules across categories. It is not a preview, a count of what might be deleted, or an action limited to the last dropdown you changed. The button starts the operation without a separate confirmation dialog.

Before using it, review the saved periods and preserve any records you need. Cleanup can permanently remove records from the live database, and this page has no Undo action.

After a successful run, Cedros shows Cleanup complete with a total. Deleted by category appears for categories with a nonzero count. Counts may represent records, files, or cleaned jobs rather than individual people.

Cleanup also handles expired operational records beyond the categories you changed, so the summary may contain additional labels. A zero result means that run reported no deletions; it does not prove that the site has no stored data. If cleanup fails, do not assume earlier deletions were rolled back.

Resolve common problems

Settings are disabled or unavailable. Wait for loading to finish. If an error or access restriction remains, ask your administrator to check your feature access and permission to manage retention.

A value changed but I did not see a save confirmation. Reload and check the saved setting. Resolve any save error before relying on the selected value.

Old records are still present. Check the saved period and whether Keep forever is selected. Consider the record's relevant date, such as a visitor's last visit or a conversation's last update. Some categories preserve the latest state. Allow for scheduled cleanup and batching; if records remain unexpectedly, ask your administrator to check cleanup failures or scheduling.

History disappeared after shortening a period. Changing the period back will not restore deleted records. Check any exports or retained backups with your administrator before planning recovery.

Run cleanup now returned an error. Record the error and ask your administrator to investigate. Some categories may already have been cleaned. Verify the remaining data and saved settings before retrying.