Skip to content

Retention

A tip cannot be deleted once it is sent, and it is not kept forever. After the retention period, and only after a documented review, the tip is permanently destroyed. This page explains both halves: why deletion does not exist, and what destruction actually removes.

Nothing in the system deletes a tip on demand. Not the person who sent it, and not an operator. There is no delete control to press, no request form, no exception path.

That absence is the protection. If a tip could be deleted, it could be destroyed by anyone with a reason to want it gone, including someone who pressures the sender to take it back. Because deletion does not exist, that pressure has nothing to work with. Once a tip is sent, it stays sent.

If you sent a tip and want nothing more to do with it, you do not have to do anything. You can stop checking on it at any time.

Every tip has a retention period. When that period ends, destruction follows a review-before-purge rule:

  1. The tip is flagged for review. Nothing is deleted silently.
  2. An authorized operator decides: keep the tip because it is still relevant, which restarts the retention clock, or clear it for destruction.
  3. Only a cleared tip is destroyed.

Destruction removes the tip’s records, its attachments, and the stored files. It also destroys the key. Each tip is sealed with its own key, and the only copies of that key live inside the tip’s own records. When the records go, the key goes with them, so nothing left in the live system can unlock what the tip said.

Destroyed does not mean every trace vanishes at the same instant. Three things are true after a purge, and each is worth stating plainly.

  • The audit trail survives. The log of operator actions is kept for accountability, with its link to the destroyed tip removed.
  • The program’s own key survives. It is shared across all tips and is not destroyed at purge. By itself it cannot recover a destroyed tip, because the per-tip key it would need no longer exists.
  • Backups age out on their own schedule. Destruction covers the live system. Encrypted backup copies of a tip can persist until the backup rotation replaces them; they are not erased at the moment of purge.

A tip also cannot be destroyed early. The retention review exists to prevent silent loss in both directions: no quiet deletion before the period ends, and no unreviewed purge after it.

The exact wording of every enforced guarantee, including the one this page explains, is in the register on How TypVault protects you.