Set the policy
Go to Settings → Data retention. Pick a window:- Forever — data stays until you delete it. This is the default.
- 7 days
- 30 days
- 90 days
- 180 days
- 365 days
What gets purged
When a workbook passes its retention window, Vern deletes:- Workbook sheet data (cell values)
- Uploaded source files
- Import run history, the agent conversation, and any saved migration state
- Export files generated from that workbook
- Integration logs — including the datasets and embeddings derived from them
- Cached import questions and answers — free text reused across runs
- Export jobs and their files — 24 hours
- Document extractions and their results — 24 hours
What “last activity” means
The clock resets every time a user edits a sheet, runs an import, or makes other changes within the workbook. A workbook in active onboarding never expires; an abandoned one will.Closing an account
When you offboard a customer or close an account, Vern removes everything belonging to that tenant — workbooks and their files, integration logs, cached questions, stored credentials, and cached values — not just the data a retention window would have caught. Stored source credentials are purged from the secret store and any cached copies cleared at the same time, so a deleted tenant leaves no usable credential behind.Offboarding is deliberately not a self-serve button. It’s irreversible bulk
deletion, so it runs as a confirmed operation with a dry-run first — ask us and
we’ll walk it through with you.
Access and audit
Two things worth knowing when someone asks how customer data is protected day to day:- Exporting is Admin-only. Downloading a sheet or workbook is restricted to Admins, because it materialises a full dataset into a file that leaves Vern. See Team.
- Administrative actions and data access are logged. Vern keeps an append-only record of privileged operations, so “who exported this, and when?” has an answer.