Data Retention Policy
Version 2026-09-07 · Effective 2026-09-07
How long we keep each kind of information, and — the part most policies skip — what deliberately survives deletion and why.
The principle
We keep information for as long as it is doing a job, and then we stop. Three things extend that: a legal obligation to keep records, a security control that is worthless if it can be erased by the person it describes, and a copy that has already left our systems.
This document forms part of our Privacy Policy.
How long we keep things
| Information | Retention |
|---|---|
| Your account (email, name, security settings) | Until you or an administrator delete it. |
| Membership records (role, voice part, section) | For the life of the organization's account. Removing a member marks the membership removed rather than erasing it, so historical attendance stays coherent. |
| Sheet music, audio, and other uploaded files | Until deleted by an administrator, or until the organization's account is closed. |
| Practice recordings you upload | Until you or an administrator delete them. |
| Attendance, RSVPs, poll responses, learning progress | For the life of the organization's account. |
| Download records (who downloaded which file, when) | Retained as part of the audit log — see below. These are the record of licence usage. |
| Audit log | Append-only, retained for the life of the organization's account. Not deleted when the thing it describes is deleted. |
| Generated PDF packets | Automatically expired and removed from storage on a scheduled sweep after a short window. |
| Payment and financial records | As long as tax and accounting obligations require, typically at least seven years. Held by both us and Stripe. |
| Email delivery records (sent, opened, bounced) | For the life of the organization's account, so administrators can tell whether a broadcast reached people. |
| Help assistant questions | Stored without a user identifier and linked only to the organization. They cannot be traced back to you by us. |
| Backups | Rolling backups age out on their own cycle. Deleted data can persist in a backup until that cycle completes. |
What survives deletion, and why
- The audit log. It is append-only by design. Deleting a song does not delete the record that somebody downloaded it, because a tamper-evident log that can be cleared by deleting the underlying record provides no assurance at all. Audit entries name the person who acted.
- Watermarks in files already downloaded. Every downloaded PDF and audio file carries the downloader’s name and identifiers inside it. Those copies are not in our systems and we cannot reach them. Deleting your account does not and cannot alter a file somebody has already saved.
- Financial records. Invoices, payments and refunds are retained for the period tax and accounting rules require, even after an account closes. Stripe retains its own copies under its own policy.
Closing an organization's account
When an organization closes its BellChord account, we delete its choruses, members, songs, files, events, and related records, and we remove its stored files from object storage. Active subscriptions for member dues are wound down at the end of the period already paid for rather than cut off mid-cycle.
Financial records are retained as described above. Backups age out on their normal cycle.
Deleting your own account
If you belong to a chorus, ask one of its administrators to remove you — that ends your access and your membership. To have your user record itself deleted, email privacy@bellchord.com. We will confirm within 30 days and tell you plainly if anything is being retained and on what basis.
Changes
Each version carries a version date. Material changes are published as a new version.
Other documents
These documents are published in English. BellChord’s interface is available in several languages; where a translation of this document is offered, the English text is the version that governs.