← BellChord

Data Retention Policy

Version 2026-09-07 · Effective 2026-09-07

How long we keep each kind of information, and — the part most policies skip — what deliberately survives deletion and why.

The principle

We keep information for as long as it is doing a job, and then we stop. Three things extend that: a legal obligation to keep records, a security control that is worthless if it can be erased by the person it describes, and a copy that has already left our systems.

This document forms part of our Privacy Policy.

How long we keep things

InformationRetention
Your account (email, name, security settings)Until you or an administrator delete it.
Membership records (role, voice part, section)For the life of the organization's account. Removing a member marks the membership removed rather than erasing it, so historical attendance stays coherent.
Sheet music, audio, and other uploaded filesUntil deleted by an administrator, or until the organization's account is closed.
Practice recordings you uploadUntil you or an administrator delete them.
Attendance, RSVPs, poll responses, learning progressFor the life of the organization's account.
Download records (who downloaded which file, when)Retained as part of the audit log — see below. These are the record of licence usage.
Audit logAppend-only, retained for the life of the organization's account. Not deleted when the thing it describes is deleted.
Generated PDF packetsAutomatically expired and removed from storage on a scheduled sweep after a short window.
Payment and financial recordsAs long as tax and accounting obligations require, typically at least seven years. Held by both us and Stripe.
Email delivery records (sent, opened, bounced)For the life of the organization's account, so administrators can tell whether a broadcast reached people.
Help assistant questionsStored without a user identifier and linked only to the organization. They cannot be traced back to you by us.
BackupsRolling backups age out on their own cycle. Deleted data can persist in a backup until that cycle completes.

What survives deletion, and why

Three things outlive a deletion. We would rather you learn that here than be surprised by it later.
  • The audit log. It is append-only by design. Deleting a song does not delete the record that somebody downloaded it, because a tamper-evident log that can be cleared by deleting the underlying record provides no assurance at all. Audit entries name the person who acted.
  • Watermarks in files already downloaded. Every downloaded PDF and audio file carries the downloader’s name and identifiers inside it. Those copies are not in our systems and we cannot reach them. Deleting your account does not and cannot alter a file somebody has already saved.
  • Financial records. Invoices, payments and refunds are retained for the period tax and accounting rules require, even after an account closes. Stripe retains its own copies under its own policy.

Closing an organization's account

When an organization closes its BellChord account, we delete its choruses, members, songs, files, events, and related records, and we remove its stored files from object storage. Active subscriptions for member dues are wound down at the end of the period already paid for rather than cut off mid-cycle.

Financial records are retained as described above. Backups age out on their normal cycle.

Deleting your own account

If you belong to a chorus, ask one of its administrators to remove you — that ends your access and your membership. To have your user record itself deleted, email privacy@bellchord.com. We will confirm within 30 days and tell you plainly if anything is being retained and on what basis.

Changes

Each version carries a version date. Material changes are published as a new version.

Other documents

These documents are published in English. BellChord’s interface is available in several languages; where a translation of this document is offered, the English text is the version that governs.