Trust Centre

Data retention

How long each kind of data is kept and what removes it, taken from what the software does today.

I. AI LTD trading as InvestorUniverse · Read from the running system on 5 October 2026, 22:32 UK time

A period is stated below only where the software enforces it. Where nothing removes a kind of data automatically, the row says so. The privacy notice is the legal statement, and this page shows how it is carried out.

Removed on a schedule

DataHow longWhat removes it
Sign-in session30 days from sign-inIt stops working when it expires and the daily job deletes it. Signing out deletes it at once, and so does ending it from your account page.
Sign-in link15 minutes (24 hours for the link that confirms an email address from a results page). It works onceThe daily job deletes it a day after it expires.
A staff session's second-step pass12 hoursAfter that the staff area asks for a new code.
Rate-limit counters, keyed by network address or account2 daysThe daily job deletes them.
Automatic block on a network address24 hours in forceThe block lapses by itself. The record that it happened is kept.
Status readings100 daysThe daily job deletes older readings.
Support messages that are resolved or marked as spam365 days after the last change to the messageThe daily job deletes them.

Kept until someone acts

DataHow longWhat removes it
Your account, company profile, raise, lists and pipelineWhile the account existsThere is no automatic deletion of an inactive account. A person deletes an account on request.
A pitch deck you uploadUntil you delete itDeleting it from your workspace removes the record and the stored file together.
Order recordsSix years, as the privacy notice saysNothing in the software deletes an order when that period ends. Removal is done by a person.
An investor's professional recordWhile the record is liveA removal or objection hides it at once (see below). Records are re-checked on the schedule in the Trust Centre.
A suppression list entryUntil the person asks us to lift itNever removed automatically, because removing it would let a later import add the person again. See the suppression list policy.
Audit trail and the change history of investor recordsNo automatic removalKept as the security record. Includes the network address and browser behind each action.
Error logNo automatic removalEntries are marked resolved by a person and are not deleted by the software.
Language model call logNo automatic removalHolds the prompt name and version, the model, token counts, cost and whether the answer was valid. It does not hold the text sent or the reply. See how we use AI.

Cookies

CookieLifetimeWhat it is for
iu_session30 daysKeeps you signed in. Always on.
iu_consent180 daysRemembers your cookie choice. Always on.
iu_partner30 daysRemembers a partner link you used. Set only when you use one.
iu_buy7 daysLinks your browser to an order. Set at checkout.
iu_anon180 daysA random id for page tests. Only if you accept optional cookies.
iu_ref30 daysCredits the person who referred you. Only if you accept optional cookies.

When you ask us to remove something

  • A removal or objection sent through the data request form hides the details from results, profiles and exports the moment it is submitted. A person then reviews it, and our own target for finishing is 24 hours.
  • The law gives us up to one month to respond to any data request. That limit is separate from our target.
  • Deleting an account, or a record that the tables above say has no automatic removal, is done by a person. Email privacy@investoruniverse.uk.

Trust Centre · Privacy notice · Suppression list policy · Security overview