Data retention
How long each kind of data is kept and what removes it, taken from what the software does today.
I. AI LTD trading as InvestorUniverse · Read from the running system on 5 October 2026, 22:32 UK time
A period is stated below only where the software enforces it. Where nothing removes a kind of data automatically, the row says so. The privacy notice is the legal statement, and this page shows how it is carried out.
Removed on a schedule
| Data | How long | What removes it |
|---|---|---|
| Sign-in session | 30 days from sign-in | It stops working when it expires and the daily job deletes it. Signing out deletes it at once, and so does ending it from your account page. |
| Sign-in link | 15 minutes (24 hours for the link that confirms an email address from a results page). It works once | The daily job deletes it a day after it expires. |
| A staff session's second-step pass | 12 hours | After that the staff area asks for a new code. |
| Rate-limit counters, keyed by network address or account | 2 days | The daily job deletes them. |
| Automatic block on a network address | 24 hours in force | The block lapses by itself. The record that it happened is kept. |
| Status readings | 100 days | The daily job deletes older readings. |
| Support messages that are resolved or marked as spam | 365 days after the last change to the message | The daily job deletes them. |
Kept until someone acts
| Data | How long | What removes it |
|---|---|---|
| Your account, company profile, raise, lists and pipeline | While the account exists | There is no automatic deletion of an inactive account. A person deletes an account on request. |
| A pitch deck you upload | Until you delete it | Deleting it from your workspace removes the record and the stored file together. |
| Order records | Six years, as the privacy notice says | Nothing in the software deletes an order when that period ends. Removal is done by a person. |
| An investor's professional record | While the record is live | A removal or objection hides it at once (see below). Records are re-checked on the schedule in the Trust Centre. |
| A suppression list entry | Until the person asks us to lift it | Never removed automatically, because removing it would let a later import add the person again. See the suppression list policy. |
| Audit trail and the change history of investor records | No automatic removal | Kept as the security record. Includes the network address and browser behind each action. |
| Error log | No automatic removal | Entries are marked resolved by a person and are not deleted by the software. |
| Language model call log | No automatic removal | Holds the prompt name and version, the model, token counts, cost and whether the answer was valid. It does not hold the text sent or the reply. See how we use AI. |
Cookies
| Cookie | Lifetime | What it is for |
|---|---|---|
| iu_session | 30 days | Keeps you signed in. Always on. |
| iu_consent | 180 days | Remembers your cookie choice. Always on. |
| iu_partner | 30 days | Remembers a partner link you used. Set only when you use one. |
| iu_buy | 7 days | Links your browser to an order. Set at checkout. |
| iu_anon | 180 days | A random id for page tests. Only if you accept optional cookies. |
| iu_ref | 30 days | Credits the person who referred you. Only if you accept optional cookies. |
When you ask us to remove something
- A removal or objection sent through the data request form hides the details from results, profiles and exports the moment it is submitted. A person then reviews it, and our own target for finishing is 24 hours.
- The law gives us up to one month to respond to any data request. That limit is separate from our target.
- Deleting an account, or a record that the tables above say has no automatic removal, is done by a person. Email privacy@investoruniverse.uk.
Trust Centre · Privacy notice · Suppression list policy · Security overview