Explain in plain EnglishClaudeChatGPTMarkdown

Data Retention

Last updated: October 5, 2026

The short version

  • Your message history stays while your account is open, because the inbox and logs are built on it.
  • Opt-outs are kept long enough to keep honoring them.
  • When you leave, we delete your data within 90 days.

How long SimpleSMS keeps each kind of data, and why. "Deleted" means removed from our production systems; backups are overwritten on their normal cycle after that.

DataKept forWhy
Message content and mediaLife of the account, or until you delete it or ask us toMessage history, the shared inbox, and support
Message metadata and delivery receiptsLife of the accountDelivery logs, billing disputes, abuse investigations
Blocked messages (up to 320 characters)Life of the accountReview of content-screen decisions
Opt-out and opt-in records, including opt-in proof you record (through the API or a contact import) and each number's subscription preference per topicWhile the account is open, and at least 4 years after the last message to that number. Deleting a contact does not delete these: they belong to the phone numberTo keep honoring opt-outs and topic preferences, and to answer TCPA claims
Contacts (phone number, name, email, company, state, tags, custom fields, notes, source), segments, subscription topics, and import records (file name, who ran it, row counts)Life of the account, or until you delete themThe address book, broadcast audiences, and merge fields
Which broadcasts a number was included in, and each broadcast's recipient list and resultsLife of the accountContact history and broadcast reporting
Verification attemptsCodes expire after 10 minutes and are only ever stored hashed; outcomes kept for the life of the accountBilling and fraud prevention
Lookup resultsCached for 24 hours. A message sent while a result is cached keeps the recipient's carrier name as part of its metadataCost and speed; delivery logs
Customer records (customers API) and per-customer usage countsLife of the account, or until you delete the customer (usage counts and attribution on past messages stay with the message history)Attributing traffic and usage to the businesses you send for
Automation events you send us (event name, phone number, your user id, properties)30 daysStarting and advancing your automations; showing recent events in the console
Automation runs (recipient, the event properties that started the run, steps taken, why it ended)Until the run ends, then 30 days. A run ends after at most 90 daysRunning the flow; showing you what each run did
Automation flows (steps and message text) and the links between your user ids and phone numbersLife of the account, or until you delete the flowRunning your automations
API request logsUp to 30 daysDebugging and security
Account audit log (who changed keys, team, webhooks, spend limits, numbers, consent, topic preferences, contact imports, segments, topics, settings, automations, and from which IP)Life of the accountSecurity and accountability
Delivery statistics (counts by day, carrier, and sending number)Life of the account; hourly detail 9 daysDeliverability reporting and degradation alerts
Account usage metrics (message counts per hour and day, first-send times)Daily counts 120 days; hourly counts until reported (about an hour); first-send times for the life of the accountBusiness reporting (Privacy §8)
Webhook delivery logs (status code, response time, and the first 2 KB of your endpoint's response)30 daysDebugging your webhook integration
Undelivered webhook events (a reference to the event, not a second copy of it)30 days, or until you replay or dismiss themRecovering events your endpoint missed
Brand and campaign registration details (including the example messages and description you write, and draft examples we suggest until you replace or confirm them), website check results, and the copy of what was filed for carrier review each time you submitLife of the registration, plus 1 yearCarrier and registry requirements; showing what the carriers reviewed
Suggestions read from your website when you ask us to fill in a registration (business details and page addresses; never the pages themselves)About 10 minutes; cleared within the hourSo that asking again does not read your site a second time
Each phone number's registration status and its history (status changes and the registration it is linked to), and the review items our team works from (registration submissions, live-access requests, requests for a toll-free number or short code, reviews that are running long)Life of the accountShowing you where a number stands; reviewing and following up on your registration
Account dataLife of the account, then 90 daysRunning the account
Product update subscriptions (email address, sign-up source, confirmation and unsubscribe dates)Until you unsubscribe or ask us to delete it; after you unsubscribe we keep the address only as a do-not-email record, unless you ask us to delete itSending the updates you asked for, and honoring unsubscribes
Billing and invoice records7 yearsTax and accounting law
Fraud and abuse signalsAs long as needed to protect the networkPreventing repeat abuse

When an account closes

Within 90 days after an account closes, we delete its message content, metadata, contacts, and account data. We keep only what the table above says outlives the account (opt-out records, billing records, fraud signals), and anything the law or a valid legal hold requires.

Deleting sooner

Customers can ask us to delete specific messages, contacts, or all of their data at any time by emailing support@joinsimplesms.com. Message recipients can use the process in Privacy §9.