Legal
Data retention
What we keep, for how long, and how to have it deleted sooner. The default is simple: while your label is a client, we keep your sources and deliverables so re-edits stay cheap and every version stays downloadable. A label's signed agreement can set different periods.
1. Schedule
| Data | Kept for | Then |
|---|---|---|
| Source media you upload or link (video, audio, artwork, lyrics) | Life of the workspace | Deleted from storage on request at any time, or within 30 days after the workspace closes; links removed from the job |
| Analysis data derived from your media (shot lists, beat grids, subject tracks, captions) | Same as the source it came from | Deleted with the source |
| Deliverables (final renders, masters, previews, poster frames) | Life of the workspace | Deleted from storage on request or within 30 days after the workspace closes; the job record notes that the file was removed |
| Job records: brief, original request snapshot, spec changes, status history, milestones | Life of the workspace | Deleted or anonymised 30 days after the workspace closes, except financial parts below |
| Chat, review notes, reactions (encrypted at rest) | Life of the workspace | Deleted with the workspace |
| Credit ledger, quotes, statements, editor accruals | 7 years from the transaction | Deleted |
| Account (name, email, role, avatar) | Until deleted by you or your label administrator | Removed within 30 days; name replaced by "former member" on records that must survive |
| Sessions and device tokens | Sessions expire automatically; device tokens until revoked | Hashes deleted |
| YouTube channel connection (id, title, encrypted refresh token) | Until the channel is disconnected or the token is revoked | Token deleted and revoked with Google |
| Notifications and email records | Life of the workspace | Deleted with the workspace; our email provider (Resend) keeps delivery logs under its own policy |
| Request/server logs | 30 days or less | Rotated automatically by the hosting platform |
| Audit log (who did what, when, from where) | Life of the workspace | Deleted with the workspace |
| Database snapshots (taken before each software release) | 30 days | Deleted; data removed from the live database is gone from snapshots once they age out |
| Data sent to AI providers (Anthropic, OpenAI, Google, AtlasCloud) for import analysis or editor tooling | Not retained by OAK beyond the resulting field, alignment or render; provider retention per its API terms | โ |
| Working copies on OAK editors' machines | Duration of the job | Editors delete local media on job completion and on offboarding; the portal revokes their access |
2. Earlier deletion on request
A label administrator can ask us to delete any source media or deliverable earlier, or to delete a whole project or workspace. Email tim@oakmediaworks.com from the administrator's account address. We confirm deletion by email within 10 business days, including from the editors' working copies. Financial records and the audit log are kept for the periods above even after a deletion request, because we are required to.
3. Keeping things longer
If you would rather we keep deliverables as an archive, or keep sources so re-edits stay cheap, tell us in writing and we will set a longer period for your label. Storage beyond the defaults may be charged at cost.
4. Export
You can download any deliverable from the portal while it is retained. On request we provide an export of your job records, chat and credit ledger as JSON/CSV within 30 days, and at termination as part of the wind-down.
5. How deletion works
- Media lives in object storage under keys tied to the job; deletion removes the object and every signed link stops working within an hour.
- Records are soft-deleted first (hidden from the portal, recoverable in case of mistakes) and then purged from storage.
- Deleted data leaves the database snapshots as they age out (30 days).
- Deletion is carried out by OAK and confirmed to the requesting administrator by email; automated purging on a schedule is not in place yet, which is why the default is to keep, not to expire.
6. Questions
tim@oakmediaworks.com. We will update this page and its effective date whenever the schedule changes, and email workspace owners about any shortening of a period.
