Toothvity · India
Data Retention
Last updated: August 2026. This page describes how long data is kept in Toothvity today and how deletion requests are handled.
Overview
While your clinic has an active Toothvity account (including an active or trialing subscription, unless otherwise suspended), we retain the data you enter to provide the service. Cancellation restricts access; it does not automatically delete clinic data. Offboarding is a controlled workspace closure — not a guarantee of permanent erasure of every clinical database row.
Retention Schedule
Summary of retention behaviour today. Details in the sections below. Plan storage quotas are on Pricing.
| Category | While Active | After Cancel | After Offboarding | Backup Residual | Notes |
|---|---|---|---|---|---|
| Clinic profile and account | Retained to operate the workspace | Not automatically deleted; access restricted | Clinic row soft-deleted (hidden from normal use) | May remain in operational backups for a limited window | Memberships deactivated on offboarding |
| Patients and clinical records | Retained while the clinic uses the product | Not automatically deleted | Not hard-deleted from primary storage today | May remain in backups for a limited window | Soft-deleted rows stay in primary storage; no automated clinical purge |
| Clinic branding files | Private cloud storage; replace removes prior active file | May remain until operational cleanup | May remain until reconciliation or retention jobs | Replaced/deleted objects may persist briefly in backups | Subject to plan quotas (see Pricing) |
| Support attachments | Kept while the ticket exists | Follow ticket lifecycle | Storage objects purged with tickets | May persist briefly in backups after purge | Operational jobs may purge older closed-ticket attachments |
| Generated PDFs | Rendered on demand; not permanent upload objects | Not stored as permanent uploads | Not stored as permanent uploads | N/A as permanent upload objects | Built from database records when you export or print |
| Billing and subscription records | Retained for billing and accounting | Retained as needed for disputes and tax | May be kept longer than clinical workspace data | Per infrastructure backup windows | Processor identifiers; not full card numbers on Toothvity servers |
| Security and audit logs | Retained for investigation | Retained for operational investigation | Not purged as part of clinic offboarding | Per infrastructure backup windows | No fixed public purge schedule published today |
| Export files you download | Generated for download | Your responsibility to store securely | Not indefinitely re-hosted by Toothvity | N/A after you download | Export within 72 hours is required before offboarding execution |
Storage Objects (Branding and Support Attachments)
Toothvity stores clinic branding (logo, banner, signature) and support ticket attachments in private cloud storage. Generated PDFs are rendered on demand from database records and are not kept as permanent upload objects. Replacing branding removes the previous file from active storage. Support attachments follow the ticket lifecycle; when attachments or tickets are deleted, storage objects are purged and usage counters update.
Cancelled or Inactive Subscriptions
When a subscription is cancelled or lapses, product access is restricted per our billing lifecycle rules. Data is not automatically deleted on cancellation. Export records you must keep before access ends. Contact support to discuss closure and deletion.
Clinic Offboarding and Deletion Requests
Clinic owners can start offboarding from Settings → Danger Zone (/dashboard/settings/danger-zone).
- Owner submits a clinic offboarding request from Danger Zone.
- A platform admin reviews the request (approve or reject).
- Before execution, the owner must complete a clinic data export from Settings → Data Exports within the prior 72 hours.
- After approval, a platform admin executes the offboarding workflow.
You may also email support@toothvity.com if you cannot access the dashboard. We verify ownership before processing.
What Clinic Offboarding Does and Does Not Remove
Removes or disables: active team access, active billing, support tickets and attachments, and clinic workspace visibility (clinic row soft-deleted).
Does not permanently purge: patient, prescription, invoice, consent, treatment-plan, or appointment database rows; clinic branding files may remain until operational cleanup; billing, audit, and security logs needed for accounting and investigations.
Data Exports Before Deletion
Owners and admins can export from Settings → Data Exports. Toothvity does not indefinitely host export archives for re-download. After you download an export, safe storage of that file is your responsibility. Platform admins cannot execute offboarding until a successful export audit event exists within the prior 72 hours.
Automated Operational Retention (Not Clinical Records)
Platform operators can run scheduled retention jobs for operational data, not for patient charts or prescriptions. Examples today: support attachments on tickets closed more than 24 months ago; unreferenced replaced branding after a 30-day grace; closed support ticket rows after 36 months; resolved alerts, terminal failed jobs, and old audit rows (12–24 months). These jobs support hygiene and cost control. They do notreplace your clinic's legal duties to retain patient records.
Backup Retention and Manual Restore
Toothvity runs on managed cloud infrastructure (including Supabase) with operational database backups and point-in-time recovery for disaster recovery only, not as clinic self-service undo. Storage objects can be exported manually by platform operators for DR drills. There is no automated restore UI for clinics. Residual copies in backups may persist for a limited period (typically up to 90 days) after primary deletion or replacement. Backups are not a substitute for exporting records your clinic must keep.
Invoices, Billing, Security, and Audit Logs
Subscription and payment records are retained to support billing disputes, tax, and accounting, and may be kept longer than clinical workspace data after closure. Security risk events and team/billing audit log rows are retained for operational investigation. We do not publish a fixed purge schedule for these logs today.
Legal Retention Obligations
Your clinic may be required under Indian law or professional rules to retain certain patient records for defined periods. Toothvity does not replace those obligations. When in doubt, consult qualified counsel and export or archive records before requesting deletion.
Related Policies
See also these Trust & Legal pages for related commitments.