ALYT
Home Legal

Data Retention & Deletion Notice

Version 1.0  |  Effective: September 6, 2026

This notice exists to answer one question in full detail, category by category: how long does ALYT keep each type of data, and how is it actually removed? Our Privacy Policy summarizes retention; this page is the complete, itemized version, including the categories where we do not yet have a fixed retention period — we would rather show you the real, unfinished state of this work than a tidy table that overstates how settled it is.

1. Retention by Category

CategoryRetention periodHow it is deleted
Account (email, password hash, name, preferences)While your account is open; removed within 90 days of account deletionHard delete on account deletion, cascading to dependent records
Voice turn metadata90 days, then automatically deletedAutomatic after 90 days; and self-service sooner, per-turn or bulk, from Voice History — a hard delete, not a soft/hidden flag
Voice transcripts (only if enabled)90 days, then automatically deletedSame as metadata above — automatic after 90 days, self-service sooner
Device telemetry90 days, then automatically deletedAutomatic rolling window; removed sooner on account deletion
Command history & reachability history30 days, then automatically deletedAutomatic rolling window; removed sooner on account deletion
Current device stateThe latest value only — overwritten, not kept as a historyRemoved on account deletion
Notifications90 days, then automatically deletedAutomatic rolling window; removed sooner on account deletion
Routine (automation) execution historyAutomatically capped at the most recent 50 runs per routineAutomatic — the oldest run is pruned as each new one is recorded
Push notification tokensUntil the provider (Apple/Google) reports the install no longer exists, or you sign out / uninstallAutomatic on provider signal, or on sign-out
Audit logs (security/account actions)IndefiniteNot user-deletable — see Section 3 for why
OAuth authorization codes (e.g., during Alexa linking)10 minutes, single-useAutomatic expiry
OAuth refresh tokens (e.g., Alexa's ongoing access)Up to 1 year, rotated on each useDeleted on unlink/revocation, or automatic expiry if unused
Encrypted backup archives30 days, then rotated outAutomatic rotation; not individually deletable mid-cycle

2. Operational Data Retention

Operational data now has fixed automatic deletion. Device telemetry and notifications are deleted 90 days after they are recorded; command history and reachability history are deleted after 30 days; routine execution history is capped at the most recent 50 runs per routine. These are automatic rolling windows — you do not have to do anything — and deleting your account removes everything tied to it at once, sooner.

These windows follow data-minimization principles under GDPR and similar laws: personal data is not kept longer than it is useful for the product to serve you. A person's account deletion still removes everything at once; these ceilings sweep the rest on a schedule so nothing accumulates indefinitely.

3. Why Audit Logs Are Not User-Deletable

Audit logs record security- and account-relevant actions — sign-ins, configuration changes, access grants and revocations — together with who performed them and when. They exist specifically to answer "what happened, and who did it" if something goes wrong, including, in the limiting case, after an account itself has been deleted. Because their entire value depends on being a trustworthy record that cannot be selectively edited by the person whose actions they describe, we do not offer self-service deletion of audit log entries, even as part of full account deletion — a minimal, de-identified trace remains (see our Delete Your Account page for exactly what that trace does and does not contain). This is a standard practice across security-conscious platforms, not an ALYT-specific attempt to retain more than necessary; the entries do not contain the content of what you said to the assistant or the content of your messages.

4. Backups

Like any responsible operator, we keep regular backups of our production systems so that a hardware failure, a bad deployment, or a serious incident does not mean permanent data loss for every customer. This means that for a limited window after you delete data (a voice turn, an integration, or your entire account), a copy of it may still exist in an already-taken backup snapshot until that snapshot itself is rotated out of the backup cycle.

What this does and does not mean in practice: data in a backup is not accessible to anyone as "your account" during that window — it exists only as an inert part of a whole-system snapshot used solely for disaster recovery, is not queried or exposed through any product feature, and is overwritten as part of our normal backup rotation. Backup snapshots are retained for 30 days and then rotated out automatically. So for at most 30 days after you delete data, an inert copy may persist inside a whole-system disaster-recovery snapshot before that snapshot is itself rotated out.

5. Third-Party Data

Where an integration sends your data to a third party (Ring, SwitchBot, Cync, aromi.ai, Amazon, and others, as described in our Privacy Policy, Section 10), that third party's own retention policy governs data once it reaches them — ALYT's deletion of an integration removes our own copy of your credentials and cached data, but does not reach into that third party's systems. Check their privacy policy, or contact them directly, for their retention practices.

6. How to Request Deletion of a Specific Category

For anything not yet covered by a self-service control in the app (see the table above for what is), email privacy@alyt.co describing exactly what you want deleted — for example, "delete all command history older than six months" or "delete all notifications for the Front Door camera." We will confirm what we can do and process verified requests within 30 days.

7. Retention and Account Deletion

Deleting your entire account is the most complete way to ensure all of the categories above (except the narrow, minimal audit trace and any residual backup window described above) are removed together. See our Delete Your Account page for the complete, itemized breakdown of what account deletion removes.

Contact

Fizzify Inc.
30 N Gould St STE N
Sheridan, WY 82801
United States

privacy@alyt.co


Last updated: September 6, 2026