OpenE2EE Relay Retention Statement
What Relay keeps, for how long, and what deletion can and cannot recall.
Encrypted delivery content
- A project's Development environment uses 24-hour retention by default and permits no more than seven days.
- Production projects can select a shorter period, up to a 30-day maximum.
- Mailbox expiry removes unacknowledged ciphertext at the configured boundary.
- A mailbox can hold no more than 3,000 accepted messages.
Attachments
- An upload authorization is valid for no more than 15 minutes.
- An incomplete upload expires after 24 hours.
- A completed attachment has a 30-day maximum retention.
- Relay deletes bytes directly on the owning expiry or deletion transition. Storage lifecycle rules are a cleanup backstop and may run later.
Inactive development projects
A project's Development environment can be suspended after 30 inactive days. The console shows the state and the available recovery or deletion action.
Usage, billing, security, and recovery records
Exact current usage remains in concept-owned service state. Closed-period aggregate usage, billing reconciliation, and narrow security or deletion fences can remain after encrypted payload deletion. These records use opaque identifiers and do not contain message content, account social graphs, provider subjects, device proofs, or protocol private material. OpenE2EE keeps each category only for its documented retry, reconciliation, security, accounting, legal, and restore period.
Deletion boundary
Account deletion removes that account’s inbound mailbox and account-owned objects. It does not recall a sent envelope from another recipient’s mailbox. Leaving a group revokes future access but does not erase shared ciphertext only because one member left. Project deletion fences new work, drains accepted work, purges project-owned state, and then verifies the deletion generation before completion.