Data Retention Policy
Last updated: September 11, 2026
Active accounts
While your account is active, Vytal Path retains profile information and health information needed to provide the features you use. User-entered and imported information generally remains until you delete it, use a dedicated deletion control, withdraw from a feature where deletion is part of that process, or delete your account, subject to legal and technical exceptions described below.
Connected-service data
Information imported from a supported connected service is retained as part of your Vytal Path account. Disconnecting stops future synchronization through that connection but does not necessarily remove information already imported. Where Vytal Path provides a dedicated connected-data deletion control, use that control to remove the applicable imported data set.
Account deletion
When you delete your account using the available Privacy & Data controls, Vytal Path deletes your profile, health information, connected-integration data, uploaded documents, and other account data from active production systems, except information that must be retained for a specific legal obligation or that remains temporarily in disaster-recovery backups.
Account deletion is intended to be irreversible. Vytal Path does not use disaster-recovery backups as an ordinary method to restore a user account after the user has requested deletion.
Backups
Vytal Path maintains automated backups for disaster recovery. The current operational target is a limited rolling retention period, and the production configuration should be kept consistent with the retention period publicly stated by Vytal Path. Information deleted from active systems may remain in an existing system-level backup until that backup expires through the normal retention cycle. Backups are restricted to recovery purposes.
Security and operational records
Security, audit, notification-delivery, and operational records may be retained for periods appropriate to security, fraud prevention, troubleshooting, legal obligations, and system integrity. User-facing recent-security-history views may display only a limited number of recent events even when protected backend audit records are retained separately for legitimate security purposes.
Payment records
Payment processors may retain transaction and related records independently under their legal, regulatory, fraud-prevention, and record-retention obligations. Those records are governed by the payment processor's own policies.
