BeforeMay docs
Security, data & AI

Retention, deletion and exports

What remains after disconnecting, deleting a login or removing a record.

Source reviewed Security and privacy documentation

Retention depends on the kind of record and the practice's instructions. The Privacy Policy contains the maintained retention schedule. Do not interpret a deletion in one system as deletion in every other system.

Common actions

ActionWhat it changesWhat it does not automatically erase
Disconnect an Outlook mailboxRemoves the connection and mailbox indexMail or attachments already filed as client/case documents; Outlook itself
Remove a firm memberRemoves that person's practice membershipPractice records and practice API keys
Client deletes their mobile-app accountDeletes the sign-in and firm connectionsDocuments and messages already held by the accounting firm
Replace or void a signing/check linkInvalidates access or cancels the open requestEvidence and completed actions already recorded
Delete data held by BeforeMayApplies the relevant record-deletion flowA provider's copy governed by its retention terms

Record schedule

The policy describes uploaded documents and extracted fields being retained while the client/job is active, then under the firm's retention requirements. Identity-check results remain while the firm keeps the client record. Didit holds its own images under the period configured with that provider; BeforeMay does not hold those biometric images.

Some operational records have automated cleanup: rate-limit events after 7 days, settled invitation metadata under the defined cleanup period and audit events after 18 months. Other deletion depends on the record flow or a firm request; there is no blanket daily purge of all client financial records.

Provider copies

Files sent for AI processing can be retained by the provider under its own agreement. The policy expressly distinguishes provider retention from deletion in BeforeMay and describes immediate post-job provider file deletion as work in progress. This guide does not present that plan as implemented.

Export before closing

Retain the records your practice needs: delivered/current workbooks, source files, signed PDFs and certificates, and applicable CDD record exports. Check the files open and relate to the intended client and period. An individual product export is not a promise of a one-click full-practice migration archive.

Clients can follow account deletion. Firm users should ask the Owner to remove their membership; contact support@beforemay.com.au for practice closure. Privacy requests go to privacy@beforemay.com.au.

Backups and recovery

Deletion from active records and expiry from retained backups are separate questions. No recovery-time, recovery-point or backup-erasure guarantee is established by this guide. If those are adoption requirements, request the current backup policy and a dated restore-test result before relying on them.

On this page