# Data retention & storage

> How long Refabric keeps each kind of data you send and receive, and how you remove it.

Refabric keeps your files and records until you delete them; only the logs — the request log and
the webhook delivery log — expire on their own. This page lists each kind of data, how long it is
kept, and what you can do about it.

Retention and deletion are separate questions. Retention is how long we keep something if you do
nothing; deletion is what you can remove yourself, and what removing it changes
([Retention & deletion](https://docs.refabric.com/records-and-libraries/retention-and-deletion)).

## How it works

- A file or record has no expiry. Its `url` is public and unsigned, and does not expire
  ([Files and media](https://docs.refabric.com/task-apis/files-and-media#download-urls)).
- Log rows are removed after their retention period.
- Deleting is permanent.

## Outputs

The files your jobs produce (`art:…`) are kept until you delete them. Delete one with
`DELETE /v1/files/{ref}` — after it, the file answers `404`, and the job that made it keeps its record
([Retention and deletion](https://docs.refabric.com/task-apis/files-and-media#retention-and-deletion)).

## Uploads

The files you upload (`file:…`) are kept; `DELETE /v1/files/file:…` answers `422 file_not_deletable`.

## Records and library items

Records (`moodboard:…`, `fabric:…`, `brand_kit:…`, `range_plan:…`, a shoot's `photoshoot:…`) and
library items you made (`pose:…`, `background:…`) are kept ([Records & libraries](https://docs.refabric.com/records-and-libraries/overview)).

## Jobs

A job — its status, its error, its event log and the list of its files — is kept, with no
retention period. A job whose files you deleted still answers its result, with those files gone.

## Request log

Every call your API keys make is in the request log (`GET /v1/account/requests`, **Panel › Developers ›
Request log**) for 30 days, then removed. Calls made in the
Refabric app are not logged.

Bodies are returned only when you ask with `expand=payloads`.

## Webhook deliveries

A finished delivery, with its attempts, is in the delivery log (**Panel › Developers › Webhooks**)
for 30 days, then removed. If every attempt failed, read the
result from the job instead ([Webhooks](https://docs.refabric.com/task-apis/calling-tasks/webhooks#delivery-and-retries)).

## Idempotency keys

An `Idempotency-Key` is remembered as long as the job it started
([Idempotency](https://docs.refabric.com/api-reference/platform/idempotency#rules)).

:::warning
Deleting is permanent. Treat every `url` as public from the moment you receive it.
:::

## Summary

| Data | Default retention | Control |
|---|---|---|
| Outputs (`art:…`) | until you delete them | `DELETE /v1/files/{ref}` · **Panel › Developers › Files & records** |
| Uploads (`file:…`) | kept | — |
| Records and library items | kept | — |
| Jobs | kept | — |
| Request log | 30 days | bodies only with `expand=payloads` |
| Webhook delivery log | 30 days | — |
| Idempotency keys | as long as their job | — |

## Related

::::cards
:::card{title="Retention & deletion" href="/records-and-libraries/retention-and-deletion"}
What deleting each kind of data changes.
:::
:::card{title="Files and media" href="/task-apis/files-and-media"}
Uploads, handles and download URLs.
:::
:::card{title="Security" href="/api-reference/platform/security"}
Keys, public URLs and webhook signatures.
:::
::::
