Skip to main content

Deletion and retention

Claude
Authored by Claude · Last updated AI generated documentation written by reading the source code
cloud services

Destroying backed-up data is deliberately slow and deliberately hard. There is no single click, anywhere in Cardinal, that erases a backup on the spot.

Every deletion control lives in your account portal, deliberately: your stored data is managed by your Cardinal Account, not by any one Media Server. If you retire a server — or leave Cardinal entirely — you never need to reinstall anything just to wind your backups down.

Snapshot retention

Each backup keeps its recent snapshots automatically: by default the last 8, and at least 90 days' worth, whichever is more generous.

Older snapshots are pruned, and file data that no surviving snapshot still refers to is deleted with them. A file you deleted locally therefore leaves your backups eventually, once every snapshot that recorded it has aged out.

Keeping many snapshots is cheap, because snapshots share file data. A snapshot costs its own list plus only the files unique to it.

Deleting a backup

Two controls wind a backup down, and both put the stored data on the same 30-day clock.

ControlWhereWhat happens
ResetThe Backup Status drawer on the Secure Backups cardRemoves the backup's configuration from your Media Server immediately — schedule, section choices, and the encryption key if you set one — and schedules the stored data for deletion 30 days out. Until that date the data is untouched. A backup that never completed a run is released immediately instead; there is nothing stored to protect.
Schedule a deletionThe backup's menu in your account portalSame power, same cooldown: the data is removed 30 days out, and the backup keeps running until then unless you also reset it.
Reset deletes the encryption key from your server

For an end-to-end encrypted backup, Reset removes the only copy of the key your server holds. During the cooldown the stored data still exists, but the only way to ever read it again is your recovery kit. Resetting an encrypted backup with no kit means cancelling the deletion preserves data that nothing can decrypt.

The 30-day cooldown

While a deletion is pending, the portal shows the backup with its deletion date, and you can cancel at any point during the window. Cancelling keeps the stored data. It does not restore a configuration that Reset removed — setting the backup up again is a fresh creation.

Any backup run during the countdown cancels the scheduled deletion automatically. Your data stays as long as something is still backing up to it, and only a server that has genuinely gone quiet winds down.

Deleting immediately

The portal can also delete a backup on the spot, from any state. It asks you to prove it is really you, right then: a one-time code sent to your email plus your account password, entered together. A logged-in browser — or anyone who has taken it over — is not enough.

If your subscription lapses

Your data is held for 30 days, then permanently deleted. Resubscribing within that window leaves everything intact, with no re-upload and no loss of snapshot history.

  • Secure Backups — setup, scheduling and what gets backed up
  • Restoring — recovering data before it ages out
  • Security — why no client is ever given a delete verb

Was this article helpful?