Deletion and retention
Destroying backed-up data is deliberately slow and deliberately hard. There is no single click, anywhere in Cardinal, that erases a backup on the spot.
Every deletion control lives in your account portal, deliberately: your stored data is managed by your Cardinal Account, not by any one Media Server. If you retire a server — or leave Cardinal entirely — you never need to reinstall anything just to wind your backups down.
Snapshot retention
Each backup keeps its recent snapshots automatically: by default the last 8, and at least 90 days' worth, whichever is more generous.
Older snapshots are pruned, and file data that no surviving snapshot still refers to is deleted with them. A file you deleted locally therefore leaves your backups eventually, once every snapshot that recorded it has aged out.
Keeping many snapshots is cheap, because snapshots share file data. A snapshot costs its own list plus only the files unique to it.
Deleting a backup
Two controls wind a backup down, and both put the stored data on the same 30-day clock.
| Control | Where | What happens |
|---|---|---|
| Reset | The Backup Status drawer on the Secure Backups card | Removes the backup's configuration from your Media Server immediately — schedule, section choices, and the encryption key if you set one — and schedules the stored data for deletion 30 days out. Until that date the data is untouched. A backup that never completed a run is released immediately instead; there is nothing stored to protect. |
| Schedule a deletion | The backup's menu in your account portal | Same power, same cooldown: the data is removed 30 days out, and the backup keeps running until then unless you also reset it. |
For an end-to-end encrypted backup, Reset removes the only copy of the key your server holds. During the cooldown the stored data still exists, but the only way to ever read it again is your recovery kit. Resetting an encrypted backup with no kit means cancelling the deletion preserves data that nothing can decrypt.
The 30-day cooldown
While a deletion is pending, the portal shows the backup with its deletion date, and you can cancel at any point during the window. Cancelling keeps the stored data. It does not restore a configuration that Reset removed — setting the backup up again is a fresh creation.
Any backup run during the countdown cancels the scheduled deletion automatically. Your data stays as long as something is still backing up to it, and only a server that has genuinely gone quiet winds down.
Deleting immediately
The portal can also delete a backup on the spot, from any state. It asks you to prove it is really you, right then: a one-time code sent to your email plus your account password, entered together. A logged-in browser — or anyone who has taken it over — is not enough.
If your subscription lapses
Your data is held for 30 days, then permanently deleted. Resubscribing within that window leaves everything intact, with no re-upload and no loss of snapshot history.
Related pages
- Secure Backups — setup, scheduling and what gets backed up
- Restoring — recovering data before it ages out
- Security — why no client is ever given a delete verb
Was this article helpful?