Data deletion
Users can delete scan metadata from each scan page unless it is linked to a payment or cleanup audit record. Disconnecting an account removes stored tokens, marks the connected account inactive, and requests provider-side token revocation for Google and Dropbox. Provider and browser login sessions are separate and remain signed in.
Completed scan metadata expires automatically after the configured retention window, defaulting to 24 hours.