Give deletion a date
A deletion promise needs a clock, a scope, and an owner. If any of those are missing, the promise is incomplete.
Choose the date before collecting
Retention should follow the task. A one-week team check-in rarely needs indefinite storage. Set the closing and deletion dates before the first invitation so respondents can evaluate the boundary.
“As long as necessary” is not a useful respondent-facing answer unless the purpose and necessity test are also clear.
Delete the related copies
Deleting the live survey may not delete CSV exports, emailed summaries, screenshots, backups, support attachments, or copied analysis documents. The survey owner needs a plan for those downstream copies.
Automatic application expiry reduces forgotten data but does not reach exports already downloaded by the owner. State that distinction rather than presenting platform deletion as universal erasure.
- When does collection stop?
- When do live responses disappear?
- What is the backup deletion window?
- Who controls exported copies?
- Can deletion be verified?
- What legal holds could override it?
Make expiry visible
Show the remaining days to respondents and owners. A visible clock prevents the retention promise from becoming invisible fine print.
CandorKit sets a seven-day database expiry, rejects new responses after expiry, and runs a scheduled cleanup. Results exported before that moment become the owner’s responsibility and are outside the automatic deletion boundary.
Put the boundary in the invitation
Tell respondents what is stored, what is not, who can read it, and when it disappears.
Create a bounded survey