Data Retention and Erasure

Data Retention Policy

Last updated: 10 August 2026 · Version 1.0

This is a courtesy translation. In the event of any discrepancy, the Spanish version prevails.

1. Data minimisation principle

At Madrugo we design our systems around data protection by design and by default. We only store the minimum information required for the Mission Control console and the companion robots to work properly.

We do not keep bulk replicas of your mailboxes or calendars; Madrugo indexes references ephemerally for the 24-hour visual view and applies strict purge schedules.

2. Structured retention schedule

The retention periods applied to each category of data stored on the platform are set out below:

Data categoryRetention periodPurge or erasure mechanism
OAuth access tokens (Google / Apple)For as long as the account stays connectedErased immediately when the account is disconnected or after a user-requested purge.
Derived memories from Gmail & WorkspaceUp to 90 days (maximum)Scheduled automatic purge, or immediate erasure on request at /app/settings.
Sync and audit logs (iagente_sync_logs)30 to 90 daysAutomatic rotation in the PostgreSQL database for incident resolution.
APNs device tokens & Live Activities180 days (inactive: disabled after 30 days)Automatically disabled after 30 days without use and permanently erased after 180 days.

3. AES-256-GCM encryption and automatic purge cycles

All data stored at rest containing credentials, tokens or memory extracts is encrypted at field level with the AES-256-GCM authenticated encryption algorithm.

Background purge cycles:Our servers run periodic scheduled clean-up jobs that detect expired records against the retention schedule and irreversibly destroy the encrypted rows in PostgreSQL and Secret Manager.

4. Right to immediate total erasure in one click

We believe users should have sovereign control over their digital footprint. Madrugo therefore provides direct, immediate mechanisms to destroy your data in full:

One-click immediate total wipe

From the settings section inside the app (/app/settings), you can press the total erasure button. This instantly and irreversibly deletes every memory, log, OAuth token and setting associated with your account.

Revoking OAuth from Google or Apple

If you revoke access from your Google account security panel (Google Account Permissions) or unlink the app from your Apple ID, the Madrugo engine will detect that the token is no longer valid and will automatically flag and delete the session on the next sync cycle.

5. Questions about retention and privacy

If you have specific questions about how we handle retention periods, or you would like to request manual confirmation that your data has been destroyed, you can contact our data protection team at privacidad@madrugo.com or soporte@madrugo.com.