Data Retention and Erasure
Data Retention Policy
Last updated: 10 August 2026 · Version 1.0
This is a courtesy translation. In the event of any discrepancy, the Spanish version prevails.
1. Data minimisation principle
At Madrugo we design our systems around data protection by design and by default. We only store the minimum information required for the Mission Control console and the companion robots to work properly.
We do not keep bulk replicas of your mailboxes or calendars; Madrugo indexes references ephemerally for the 24-hour visual view and applies strict purge schedules.
2. Structured retention schedule
The retention periods applied to each category of data stored on the platform are set out below:
| Data category | Retention period | Purge or erasure mechanism |
|---|---|---|
| OAuth access tokens (Google / Apple) | For as long as the account stays connected | Erased immediately when the account is disconnected or after a user-requested purge. |
| Derived memories from Gmail & Workspace | Up to 90 days (maximum) | Scheduled automatic purge, or immediate erasure on request at /app/settings. |
Sync and audit logs (iagente_sync_logs) | 30 to 90 days | Automatic rotation in the PostgreSQL database for incident resolution. |
| APNs device tokens & Live Activities | 180 days (inactive: disabled after 30 days) | Automatically disabled after 30 days without use and permanently erased after 180 days. |
3. AES-256-GCM encryption and automatic purge cycles
All data stored at rest containing credentials, tokens or memory extracts is encrypted at field level with the AES-256-GCM authenticated encryption algorithm.
4. Right to immediate total erasure in one click
We believe users should have sovereign control over their digital footprint. Madrugo therefore provides direct, immediate mechanisms to destroy your data in full:
One-click immediate total wipe
From the settings section inside the app (/app/settings), you can press the total erasure button. This instantly and irreversibly deletes every memory, log, OAuth token and setting associated with your account.
Revoking OAuth from Google or Apple
If you revoke access from your Google account security panel (Google Account Permissions) or unlink the app from your Apple ID, the Madrugo engine will detect that the token is no longer valid and will automatically flag and delete the session on the next sync cycle.
5. Questions about retention and privacy
If you have specific questions about how we handle retention periods, or you would like to request manual confirmation that your data has been destroyed, you can contact our data protection team at privacidad@madrugo.com or soporte@madrugo.com.