| Account identity state | Username, account status, account creation state, recovery boundary state, account deletion state | Retained for the duration of the service relationship. Removed from normal service operation when the user deletes the account, subject only to legal, security, compliance, accounting, or valid preservation constraints. |
| Authentication material | Password verification material, server-side PIN verification state, recovery-related state, excluding plaintext passwords, plaintext PINs, or plaintext recovery phrases | Retained while the account exists. Removed from normal service operation when the user deletes the account, subject only to legal, security, compliance, accounting, or valid preservation constraints. Plaintext passwords, plaintext PINs, and plaintext recovery phrases must not be retained. |
| Device state | Trusted device list, enrollment state, revocation state, replacement state, Privacy-Preserving Device Handles, Device Trust status, optional Enigm OS trust signals | Retained until the user removes the device, deletes the account, or the lifecycle state is no longer required. Device deletion removes the associated device state from normal operation. |
| Session state | Active sessions, session creation state, last activity state, termination state | Enigm App sessions use a 1-hour validity window and are automatically renewed while eligible. Enigm Command sessions are limited to 6 hours. Session lifecycle records are minimized and retained only as required for security, abuse prevention, or operational review. |
| PIN and profile risk state | PIN validation outcomes, reverse PIN event state, repeated incorrect PIN risk state, profile risk status | Retained only as required to enforce account security, show current risk state, support auditability, and clear the risk state after successful PIN validation. Plaintext PIN values must not be retained. |
| Profile security level | Low, Medium, High, or Extreme profile security level and the underlying account configuration signals required to display it | Retained while the account exists or until the user changes the relevant security configuration. |
| Message content | Encrypted messages, encrypted attachments, encrypted multimedia | User-defined message lifetime up to a maximum of 30 days. Users can manually delete messages immediately. Server-side storage, where required, stores encrypted content only. |
| Message metadata | Delivery state, synchronization state, expiration state, conversation membership, lifecycle markers | Partially encrypted and otherwise protected according to the applicable product and storage domain. Follows the message lifecycle where possible, with a maximum of 30 days for normal message-related lifecycle state unless security, abuse, or legal constraints require limited preservation. |
| Enigm Server lifecycle data | Server lifecycle state, server ID join requests, membership, region selection, server audit visibility | Retained while the user or customer maintains the Enigm Server service. Deleted when the user or customer deletes the server environment, subject only to legal, security, or compliance constraints. |
| Enigm Server content | Server-scoped encrypted messages, encrypted attachments, encrypted multimedia, encrypted user-generated content | Follows the message-content retention model: user-defined lifetime up to a maximum of 30 days, with immediate manual deletion where authorized by policy. |
| Enigm Link lifecycle data | Official USB association, product entitlement, update channel, version state, official device validation state, revocation, replacement or retirement state | Retained while the user maintains Enigm Link service or until the lifecycle state is no longer required, subject only to legal, security, support, or operational constraints. |
| Enigm Key emergency data | Emergency alert messages, emergency contacts, emergency activation event, event-bound location sharing, emergency event end state | Treated as message and emergency-event data. Retained according to the message lifecycle, up to a maximum of 30 days, and minimized after the user cancels the emergency sending workflow. |
| Enigm Key device lifecycle data | Account association, initial linking state, device revocation state, loss state, replacement state | Retained until the user removes or revokes the Enigm Key, deletes the account, or the lifecycle state is no longer required, subject only to legal, security, or operational constraints. |
| Enigm eSIM data | Activation state, Enigm account association, connectivity lifecycle state, service status metadata, unlinking, deletion, replacement or retirement state | Retained until the user deletes or retires the Enigm eSIM service, subject only to legal, security, or operational constraints. |
| Security data | Authentication events, Device Trust events, runtime protection findings, Active Defense findings, Enigm Intelligence events, incident records, defensive action records | Retained for a maximum of 30 days for normal security operations unless an active investigation, legal obligation, or security requirement requires preservation. |
| Operational data | Service health events, error logs, availability logs, abuse prevention records, rate-limit events, security-control events | Anonymized where possible and retained for a maximum of 30 days for normal operations. |
| Payment data | Payment status, subscription state, entitlement state, payment method category, purchase country selected by the user, transaction reference, Code Coin redemption state, invoice or accounting records when requested | Retained for the duration of the user service relationship and according to applicable legal, accounting, tax, abuse-prevention, and security obligations. Standard payment enrollment does not require email address, phone number, or identity document collection. |
| Training data | Essential or advanced training state, final-exam completion state, product education progress | Retained while required for account education, product guidance, support, enterprise review, or user-requested deletion, subject to legal, security, compliance, or operational constraints. |
| Support and legal data | Support requests, legal inquiries, security disclosure reports, responsible disclosure communications, enterprise security inquiries | Retained for 30 days after the case is closed, unless legal, security, compliance, or contractual obligations require preservation. |