Doci Privacy Policy
This translation is provided for convenience. The Korean version prevails.
Effective September 29, 2026 · Version doci-2026-09-29.3
Teams and document collections
We use team names, descriptions, membership, invitations, permissions, and document and collection associations to provide collaboration. Teammates can see each other’s nicknames and team permissions. Leaving or being removed ends team-granted document access. Account deletion removes your team membership and invitation records. Moving a personal collection into a team preserves existing sharing links; newly added team documents are not exposed through those external links.
NAVER sign-up defaults
When you first sign up with NAVER, we prefill your nickname with the nickname you consent to share. Change it if it is already taken or does not meet Doci’s nickname rules. After sign-up, we import your consented NAVER profile photo into Doci storage as your default photo, remove photo metadata and resize it. If import fails, we use a profile icon. Existing members’ nicknames and photos are not overwritten. You can change them or remove your photo in My settings. After sign-up, we delete the temporary nickname and external photo URL; your stored profile photo is deleted when you withdraw.
Finding friends and email
To help people find friends, we store the email your social sign-in provider shares with your consent and update it when you sign in. For Google and Kakao, we use only verified email addresses. If no email is provided, people can find you by nickname instead. We do not show your email in search results or to other members. You can turn off email lookup under My settings → Friends. We do not merge accounts by email; if another account already has the same address, we do not register it again. Your account email is deleted when you withdraw.
Account information and consent
We use the unique account identifier from your social sign-in provider, your nickname, and the version and time of your consent to authenticate members and provide the service. Your display settings (text size, start page and so on) are kept with your account, and the profile photo you upload yourself in My settings (optional) is kept in Doci’s file storage. Profile photos uploaded earlier stay with your account information as a small square image until they are moved to the file storage. Profile photos are saved again as an image no larger than 1024 px on the long side and a small square image, with photo details such as the location removed, and are currently shown only in your own menu and settings screen. We do not collect your date of birth, and we do not automatically copy your real name, profile photo or email from other services into your public nickname. If you do not consent to the collection and use of the information needed to sign up, you cannot become a member.
Kakao sign-in is available only when the feature is enabled. If you use it, a sign-in request is sent to Kakao, and Doci stores your Kakao member number and sign-in records for authentication. We do not receive your Kakao name or profile picture, and do not show your member number or external sign-in tokens to other participants. External sign-in tokens are stored encrypted. When you withdraw, we delete the account’s sign-in connections and records and request that Kakao unlink Doci. If unlinking fails, we keep the tokens and retry for up to seven days. Your Kakao account itself is not deleted.
Documents and participation records
We store document titles, body text, formatting, tables and attached information, edit history, sharing permissions, comments and responses to keep documents and let people work on them together. A member’s library and My templates are linked to their account. Participants’ names and edit details may be shown depending on each document’s access permissions, and members who deleted their account are shown without a name as ‘Deleted user’. Do not write sensitive personal information or passwords in documents.
We link the time a member last viewed a document and its version at that time to their account and the document, so we can show what changed since their last visit. Owners can compare against that history; other participants see only content they can currently access.
My tasks gathers titles, statuses, due dates and other details of unfinished items assigned to you from documents you can currently open, and shows them to you. We do not save this combined list separately on the server.
Comment suggestions, reactions and mentions
When you quote a sentence or suggest a change, we store the comment, its author and creation time, the original text and its position, a short surrounding passage used to find it again, and the proposed replacement. We also store whether the suggestion was applied or declined, who handled it and when. People who can view the document can see its comments and suggestions. The quoted original text is shown only while it can still be found in the current body, and is no longer shown after a suggestion is applied. The surrounding passage used to locate it is not shown. Owners and people with editing access can apply or decline suggestions.
For reactions, we store who reacted to which comment, the reaction type and the time. People who can view the document see only counts by type and their own choices. Even the owner cannot see a list of people who reacted. Reactions do not send notifications. Removing your reaction deletes its record.
When a member mentions someone with @ in a comment, we store that person's account reference with the comment and show their display name to people who can view the document. We notify the mentioned member. New change suggestions notify the owner and members with editing access who can still view the document; applying or declining a suggestion notifies the member who proposed it. We do not notify you of your own actions, or send notifications to people who muted the document or lost access.
Deleting a comment clears its quoted text, surrounding passage, proposed text, mention references and reactions. Hiding a comment keeps this information but stops showing it. When you delete your account, we delete your reactions, comments and suggestions. Comments and suggestions with replies from others leave an empty placeholder. We also remove references to your account from mentions in other comments. Changes already applied to someone else's document body and names typed into text are not automatically removed. Permanently deleting a document deletes its comments, suggestions, reactions and mention records.
Group space
When a member creates a group space, we store its name, owner, document list and each document’s sharing permissions, information needed to verify and redisplay the space link, and the members who joined and when they joined. People invited through the space link can see the space name, titles, last-modified times and sharing permissions of available documents, and the number of members. Each document opens with its own permissions. Only the space creator can see members’ nicknames and join times.
When a member leaves or is removed, we delete their space membership record. Deleting a space removes its name, links, document list and membership records, while the documents remain. Space-specific links are also turned off for documents the space creator still owns that are not in the trash. Permanently deleting a document removes it from the space list too.
Notifications
To show notifications to members, we store the recipient, notification type, related document and item, person who caused the notification, creation time and read time. Only the recipient can see a notification. We do not copy document content into notification records; we check current content and access permissions each time they are viewed. If you can no longer access a document, its notifications are no longer shown.
We link each document’s notification mute setting and the time it was set to your account. We may create reminders as task due dates or poll and survey deadlines approach. You can turn reminders off in your account settings. Your reminder preference is stored with your account.
Once a day, we delete notifications more than 90 days old and older notifications beyond each member’s newest 500. We also keep records identifying the document, item, due date and similar details to prevent duplicate reminders, and delete them during cleanup once they are over 60 days old.
Document webhooks and phone notifications
Document webhooks are currently disabled in production. Only when this feature is enabled can the owner send document change notifications to an external service they choose. Sent data includes document, table, item, poll and form titles, statuses, change types, times and counts, the document identifier and a document address without a share link secret. We do not send the document body, comment text or a participant list, but personal information such as names typed into titles or statuses may be included. People who can view notifications in the external service may also see this information.
When a webhook is configured, we encrypt and store the receiving service's address. We also store its domain and last four characters for the settings screen, notification types, enabled state, who configured it and when, and delivery results. Delivery records are kept for 30 days and then deleted. Deleting the webhook or permanently deleting the document deletes its settings and delivery records. Changing the owner disables delivery and deletes the receiving address. Notifications already sent to an external service are not erased when you delete the document or your Doci account; they follow the receiving service's retention and deletion rules.
Phone notifications are currently disabled in production. Only when this feature is enabled can members allow notifications on a device and subscribe. We store the device's push receiving address (endpoint), encryption keys, subscription time and delivery status, linked to the login session, device and account. Notifications are encrypted and sent through browser push services such as Apple, Google and Mozilla. We send only a generic message that there is a new notification, rather than document titles, body text or participant names. Unsubscribing or signing out deletes the corresponding subscription information; deleting your account deletes it for all devices. Manage notifications already displayed on your device in its notification settings.
Guest display names
Guests can optionally enter a name for each document so people can recognize them in comments and named polls. We store up to 40 characters in the document and show it as “Name · Visitor number” to people who can view that document. Only the owner can see names and individual choices in named polls. You can change or clear the name while you can access the document from the same guest device. If you clear device data or your 30-day device session expires and is replaced, you may no longer be able to change or clear the previous name yourself. In that case, contact Doci.
We keep the last saved name and the time it was saved in this device’s browser storage to prefill the name in your next document. Saving an empty name also clears the name remembered on this device. Clearing browser data does not clear names stored in documents.
Attendance surveys and date polls
Attendance surveys store names, notes and numeric answers you enter in the questions, your selected answers, and submission and update times to collect attendance responses. Answers are linked to member or guest participation records to prevent duplicate submissions and let you find your own answers again. You can view your own answers; only the document owner can view other people’s individual answers and submission times. Account names and device information are not automatically shown with survey answers. If the owner enables result sharing before publishing, participants can see aggregates such as counts per choice and numeric totals according to the result visibility settings. Names, notes and date answers are not shared. With few responses, someone may infer an individual answer from the aggregates.
Date polls store your selected date choices and submission and update times, linked to your participation record, to collect available dates. For named polls, only the owner can see display names and individual choices. For anonymous polls, even the owner cannot see individual choices. You can view your own choices. Other participants can only see aggregates according to the result visibility set by the owner.
For time and rating questions, we store the time you enter and the rating you choose (1–5) with your other survey answers. Only you and the document owner can see individual answers. Surveys with result sharing enabled show counts for each rating and the average according to their visibility settings. Time answers are not shared with other participants. First-come surveys show capacity and remaining places regardless of result visibility settings, and polls with capacity limits show counts for each choice. These numbers may allow people to infer how many people responded or an individual’s choice.
Settlement names and amounts
Settlements store the person and group names you enter, group members, expense amounts and dates, payers and people excluded from a split as document content to split costs and calculate who pays or receives how much. People who can view the document can see this information and the calculated shares. An author label linked to an account becomes “Former user” after withdrawal, but names and amounts entered directly in another person’s settlement document are not automatically deleted. They can be edited or deleted according to the document’s editing permissions.
When you select Sent, we save the sender and recipient (people or groups), amount and date as a row in the expense split table. This is a participant’s record, not an actual transfer or confirmation from a bank. People who can view the document can see it, and editing permissions determine who can cancel or edit it. Canceling a record hides the row, which can be restored from hidden items. History keeps the content from when you save the document. Like other expense split content, it follows the document’s history, retention and deletion rules. Records and names and amounts entered in someone else’s document are not automatically deleted when you delete your account.
Table calculations, links and CSV
Formulas, row links to other tables in the same document, and rollup settings are stored as document content. Calculation and rollup results are computed from table values as needed, rather than saved as separate cell values. Timelines and charts also render or calculate table values you can already view on your device.
CSV import reads the file on your device. When you create the table, it sends cell content and column settings to the server to save in the document. The CSV file itself is not uploaded or retained, but imported personal information such as names and contact details follows the same document permissions, history, retention and deletion rules as table content entered by hand.
CSV downloads create a file on your device. It may include names and values shown in the table, as well as creator and editor names you have permission to view. Deleting a document or your account does not delete downloaded files, so please manage them on the device where they were saved.
Table rules, repeating items and unsettled expense reminders
When the owner enables an automatic table rule, we store its condition, action, target column, enabled state, creator and creation time. Completing an item can fill the chosen date cell with today's date; completing or adding an item can notify the owner or assignee. The owner and people with editing access can see rule settings, and anyone who can view the document can see changed values. Repeat settings are stored with the item. When a completed item's deadline passes and the next round arrives, the system reopens its status, moves its deadline and records the previous round's date. These values follow the document's history, retention and deletion rules.
Unsettled expense reminders check whether transfers remain in an expense split table and notify only the document's member owner. The notification includes no settlement amounts or participant names. We store a record identifying the calculation result to avoid repeating reminders for the same state. These reminders follow the same notification, retention and deletion settings as other reminders. You can turn off reminders in your account settings or mute the document.
Table of contents and content from other documents
The table of contents is built from headings in the current document. Adding content from another document stores only references to the source document and text location. The source is read using each viewer's current permissions and displayed as read-only. Being able to view the document containing the reference does not let you see the source without permission. No copy of the source content is stored in the containing document's body, search index, AI index or history. Duplicating that document does not create a copy of the source content either. If the source is deleted or you lose access, it is no longer shown.
Attached files and photos
Files and photos that members upload to documents are treated as document content. Files are kept on a file storage device (NAS) that the Doci operator manages directly, together with each file’s name, size, type, uploader and upload time. When photos (JPEG, PNG, WebP, GIF) are uploaded, we remove metadata such as the location and camera details and create separate small images for previews. If a photo cannot be read, for example because the file is damaged, it may be kept as a download-only file without its metadata removed. We do not remove metadata inside other files, such as author details in PDFs or office documents, so check them before uploading. Only people who can view the document (the owner and people with edit, comment or view permission) can preview and download its files; poll and survey response links cannot see them. Each file can be up to 20 MB, one document can hold up to 100 MB of files in total, and executable files are not accepted.
AI assistant
The AI assistant is optional. AI processing happens when a member makes a request in the AI assistant panel, or when a scheduled feature they turned on themselves (such as the weekly progress summary) runs. The request, any selected text, and the document content the feature needs, limited to what the requester can currently see (body text, tables, comments, poll and survey results, decisions, text from attached text files and so on), are then sent to an AI model. In a shared document this can include content written by other participants and names that appear in the document. When an AI feature needs attached photos or PDFs, the Doci server reads their text itself (macOS built-in text recognition) and sends that text and, if needed, the photo itself to the AI model. Guests can only use public template recommendations. The document search index, however, is built for every document whether or not the AI assistant is used (see below).
AI processing goes through OpenRouter, an AI service in the United States, and is carried out by the AI model providers OpenRouter connects to. OpenRouter picks one of the providers that offer the model and sends the request there, and Doci does not separately restrict whether providers retain data or use it for training. Depending on the provider, request and response content may therefore be kept for a period of time or used to improve the provider's own services (including model training). If the provider handling a request fails, the request is retried only with the same provider and is not passed on to another provider. No account identifier is attached to requests. Doci does not use AI requests or document content to train AI, and has no screen where the operator can read the original requests. AI results are first shown to the requester as a preview and only go into the document when they apply them.
For requests that need up-to-date information (creating a document, adding content and so on), the AI builds a short search query based on your request and the document's content, and a meta-search program Doci runs on its own server (SearXNG) sends that query to external search engines, including ones outside Korea. Search queries may include what is written in your request or the document (including personal information such as names and contact details), so please do not put anything in your request that you would not want sent to external search engines. Search engines receive the request from Doci's server, so your account and device information are not passed on. For each request Doci's server opens and reads at most 3 highly relevant web pages, and their text is deleted once processing ends. Results that use web material list the sources used (title, link and search date). Web search cannot be turned off separately.
For template recommendations, the topic you enter (guests included) and the titles and summaries of public templates, and for search by meaning, related documents and asking your documents, the search words, are sent to OpenRouter's embedding feature (the bge-m3 model), which turns them into lists of numbers that represent meaning. For this document search, Doci sends the title and the text excerpts visible with view access of every document that is not in the trash (member and guest documents) to OpenRouter's embedding feature and indexes them each time a document is created or changed, whether or not anyone uses the AI assistant. Search results only show documents the searching member can currently open.
Guest display names may also be included in comments or edit information read by AI. Names of participants linked as assignees are included in the document search index and sent to OpenRouter’s embedding service.
Retention and deletion of AI records
Requests, document content and tool results used in an AI task are kept only while the task is being processed, and a ready result can only be opened or applied for 30 minutes if it is an answer, or 15 minutes if it is a proposal that changes a document. When a task is applied, cancelled, fails or expires, its request and result content are deleted, and the task record without content (feature, status, times and identifiers of applied results) is deleted after 30 days. Results you apply become document content and follow the document retention rules, and the information needed to undo an AI change is kept for 30 days. In the conversation beside the document, your requests (up to 1,000 characters) and the answers (up to 1,600 characters) are visible only on the device and account that started the conversation, and are deleted 30 days after they were sent. You can also delete a conversation yourself. Weekly progress summary previews that were not applied are deleted after 7 days. The search index of every document (titles, text excerpts and lists of numbers) is kept in Doci's database, rebuilt when a document changes, and deleted when the document is moved to the trash or deleted forever. Text extracted from text files for AI to read is deleted together with the file. Usage statistics keep only the feature, status, time taken, character counts, token counts, cost and whether a search succeeded, with no request content, and they can no longer be linked to anyone once the task record is deleted or the member leaves. When you leave Doci, your AI conversations, task records and undo information are deleted too. These records may also remain in database backups for disaster recovery for up to 30 days.
Outsourcing and transfer abroad for AI processing
To provide the AI assistant, Doci entrusts the processing of content that may contain personal information to businesses outside Korea as follows.
- Names included in transferred data: assignee names in the document search index and guest display names in comments or edit information needed for an AI request may also be included.
- Recipients: OpenRouter, Inc. (169 Madison Ave #2404, New York, NY 10016, USA · privacy contact privacy@openrouter.ai) and one AI model provider that OpenRouter picks for each request. Currently the providers are Reka, Wafer, DekaLLM, Ionstream, DeepInfra, Phala, Mancer, Parasail, Chutes, AkashML, CoreWeave, Novita, Alibaba, Cloudflare and Venice for the chat model (Qwen3.8 27B), and Parasail and DeepInfra for embeddings (bge-m3). The list can change and can be checked on OpenRouter's provider page for each model.
- Destination country: United States (OpenRouter processes data in Google Cloud regions in the US). Most model providers are also US companies, but some have their headquarters in another country (for example Alibaba in China), some do not state where they process data, and some are decentralized providers that process data on servers spread across several countries.
- When and how: sent over an encrypted connection (HTTPS) each time an AI feature is requested or a scheduled feature you turned on runs, and each time the document index is built or updated.
- Items transferred: AI requests and selected text, the document content a feature needs (which may contain personal information such as text written by other participants and names in the document), text read from attached photos and PDFs and, where needed, the photos, template recommendation topics, and, for the search index, the titles and text excerpts of every document plus search words. Account identifiers are not sent.
- Purpose: producing AI assistant results, template recommendations, search by meaning and finding related documents
- Retention period: under its data processing agreement, OpenRouter deletes request and response content right after the response is generated, and keeps only usage records without content (token counts, processing time and so on) for as long as its business and legal obligations require. How long model providers keep data and how they may use it (including for training) follows each provider's own policy, and Doci does not separately restrict this. Each provider's policy can be checked on OpenRouter's provider page for each model.
- How to refuse and what happens if you do: if you do not use the AI assistant, nothing is sent because of AI requests. You then cannot use the AI features, but all document features keep working. In a shared document your writing may be included when another participant uses AI, so do not share the document if you do not want that. Sending for the search index happens for every document whether or not AI is used, and there is currently no way to refuse only this. If you do not want it, delete the document (moving it to the trash also deletes its stored index right away) or let us know through the Doci contact form.
- External search engines: for web searches, search queries built from your request and the document's content are sent to external search and news engines (DuckDuckGo, Naver, Google News, Bing News, Wikipedia, Wikinews). Search queries may include personal information.
Operator access
To run the service (usage statistics, handling inquiries and reports, and checking for problems), one designated operator can view the member list (nickname, sign-up date, last sign-in time, sign-in method, language setting and number of documents) and the document list (title, how it was created, status, creation and edit times, the number of participants, comments and share links, and the number and size of files). The operator does not see document contents, file names or contents, or share link secrets, and each operator view is logged. Daily statistics are kept only as totals that cannot identify individuals.
Browser storage and share links
We keep your sign-in session, device identification information, recent document access records and unsaved drafts in cookies and browser storage. Link secrets are stored on the server as hashes. If you clear your browser data, you may lose guest access records or unsaved input. Photos and files you viewed in documents may remain in your browser cache (permission is checked again each time they are opened). On a device that several people use, clear the browser data when you are done. We do not put ads or visitor analytics on document screens.
Display choices such as table views and collapsed headings are remembered in this device’s browser storage so you can reopen the same view. You can clear them with “Reset remembered views” or by clearing browser data.
“Show title in link previews” is off by default. If the owner enables it for a link, anyone with that link and link preview services such as KakaoTalk can see the document title (or the question title and deadline for a poll or form link). The body and participant names are not shown. Turning it off, revoking the link or reissuing it stops Doci from showing the title, but previews already created by a messenger may remain on that service.
This device also remembers date columns chosen for timelines, and chart category and value columns, chart shape and summary choices. These display preferences are not stored separately on the server or shared with others. You can clear them by resetting remembered views or deleting browser data.
Sending shares and calendar files
When an owner selects “Copy with title” or “Send”, the device builds a sharing message with the document or question title, the poll or survey deadline if present, and the address including the link’s secret. The message goes through the chosen clipboard or device share sheet and is not separately stored on Doci’s server. Recipients and the selected app can see the title and link sent. Deleting the document in Doci does not delete messages already copied or sent; their retention and deletion are managed by recipients and the app.
“Send via KakaoTalk” is available only when KakaoTalk sharing is enabled. When the owner selects it, the browser loads Kakao’s sharing script, and Kakao receives the IP address, browser information, and the title, message text and link, including its secret, to be sent. Kakao’s sharing script may store information in this device’s browser. Recipients can see the message sent. Retention and deletion of information held by Kakao and on your device follow the service’s policies and browser settings. Deleting a Doci document or withdrawing does not delete messages already sent.
ICS files downloaded to add an event to a calendar are created on your device and are not separately stored on Doci’s server. They contain the document title, information field name, and date and time, but no share link, participant list or document body. Personal information entered directly in the title or field name may be included. People who receive the file or have access to the calendar you import it into can see its content. Calendar settings may sync it to an external service. Deleting a document or withdrawing does not delete downloaded files or calendar events, so manage them on your device and in your calendar.
Retention and deletion requests
Account information is kept while we provide the member service and is deleted as soon as you delete your account. You can delete your account right away under Account in My settings by typing a confirmation phrase, and you are signed out on every device. Deleting your account deletes your sign-in connection, nickname, settings and consent records, your profile photo, your library organization, My templates and saved bundles, the documents you own (including shared documents and documents in the Trash), your comments and poll & survey responses in other people’s documents, and the inquiries you sent from your account. If other people replied to one of your comments, only an emptied ‘deleted comment’ placeholder remains. The body text, tables, records and files you added to other people’s documents are part of those documents, so they stay, and the author is shown without a name as ‘Deleted user’. Guest documents left on a device where you never signed in are not part of your account, so they stay. Anything that takes longer is finished within a few minutes. When you change or delete your profile photo, it stops being shown right away and is erased from file storage within 24 hours. Documents moved to the Trash can be restored within 30 days, but not after permanent deletion. Documents made without signing in are moved to the Trash if nobody opens them for 90 days and permanently deleted 30 days later. When you sign in on a device, the documents made on that device without signing in are moved to your account library and kept as member documents from then on. Files in a document in the Trash are kept until the restore deadline but cannot be opened, and they are erased from file storage within 24 hours of permanent deletion. Files uploaded to a document but never used are deleted after 24 hours, and files removed from a document are kept for 30 days for undo and history restore and then deleted. If a document made by copying still uses the same file, that file is deleted only after it is removed from that document too. When you delete your account, files you uploaded but never used in a document are deleted, and the files of the documents and profile photo deleted with your account are erased from file storage within 24 hours. Database backup copies kept for recovery from failures are deleted 30 days after they are made, and if we ever restore from a backup before then, the account deletion and permanent deletion records are applied again before the restored data is used. If we start keeping backups of file storage, we will add how long backup copies are kept to this policy. External sign-in tokens are stored encrypted and revoked when the account is deleted; a failed revocation is retried for up to 7 days. Your Google or Naver account itself is not deleted. Team-created documents are an exception. If another active teammate remains when you delete your account, their ownership passes to the team administrator or a successor, and the documents, attachments and team collections stay with the team. The administrator can also reassign team document ownership. Personal documents brought into a team follow their original ownership and deletion rules. If no eligible teammate remains, they are deleted as shown in the account deletion confirmation.
Guest display names, attendance survey and date poll responses, and settlement content are kept with the document and deleted when it is permanently deleted. Documents moved to the trash can be restored for 30 days. Guest-owned documents that nobody opens for 90 days move to the trash and are permanently deleted 30 days later. This 90-day rule does not separately apply to guest names and responses in someone else’s document. When a member withdraws, we delete their own documents and their comments, poll responses and survey answers in other people’s documents. Comments with replies from others remain only as empty placeholders. Deleted information may remain in disaster recovery database backups for up to 30 days from the backup’s creation. Team-created documents are an exception. If another active teammate remains when you delete your account, their ownership passes to the team administrator or a successor, and the documents, attachments and team collections stay with the team. The administrator can also reassign team document ownership. Personal documents brought into a team follow their original ownership and deletion rules. If no eligible teammate remains, they are deleted as shown in the account deletion confirmation.
Permanently deleting a document also deletes its notifications, per-document notification settings, reminder deduplication records and last-view records. Deleting your account deletes your received notifications and notification settings, last-view records, spaces you created and their links, document lists and membership records, and your membership records in other spaces. In notifications retained for other people, your activity is attributed to a deleted user. Team-created documents are an exception. If another active teammate remains when you delete your account, their ownership passes to the team administrator or a successor, and the documents, attachments and team collections stay with the team. The administrator can also reassign team document ownership. Personal documents brought into a team follow their original ownership and deletion rules. If no eligible teammate remains, they are deleted as shown in the account deletion confirmation.
Contact and your rights
You can delete your account (and your information) yourself in My settings. Please send requests to access or correct your personal information, and other account requests, through the Doci contact form. The content of your inquiry and, if you are signed in, your account identifier are kept for 90 days to handle the inquiry, and inquiries sent from your account are deleted when you delete your account. Do not send passwords, verification codes or resident registration numbers.