Data retention & deletion

Effective September 18, 2026 · QuoteVitals is operated by Fandonia LLC, USA

Three commitments run through everything below. You can delete your account yourself, at any time, from inside the app — no email, no phone call, no waiting on us. Your documents are yours, held to run the product for you and for nothing else. When we delete, we delete the files, the extracted data and the notes, not just the pointer to them.

1. Archiving

Archiving is for a capital request where the decision has been made. It clears the board without losing the record.

When you archive a request it leaves the open view and appears under Archived. The bid tab, memo, notes, corrections, approval record and every quote file stay exactly as they were, and anyone who could see it before can still open and download it. No new quotes can be filed into it — a late quote arriving by email is held rather than attached. The retention clock starts.

Restoring puts it back at any time before the retention period ends, and stops the clock. Archiving again restarts it from the new date. Archiving never deletes anything and is never automatic. Owners and reviewers can archive; viewers cannot.

2. Retention

Your organisation chooses how long archived requests are kept. The default is 24 months from the archive date. An owner can change it in Settings to 12, 24 or 36 months, or to keep everything until someone deletes it. The choice applies to the whole organisation, including requests archived before the change.

Open requests are never aged out. Retention only counts down on archived ones.

Thirty days before an archived request reaches the end of the period, the organisation's owners get one email listing what will be purged. Restoring the request, or extending the period, stops the purge. The purge runs nightly: storage files are removed first, then every database row.

3. Deleting a comparison

An owner can delete a capital request at any time. It is immediate and cannot be undone. Every quote, specification and output file is removed from storage, then all extracted data, flags, allocations, corrections, notes and events, then the approval record and the request itself. A deletion receipt is written so the organisation has a record that it happened.

Emails already sent from the request — a memo, a push-back note — are in the recipients' mailboxes and cannot be recalled.

4. Deleting your account

You can delete your account at any time, from Settings on the web or in the iOS app, without contacting us. You confirm by typing your email address, and it takes effect immediately.

You are signed out everywhere and can no longer sign in. Your name, email, role and sign-in records are removed. In your organisation's records, your name on past approvals and corrections is replaced — the approvals themselves stay, because they belong to the organisation's purchase record rather than to you.

What happens to the organisation depends on your role:

Your situationResult
A reviewer or viewer, or an owner with other ownersThe organisation is untouched and stays with the team.
The only owner, with other membersYou must name another owner first. The app will not leave an organisation ownerless.
The only owner and the only memberDeleting your account also schedules the organisation for deletion, as below.

5. Deleting the organisation

Only an owner can do this, from Settings, by typing the organisation's name. It is deliberately not immediate.

  1. The organisation is frozen. Nobody can upload, edit, approve or send; everyone can still read and download. The inbound quote address stops accepting mail.
  2. Every owner is emailed at once, and again on day 7 and day 12, with a link to cancel.
  3. Any owner can cancel during the 14-day window, which restores the organisation exactly as it was.
  4. On day 14 everything is purged: every capital request, then the storage folder, the team, the retention setting and the organisation record.

The window exists because an organisation's data usually belongs to more than one person, and a single owner should not be able to erase a hospital's purchase record by mistake or on their last day. If you need a faster purge under a contractual obligation, contact us and we will complete it within two business days after confirming with a second owner or an authorised contact.

6. Lapsed subscriptions

If a subscription lapses the organisation becomes read-only rather than inaccessible — you keep reading and downloading. Owners are emailed on day 1 and again on day 30. On day 46 the standard 14-day deletion window begins, so everything is purged on day 60 unless the plan is renewed. You are told before anything is removed.

7. What survives deletion

After a purge, what remains contains no quote document, no extracted figures, no notes and no personal name:

8. Backups

Deletion from the live database and live file storage is immediate; once a purge finishes the data cannot be read through the app or its API. Encrypted backups are kept on a short cycle and are never restored except to recover from a failure of the service. If we ever did restore from a backup taken before your deletion, the deletion receipts are what let us re-run every deletion recorded since.

We do not keep copies of your data on laptops, in email, or in support tools.

9. Requests and contact

The self-service tools above are how we honour a statutory right to erasure or access. If you cannot reach the app, or your hospital's process requires a written request, email direction@fandonia.app from the address on your account. We act on account deletions within 2 business days and on organisation deletions after confirming with a second owner. We answer access, correction and purge requests — including a document that should never have been uploaded — within 10 business days. There is no charge.

10. Changes

We review this page at least once a year and whenever we change a retention period, add a processor that handles document content, or change how deletion works. Changes that shorten a retention period or add such a processor are emailed to organisation owners at least 30 days before they take effect.