> ## Documentation Index
> Fetch the complete documentation index at: https://glide-9da73dea.mintlify.site/llms.txt
> Use this file to discover all available pages before exploring further.

# Retention tiers

> How activity_log rows age across Hot, Warm, Cold, and Regulatory tiers. Per-entity policy. Nightly Inngest sweep.

Activity log rows accumulate; storage costs grow linearly with traffic.
Glide OSS organizes rows into four retention tiers per OSS plan §M4,
configurable per entity:

| Tier | Configured age band | Intended storage |
| - | - | - |
| Hot | 0–7 days | Postgres |
| Warm | 7–90 days | Compressed storage |
| Cold | 90 days–1 year | Archive storage |
| Regulatory | 1–7 years, disabled by default | Deep archive |

The OSS plan rationale: most operators don't need the regulatory tier;
turning it on commits to a multi-year retention obligation that's
expensive + GDPR-tense (longer retention = more rows the user can
demand redaction on). The default is off; operators in jurisdictions
that require it (US FinCEN, EU AMLD) flip it on per entity.

## Implementation status

The `retention-tier-sweep` function is scheduled daily at 03:00 UTC, but returns `status: 'skipped'` with `reason: 'retention_enforcement_not_deployed'`. It does not archive, delete or mark rows as transitioned.

The age bands above describe configuration targets. The previous count-and-timestamp implementation was removed because it suggested that retention had occurred. Do not treat the schedule, configured thresholds or old sweep timestamps as evidence of archival or deletion.

## Configuring per entity

Admins use the `/admin/retention` UI:

```
Hot tier (days)              [  7 ]
Warm tier (days)             [ 90 ]
Cold tier (days)             [365 ]
Regulatory tier (days)       [2555]    [ ] Enable regulatory tier
Notes                        [        ]
```

The values are validated server-side: `hot < warm < cold` is required;
`regulatory > cold` if `regulatoryEnabled = true`. Stored sweep timestamps do not establish that retention enforcement ran.

## DSAR + retention interaction

Retention configuration expresses intended age bands; enforcement is currently disabled.
The DSAR redaction workflow (`/admin/dsar`) is the *lower* bound — a
right-to-redaction request can flag fields as `[REDACTED]` regardless
of which tier the row is in. The append-only-trigger pattern guarantees
the row's existence stays for audit-log integrity even after redaction.

See [DSAR redaction workflow](/oss/concepts/money-safety-contracts)
for the full picture.

## Reading list

* [Money-safety contracts](/oss/concepts/money-safety-contracts) —
  the F-rules around append-only `activity_log`.
* [Receipt schema](/oss/standards/receipt) — what's in each row.
* Source: `apps/web/drizzle/0048_retention_tier_config.sql` +
  `apps/web/src/inngest/functions/retention-tier-sweep.ts`.


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.