Security & architectureSecurity reviewersReviewed by Security
Data retention and metadata boundary
Heads up: Retention (days after close) is separate from the 3+ responses rule for viewing aggregates (see Viewing results (/docs/docs-viewing-results)).…
1 MIN READ·UPDATED AUG 2, 2026·MAINTAINED BY SECURITY
Heads up: Retention (days after close) is separate from the 3+ responses rule for viewing aggregates (see Viewing results). The platform also avoids per-response admin metadata by design.
Retention (admin-configured)
When creating a poll, the Data retention after poll closes setting offers 7, 14, 30, 60, or 90 days. Responses are permanently deleted after this period.
This is a product-level purge window for encrypted responses after the poll ends - separate from the unlock threshold (3 responses) which governs when aggregates become visible.
What the platform avoids storing
InviziPoll does not store row-level response timelines, IP-derived rankings, or per-ballot audit trails in the admin analytics surface. Operational logs may record admin actions (for example who changed a setting) without turning the respondent data store into a per-person feed.
Tenant purge
Irreversible tenant purge workflows destroy stored data without decrypting content - consistent with zero-knowledge operations.