Data Retention Policy
Last updated: May 24, 2026
Table of contents
1. Overview
This Data Retention Policy explains how Joby retains and deletes data across major product areas.
Actual retention may vary based on Customer settings, subscription status, legal holds, security needs, backups, third-party provider retention, product limitations, and written agreements. Customer is responsible for setting its own record retention policies for Customer Data and for exporting records it must keep.
2. Retention Matrix
Account and organization profile data
Typical retention: account life plus a reasonable period for legal, security, billing, and support records.
Notes: includes users, roles, company settings, login metadata, and support records.
Billing, invoices, subscriptions, and payment metadata
Typical retention: as needed for tax, accounting, fraud prevention, dispute, and legal obligations.
Notes: full card numbers are processed by payment providers; Joby does not store full PAN/CVV.
CRM records, leads, clients, jobs, estimates, invoices, service plans, notes, and files
Typical retention: retained as Customer Data until deleted by Customer, account termination/export period ends, or a written agreement requires different handling.
Notes: Customer controls business record retention and should export required records before deletion.
Calls, voicemails, recordings, messages, emails, and transcripts
Typical retention: retained as Customer Data unless Customer deletes them, account retention rules apply, or provider/system limits apply.
Notes: Customer is responsible for recording/transcription notices, consent, and retention rules.
AI prompts, AI outputs, call summaries, generated messages, and AI agent transcripts
Typical retention: retained as Customer Data when saved to records; transient audio streams may not be retained by Joby after processing unless saved by a feature.
Notes: AI providers may process data as subprocessors according to their terms and Joby's Data Processing Addendum.
Time-clock records, break records, job time entries, GPS proof attached to time events, and payroll reports
Typical retention: retained as Customer Data until deleted by Customer or account retention rules apply.
Notes: Customer should retain payroll/time records according to wage/hour and tax requirements that apply to its business.
Raw live location route points
Typical retention: retained according to the organization's selected live tracking setting, currently 7, 14, or 30 days.
Notes: route points may be deleted from active systems after the configured window, while time entries, GPS proof attached to clock events, exports, reports, or audit logs may remain longer.
Audit logs, security logs, app logs, and operational diagnostics
Typical retention: retained as needed for security, fraud prevention, troubleshooting, compliance, and service reliability.
Notes: log retention may vary by provider, environment, severity, and security need.
Marketing website analytics and advertising events
Typical retention: governed by cookie choices, analytics provider settings, and marketing configuration.
Notes: non-essential marketing trackers on joby.io should load only after cookie consent.
Backups and disaster recovery copies
Typical retention: retained until overwritten by normal backup rotation.
Notes: deleted data may persist in backups for a limited time and is not restored except for disaster recovery, security, or legal reasons.
3. Account Termination and Export
After termination, Joby generally provides a limited period, typically up to 30 days, for Customer to export Customer Data unless a written agreement says otherwise.
After the export period, Joby may delete Customer Data from active systems. Backup deletion follows ordinary backup rotation. Joby may retain limited records where needed for legal, tax, billing, fraud prevention, dispute, security, or compliance purposes.
4. Deletion Requests
Business customers can request account or data deletion by contacting support@joby.io or privacy@joby.io.
If Joby processes data on behalf of a business customer, end customers, workers, or contacts should direct deletion requests to that business. Joby may forward or redirect requests to the business customer where appropriate.
5. Legal Holds and Preservation
Joby may preserve data if required by law, legal process, dispute, security investigation, fraud investigation, abuse investigation, tax/accounting obligation, or written instruction from Customer.
Customers should notify Joby promptly if they need a litigation hold or special preservation arrangement. Joby does not guarantee preservation unless confirmed in writing.
6. Customer Policy Needed
Customer should maintain its own retention schedule for:
- Customer records and communications
- Call recordings and transcripts
- Employee, contractor, and subcontractor time records
- Payroll support records
- GPS proof and live route history
- Estimate, invoice, payment, and service plan records
- Tax and accounting records
- AI-generated content and summaries
- Deleted users and access logs
Counsel should align retention with federal, state, industry, employment, tax, privacy, and contract requirements.
