Data retention
This page states, in one place, how long Consentfolio keeps consent data and what's actually in it.
Consent validity: 12 months
A visitor's consent is valid for 12 months. A returning visitor is re-prompted when either:
- their consent record is more than 12 months old, or
- the consent-material parts of your published configuration have changed since they last chose (categories, purpose text, script lists, or the Consent Mode mapping. Cosmetic changes like colors or copy wording do not force a re-prompt).
Receipt retention: life of the consent + 1 year
Each consent event (accept, reject, custom choice, update, or withdrawal) is recorded as a receipt. Receipts are retained for the life of the consent they represent, plus 1 year after that consent is superseded or expires. That is about two years in total for a consent that runs its full validity. After that window, receipts are permanently and irreversibly deleted by an automated monthly purge. There is no manual step and no extended grace period beyond the monthly cadence.
Data minimization
Consent receipts are deliberately minimal. They do not contain:
- IP address
- User-agent / browser fingerprint
- The page URL the consent was given on
What they do contain is limited to what's needed to prove a consent event happened and reconstruct it later: the consent choices made (per category, before and after), the published configuration version those choices were made against, a client-generated visitor UUID, a client-generated event UUID, the origin host the request came from, and server/client timestamps. Nothing in a receipt feeds into analytics or is used for tracking.
Cancellation
If a project is canceled, its receipts, CSV export, and visitor-UUID DSAR lookup all remain accessible, on a read-only basis, for the same retention window described above. Canceling does not shorten or reset that clock, and it does not delete anything early.
Data subject requests (DSAR)
Each project supports a CSV export of its receipts and a lookup by visitor UUID. The preferences modal shows visitors their own consent ID and date, so a visitor can quote that ID back to you (or to us, if applicable) to have their record located quickly.
Consentfolio