← Help

Finance

Set signing request metadata retention

Product team · Reviewed

Settings → Signing privacy controls the lifetime of request metadata collected with new signatures. Owners and administrators can set a period from 7 to 3,650 days; the initial product setting is 365 days. Select a period appropriate for your business's retention requirements.

Keep the signed record stable

A new signing response records its document hash, signer's marks, consent and timestamp. Its private hashed network address and device description are stored separately. The immutable response contains a receipt identifier, digest, expiry and policy version, allowing the request metadata to expire without changing the signed document hash.

These values describe the request received by the application. They are not independent proof of a person's physical location or identity.

For example, a signature collected under a 90-day policy retains that expiry even if the business later chooses 180 days. The change applies to future signing requests. The hourly worker clears expired network/device fields and retains a deletion receipt. Signed documents and payment history stay intact.

Hold or release a receipt

Open a recent request receipt to place its metadata on hold with a reason. A hold prevents scheduled deletion. Release it with another recorded reason when appropriate. If its original expiry has passed, the next worker run can delete the metadata. Expired metadata cannot be restored.

Both changes require current administrator or owner access and compare the hold state you reviewed. Repeating an unchanged request preserves its original result; a conflicting change requires a fresh review.

Earlier records and setup

Older signed records may contain metadata inside their frozen snapshots or legacy signature columns. This policy does not rewrite those immutable records. The page identifies legacy signatures with separate metadata; a zero count does not assert that every old snapshot is metadata-free.

Payment-method authorizations retain their own consent and retention policy. They are not affected by this setting. Activate and rehearse the signature-evidence-retention worker during coordinated setup, including held, expired and concurrently signed records. A paused worker delays cleanup; it does not erase the signed document.