All legal documents

Document deletion and recovery policy

What happens when you delete a document, how long you have to change your mind, what is destroyed when the window closes, and what we keep afterwards.

Effective27 July 2026Version1.0Clauses9
Contents(9)
  1. 1.What the words mean
  2. 2.Deleting a document
  3. 3.The recovery window
  4. 4.Permanent deletion
  5. 5.What we delete without being asked
  6. 6.Who can do what
  7. 7.What survives permanent deletion
  8. 8.Getting your documents out
  9. 9.Changes to this policy

This policy forms part of the terms of service and expands on the retention table in the privacy policy. It describes deletion inside a workspace. Closing an account or a whole workspace is covered by clause 9 of the terms.

The short version

Deleting a document does not destroy it. It moves to the Deleted tab and stays fully restorable for your workspace's recovery window, 30 days by default. After that it is destroyed for good, files included, and nobody can bring it back. The audit trail of what happened to it is kept either way.

1.What the words mean

Delete
Move a document to the Deleted tab. Reversible. Nothing is destroyed and no data leaves our systems.
Restore
Bring a deleted document back into the documents list, exactly as it was when it was deleted.
Recovery window
The period a deleted document stays restorable. Set per workspace, 30 days unless an admin changes it, and never shorter than 1 day or longer than 180.
Permanent deletion
Destroying the document, its stored files and everything attached to it. Irreversible, by us and by anyone else.
Audit trail
The append-only, hash-chained record of what happened to a document. Described in clause 7 and in the security overview.

2.Deleting a document

Any member of a workspace can delete a document in it. The document leaves the documents list and appears in the Deleted tab, which shows who deleted it, when, and how many days are left before it is destroyed.

Deleting is recorded in the document's activity feed and in its audit trail, with the account that did it. There is no way to delete a document quietly.

Deleting a document that is out for signature cancels it

If a document is still awaiting signatures, deleting it also cancels it: every outstanding signing link stops working immediately and recipients who have not signed can no longer do so. This is not undone by restoring the document. Restoring gives you the document back; sending it out again is a new signature request.

Signatures already collected are unaffected. A document that was completed before it was deleted is still a completed document when you restore it, with the same signed file, the same certificate of completion and the same hashes.

3.The recovery window

A deleted document stays restorable for the whole of the recovery window. During that time any member can restore it in one click from the Deleted tab, and members can still open it and download the original and signed files.

What the recovery window means in practice

Question

How long?

Answer

30 days by default. An admin can set anything from 1 to 180 days in workspace settings.

Question

Who can restore it?

Answer

Any member of the workspace. Viewers cannot.

Question

Can I still download it?

Answer

Yes. Members can download the original and, if it was completed, the signed file and certificate, for as long as it is in the Deleted tab.

Question

Can recipients still reach it?

Answer

No. Every signing link is revoked the moment the document is deleted, including on completed documents.

Question

Does it still count towards anything?

Answer

No. Deleted documents are excluded from the dashboard, search, the activity feed, reminders and expiry.

Question

What if an admin changes the window?

Answer

Documents already in the Deleted tab keep the window they were deleted under. A shorter policy never destroys something earlier than the person who deleted it was told it would be.

4.Permanent deletion

A document is destroyed permanently in one of three ways: its recovery window closes and the daily maintenance job destroys it; an admin destroys it early from the Deleted tab; or an admin empties the Deleted tab.

Only admins and owners can destroy a document before its window closes. Ordinary members can delete and restore, but cannot make anything unrecoverable. The worst a member can do is something an admin can undo.

  • The document record is deleted from the database.
  • Its recipients, fields, signature images and captured values go with it.
  • Its activity feed goes with it.
  • The original file, the signed file and the certificate of completion are deleted from encrypted object storage.

We cannot undo this, and neither can support

Files are encrypted at rest and there is no separate copy held back for recovery. Once a document is permanently deleted there is nothing left to restore, whoever asks and whatever they are willing to pay. Export anything you might need before the window closes.

Backups are a separate system with their own rotation, described in the security overview. A permanently deleted document may persist in an encrypted backup until that backup ages out on its normal cycle. Backups are never used to restore an individual document, only to recover from a disaster affecting the whole service.

5.What we delete without being asked

The only automatic destruction is the one described above: documents whose recovery window has closed. We do not delete documents because a workspace is inactive, because a plan was downgraded, or because a document is old. A document you have not deleted stays until you do.

Signing links and one-time tokens are the exception, and they are not documents: they are revoked when used, cancelled or expired, and purged on the same daily job.

6.Who can do what

Action

See the Deleted tab

Viewer

Yes

Member

Yes

Admin

Yes

Owner

Yes

Action

Delete a document

Viewer

No

Member

Yes

Admin

Yes

Owner

Yes

Action

Restore a deleted document

Viewer

No

Member

Yes

Admin

Yes

Owner

Yes

Action

Destroy one permanently

Viewer

No

Member

No

Admin

Yes

Owner

Yes

Action

Empty the Deleted tab

Viewer

No

Member

No

Admin

Yes

Owner

Yes

Action

Change the recovery window

Viewer

No

Member

No

Admin

Yes

Owner

Yes

Every one of these actions is written to the audit trail with the account that performed it, the time, and the network address it came from.

7.What survives permanent deletion

The audit trail. Nothing else.

A document's audit trail is append-only and hash-chained: each entry carries the hash of the one before it, which is what makes the record evidence rather than a list somebody could have edited afterwards. Entries are never rewritten and never removed, including when the document they describe is destroyed. What remains is the record of what happened: that the document existed, that it was sent, viewed, signed, downloaded, deleted and destroyed, by whom and when, together with the fingerprints of the files.

Why we cannot remove audit entries on request

Removing entries from a hash chain breaks it. The break is not confined to the document in question: it is the mechanism by which every other document in the workspace proves it has not been tampered with. Other parties to a signed document also have a legitimate interest in the evidence of their own signature, which is not ours to destroy on one party's request. This is the position taken by GDPR Article 17(3)(b) and (e) and the corresponding exemptions in section 17 of the DPDP Act, 2023.

The audit trail does not contain the document itself. It holds no page content, no field values, no signature images and no attachments. Those are destroyed with the document. What it holds about a person is their name, their email address, the network address they acted from, and what they did.

If you need personal data removed from an audit trail, which is a data subject request rather than a document deletion, write to privacy@dropthedoc.xyz. We handle those under clause 12 of the privacy policy, which explains what we can anonymise and what we cannot.

8.Getting your documents out

Before deleting anything you may need later, download it. From any document you can take the original file, the signed PDF, and the certificate of completion. From the activity page you can export the full event log as a CSV, filtered however you like.

All of that stays available while a document is in the Deleted tab, so a document deleted by mistake can still be exported while you decide whether to restore it.

9.Changes to this policy

If we change how deletion works in a way that shortens what we keep or reduces what you can recover, we will give account holders at least 30 days' notice by email before it takes effect. Clarifications and corrections are published here with the version bumped.

Questions about this policy go to support@dropthedoc.xyz. Questions about personal data go to privacy@dropthedoc.xyz.

Version history

  • Version 1.0 · 27 July 2026

    First publication.