Document deletion and recovery policy
What happens when you delete a document, how long you have to change your mind, what is destroyed when the window closes, and what we keep afterwards.
Contents(9)
This policy forms part of the terms of service and expands on the retention table in the privacy policy. It describes deletion inside a workspace. Closing an account or a whole workspace is covered by clause 9 of the terms.
The short version
Deleting a document does not destroy it. It moves to the Deleted tab and stays fully restorable for your workspace's recovery window, 30 days by default. After that it is destroyed for good, files included, and nobody can bring it back. The audit trail of what happened to it is kept either way.
1.What the words mean
- Delete
- Move a document to the Deleted tab. Reversible. Nothing is destroyed and no data leaves our systems.
- Restore
- Bring a deleted document back into the documents list, exactly as it was when it was deleted.
- Recovery window
- The period a deleted document stays restorable. Set per workspace, 30 days unless an admin changes it, and never shorter than 1 day or longer than 180.
- Permanent deletion
- Destroying the document, its stored files and everything attached to it. Irreversible, by us and by anyone else.
- Audit trail
- The append-only, hash-chained record of what happened to a document. Described in clause 7 and in the security overview.
2.Deleting a document
Any member of a workspace can delete a document in it. The document leaves the documents list and appears in the Deleted tab, which shows who deleted it, when, and how many days are left before it is destroyed.
Deleting is recorded in the document's activity feed and in its audit trail, with the account that did it. There is no way to delete a document quietly.
Deleting a document that is out for signature cancels it
If a document is still awaiting signatures, deleting it also cancels it: every outstanding signing link stops working immediately and recipients who have not signed can no longer do so. This is not undone by restoring the document. Restoring gives you the document back; sending it out again is a new signature request.
Signatures already collected are unaffected. A document that was completed before it was deleted is still a completed document when you restore it, with the same signed file, the same certificate of completion and the same hashes.
3.The recovery window
A deleted document stays restorable for the whole of the recovery window. During that time any member can restore it in one click from the Deleted tab, and members can still open it and download the original and signed files.
What the recovery window means in practice
Question
How long?
Answer
30 days by default. An admin can set anything from 1 to 180 days in workspace settings.
Question
Who can restore it?
Answer
Any member of the workspace. Viewers cannot.
Question
Can I still download it?
Answer
Yes. Members can download the original and, if it was completed, the signed file and certificate, for as long as it is in the Deleted tab.
Question
Can recipients still reach it?
Answer
No. Every signing link is revoked the moment the document is deleted, including on completed documents.
Question
Does it still count towards anything?
Answer
No. Deleted documents are excluded from the dashboard, search, the activity feed, reminders and expiry.
Question
What if an admin changes the window?
Answer
Documents already in the Deleted tab keep the window they were deleted under. A shorter policy never destroys something earlier than the person who deleted it was told it would be.
4.Permanent deletion
A document is destroyed permanently in one of three ways: its recovery window closes and the daily maintenance job destroys it; an admin destroys it early from the Deleted tab; or an admin empties the Deleted tab.
Only admins and owners can destroy a document before its window closes. Ordinary members can delete and restore, but cannot make anything unrecoverable. The worst a member can do is something an admin can undo.
- The document record is deleted from the database.
- Its recipients, fields, signature images and captured values go with it.
- Its activity feed goes with it.
- The original file, the signed file and the certificate of completion are deleted from encrypted object storage.
We cannot undo this, and neither can support
Files are encrypted at rest and there is no separate copy held back for recovery. Once a document is permanently deleted there is nothing left to restore, whoever asks and whatever they are willing to pay. Export anything you might need before the window closes.
Backups are a separate system with their own rotation, described in the security overview. A permanently deleted document may persist in an encrypted backup until that backup ages out on its normal cycle. Backups are never used to restore an individual document, only to recover from a disaster affecting the whole service.
5.What we delete without being asked
The only automatic destruction is the one described above: documents whose recovery window has closed. We do not delete documents because a workspace is inactive, because a plan was downgraded, or because a document is old. A document you have not deleted stays until you do.
Signing links and one-time tokens are the exception, and they are not documents: they are revoked when used, cancelled or expired, and purged on the same daily job.
6.Who can do what
Action
See the Deleted tab
Viewer
Yes
Member
Yes
Admin
Yes
Owner
Yes
Action
Delete a document
Viewer
No
Member
Yes
Admin
Yes
Owner
Yes
Action
Restore a deleted document
Viewer
No
Member
Yes
Admin
Yes
Owner
Yes
Action
Destroy one permanently
Viewer
No
Member
No
Admin
Yes
Owner
Yes
Action
Empty the Deleted tab
Viewer
No
Member
No
Admin
Yes
Owner
Yes
Action
Change the recovery window
Viewer
No
Member
No
Admin
Yes
Owner
Yes
Every one of these actions is written to the audit trail with the account that performed it, the time, and the network address it came from.
7.What survives permanent deletion
The audit trail. Nothing else.
A document's audit trail is append-only and hash-chained: each entry carries the hash of the one before it, which is what makes the record evidence rather than a list somebody could have edited afterwards. Entries are never rewritten and never removed, including when the document they describe is destroyed. What remains is the record of what happened: that the document existed, that it was sent, viewed, signed, downloaded, deleted and destroyed, by whom and when, together with the fingerprints of the files.
Why we cannot remove audit entries on request
Removing entries from a hash chain breaks it. The break is not confined to the document in question: it is the mechanism by which every other document in the workspace proves it has not been tampered with. Other parties to a signed document also have a legitimate interest in the evidence of their own signature, which is not ours to destroy on one party's request. This is the position taken by GDPR Article 17(3)(b) and (e) and the corresponding exemptions in section 17 of the DPDP Act, 2023.
The audit trail does not contain the document itself. It holds no page content, no field values, no signature images and no attachments. Those are destroyed with the document. What it holds about a person is their name, their email address, the network address they acted from, and what they did.
If you need personal data removed from an audit trail, which is a data subject request rather than a document deletion, write to privacy@dropthedoc.xyz. We handle those under clause 12 of the privacy policy, which explains what we can anonymise and what we cannot.
8.Getting your documents out
Before deleting anything you may need later, download it. From any document you can take the original file, the signed PDF, and the certificate of completion. From the activity page you can export the full event log as a CSV, filtered however you like.
All of that stays available while a document is in the Deleted tab, so a document deleted by mistake can still be exported while you decide whether to restore it.
9.Changes to this policy
If we change how deletion works in a way that shortens what we keep or reduces what you can recover, we will give account holders at least 30 days' notice by email before it takes effect. Clarifications and corrections are published here with the version bumped.
Questions about this policy go to support@dropthedoc.xyz. Questions about personal data go to privacy@dropthedoc.xyz.
Version history
- Version 1.0 · 27 July 2026
First publication.