Product FeatureSecurity

Data Retention Window: Share Sensitive HTML Without Leaving a Trace

HTMLvault Team·June 15, 2026·7 min read

The Problem with Content at Rest

Most secure sharing tools focus on access control: who can view, when, for how long. That's necessary, but for some content, it's not sufficient. The moment a document sits on a server—any server—it becomes a liability. It can be subpoenaed. It can be breached. It can show up in an audit you didn't anticipate.

Angela Pruitt, the controller at Synergetics Worldwide, keeps a binder tab labeled "content that outlived its usefulness." The whole point of a retention policy is to keep that tab thin.

For certain use cases, the only acceptable posture is ephemeral sharing: the content exists just long enough to be consumed, then it's gone. Not archived. Not soft-deleted. Purged.

HTMLvault's Data Retention window is designed for these scenarios: every account already has one, and it permanently deletes your HTML from our infrastructure once a link's expiration passes and the window elapses afterward.

Who This Is For

The Data Retention window serves users who share content that's too sensitive to persist:

  • M&A deal teams sharing term sheets or LOIs with outside counsel
  • Sales reps sending custom pricing that includes confidential margin data
  • HR and recruiting distributing compensation benchmarks or candidate evaluations
  • Healthcare and legal teams sharing documents containing PII or PHI
  • Security teams distributing incident reports or vulnerability disclosures

If your IT or legal stakeholder has ever asked "where does this data live after it's shared?"—this feature gives you a concrete answer: nowhere, once the window closes.

How It Works

Data Retention works in two stages. First, your link's own expiration passes and it stops being viewable—that's per-link, set the same way you always set it (dashboard, API, or any integration). Second, once your account's Data Retention window elapses on top of that expiration, HTMLvault permanently deletes the underlying HTML. There's nothing extra to turn on: every account already has a Data Retention window (90 days by default), and it applies automatically to any link that has an expiration set.

You control two things:

  • The link's expiration — when it stops being viewable (e.g., "expires after 72 hours")
  • Your account's Data Retention window — how long after that expiration the content is kept before it's purged. Every plan can set this as short as 7 days; Pro and above can also choose 1 or 2 years if they'd rather keep expired content recoverable

Once your Data Retention window elapses past the link's expiration, our system permanently deletes the HTML payload. The link record remains, and its aggregate view counters survive—but the per-visitor view details (geo, device, referrer, scroll depth, time on page) are deleted along with the content, and none of it is recoverable, by you, by us, or by anyone.

Four-stage lifecycle of an HTMLvault link, from upload to retention purge Lifecycle of a link under the data retention window STAGE 1 STAGE 2 STAGE 3 STAGE 4 Upload HTML Set an expiration Live Viewable, tracked Expired Not viewable Purged Counts kept, HTML gone
The purge is a second clock: expiry only closes the door, and the HTML stays on disk until the account's data retention window runs out on top of it.

How to Configure the Data Retention Window

Every account already has a Data Retention window—90 days by default—so there's nothing to turn on. What you configure is how long it is, and which links it applies to:

  1. Go to Settings → Defaults and find the Data retention control near the bottom of the page
  2. Choose how long expired content should be kept before it's purged: 7, 30, or 90 days on any plan, or 1 or 2 years on Pro and above if you'd rather keep it recoverable. On Free, the longer options are marked "(Pro)" and open an upgrade prompt rather than selecting
  3. Click Save. Save and Cancel appear only once you've changed the value, and a green "Saved." confirmation follows. The window applies account-wide, to every link you own
  4. Give any link you want purged an expiration—from the dashboard, the API, or an integration (Claude, Zapier, Clay, etc.). Links with no expiration are never purged

Via the API, this just means setting the expires_at parameter on the link as usual. Once that expiration passes and your account's Data Retention window elapses on top of it, HTMLvault purges the HTML payload automatically—no additional call required. On Enterprise, retention is set centrally as org policy, so the control doesn't appear on the member's own settings page at all.

Mockup of the Data retention control on the Settings Defaults page Settings → Defaults: Data retention Data retention Pro How long after a link expires before its HTML content and view details are deleted. Aggregate view counts are always preserved. 30 DAYS Save Cancel Saved. 1 Options: 7 days, 30 days, 90 days, 1 year (Pro), 2 years (Pro) Save, Cancel and the confirmation appear only after you change the value.
One account-wide Data retention setting governs every link you own—there is no per-link retention toggle, and on Enterprise the card is hidden because the org sets the policy centrally.

Worked Example: Angela's Compensation Proposal

Angela Pruitt needs to send a candidate a custom compensation package. The HTML includes base salary, equity grant details, and internal band comparisons—information that should never persist longer than necessary, and precisely the kind of thing she'd rather not explain to outside counsel two years from now.

Her account's Data Retention window is already set to the shortest option, 7 days. She creates an HTMLvault link with these settings:

  • Expiration: 72 hours
  • Password protection: enabled (shared via a separate channel)

The candidate views the proposal twice over the next day. At the 72-hour mark, the link expires: the candidate—or anyone else who was forwarded the URL—can no longer view it. The HTML itself isn't gone yet. Seven days later, once the Data Retention window elapses on top of that expiration, HTMLvault permanently purges the payload. From that point there's no HTML at rest for Legal to ask about—just the link's aggregate view count, which is the only number Angela wanted to keep anyway.

Timeline of a compensation proposal link from creation through expiry to purge Compensation proposal: 72-hour expiry, 7-day retention LINK TIMELINE View 1 View 2 Expires Purged 0 H 24 H 72 H +7 DAYS Viewable and tracked Retention window
Two views land inside the first day, but the payload survives the expiry by a full week—sizing the retention window is what decides how long that gap stays open.

Limits and Caveats

Before relying on the Data Retention window, understand the tradeoffs:

  • Irreversible — once purged, the content cannot be recovered. There is no undo, no backup. If you need the HTML again, you must re-upload it.
  • Aggregate counts persist, everything else doesn't — view counts survive the purge. Per-visitor detail—geo, device, referrer, scroll depth, time on page—is deleted along with the content, not retained.
  • No caching guarantees downstream — HTMLvault deletes data from its own infrastructure. We cannot control browser caches, proxy caches, or screenshots taken by viewers.
  • Not purged the instant a link expires — expiring a link makes it inaccessible immediately, but the underlying HTML stays in place until your account's Data Retention window elapses afterward (as short as 7 days, on any plan). Only Pro and above can extend that window, to 1 or 2 years, for content they'd rather keep recoverable.
  • A constraint is required — the purge only applies to links with an expiration set. Links configured to never expire are never purged.
  • It's an account-level setting, not a per-link one — changing the window changes it for every link you own. On Enterprise the window is set as org policy, so individual members won't see the control.

Why This Matters

Sales and recruiting teams regularly share content that's sensitive enough to warrant access controls but not sensitive enough to justify a full secure data room. Without a defined retention window, that means accepting risk: the content sits on a server, and you hope nothing goes wrong.

Configuring a Data Retention window changes the calculus. The compliance lead who sends a comp proposal now has a defensible answer when Legal asks about data persistence. The sales rep sharing custom pricing doesn't have to wonder whether that margin data will surface in a breach three years from now. And IT has an auditable, policy-enforceable posture to point to—not just a verbal assurance.

Ephemeral sharing on its own isn't new. Getting it alongside analytics, password protection, PII scanning, and white-labeling—inside a tool that IT already approved—is what makes it practical at scale.

Product Featuredata retentionsecuritycompliancesensitive dataephemeral sharing
HTMLvault

Share HTML securely — without losing your job.

The enterprise-grade platform for sharing HTML pages, reports, and dashboards with full PII scanning, access controls, and audit trails.

Start for free

Related Posts