The Problem with Content at Rest
Most secure sharing tools focus on access control: who can view, when, for how long. That's necessary, but for some content, it's not sufficient. The moment a document sits on a server—any server—it becomes a liability. It can be subpoenaed. It can be breached. It can show up in an audit you didn't anticipate.
Angela Pruitt, the controller at Synergetics Worldwide, keeps a binder tab labeled "content that outlived its usefulness." The whole point of a retention policy is to keep that tab thin.
For certain use cases, the only acceptable posture is ephemeral sharing: the content exists just long enough to be consumed, then it's gone. Not archived. Not soft-deleted. Purged.
HTMLvault's Data Retention window is designed for these scenarios: every account already has one, and it permanently deletes your HTML from our infrastructure once a link's expiration passes and the window elapses afterward.
Who This Is For
The Data Retention window serves users who share content that's too sensitive to persist:
- M&A deal teams sharing term sheets or LOIs with outside counsel
- Sales reps sending custom pricing that includes confidential margin data
- HR and recruiting distributing compensation benchmarks or candidate evaluations
- Healthcare and legal teams sharing documents containing PII or PHI
- Security teams distributing incident reports or vulnerability disclosures
If your IT or legal stakeholder has ever asked "where does this data live after it's shared?"—this feature gives you a concrete answer: nowhere, once the window closes.
How It Works
Data Retention works in two stages. First, your link's own expiration passes and it stops being viewable—that's per-link, set the same way you always set it (dashboard, API, or any integration). Second, once your account's Data Retention window elapses on top of that expiration, HTMLvault permanently deletes the underlying HTML. There's nothing extra to turn on: every account already has a Data Retention window (90 days by default), and it applies automatically to any link that has an expiration set.
You control two things:
- The link's expiration — when it stops being viewable (e.g., "expires after 72 hours")
- Your account's Data Retention window — how long after that expiration the content is kept before it's purged. Every plan can set this as short as 7 days; Pro and above can also choose 1 or 2 years if they'd rather keep expired content recoverable
Once your Data Retention window elapses past the link's expiration, our system permanently deletes the HTML payload. The link record remains, and its aggregate view counters survive—but the per-visitor view details (geo, device, referrer, scroll depth, time on page) are deleted along with the content, and none of it is recoverable, by you, by us, or by anyone.
How to Configure the Data Retention Window
Every account already has a Data Retention window—90 days by default—so there's nothing to turn on. What you configure is how long it is, and which links it applies to:
- Go to Settings → Defaults and find the Data retention control near the bottom of the page
- Choose how long expired content should be kept before it's purged: 7, 30, or 90 days on any plan, or 1 or 2 years on Pro and above if you'd rather keep it recoverable. On Free, the longer options are marked "(Pro)" and open an upgrade prompt rather than selecting
- Click Save. Save and Cancel appear only once you've changed the value, and a green "Saved." confirmation follows. The window applies account-wide, to every link you own
- Give any link you want purged an expiration—from the dashboard, the API, or an integration (Claude, Zapier, Clay, etc.). Links with no expiration are never purged
Via the API, this just means setting the expires_at parameter on the link as usual. Once that expiration passes and your account's Data Retention window elapses on top of it, HTMLvault purges the HTML payload automatically—no additional call required. On Enterprise, retention is set centrally as org policy, so the control doesn't appear on the member's own settings page at all.
Worked Example: Angela's Compensation Proposal
Angela Pruitt needs to send a candidate a custom compensation package. The HTML includes base salary, equity grant details, and internal band comparisons—information that should never persist longer than necessary, and precisely the kind of thing she'd rather not explain to outside counsel two years from now.
Her account's Data Retention window is already set to the shortest option, 7 days. She creates an HTMLvault link with these settings:
- Expiration: 72 hours
- Password protection: enabled (shared via a separate channel)
The candidate views the proposal twice over the next day. At the 72-hour mark, the link expires: the candidate—or anyone else who was forwarded the URL—can no longer view it. The HTML itself isn't gone yet. Seven days later, once the Data Retention window elapses on top of that expiration, HTMLvault permanently purges the payload. From that point there's no HTML at rest for Legal to ask about—just the link's aggregate view count, which is the only number Angela wanted to keep anyway.
Limits and Caveats
Before relying on the Data Retention window, understand the tradeoffs:
- Irreversible — once purged, the content cannot be recovered. There is no undo, no backup. If you need the HTML again, you must re-upload it.
- Aggregate counts persist, everything else doesn't — view counts survive the purge. Per-visitor detail—geo, device, referrer, scroll depth, time on page—is deleted along with the content, not retained.
- No caching guarantees downstream — HTMLvault deletes data from its own infrastructure. We cannot control browser caches, proxy caches, or screenshots taken by viewers.
- Not purged the instant a link expires — expiring a link makes it inaccessible immediately, but the underlying HTML stays in place until your account's Data Retention window elapses afterward (as short as 7 days, on any plan). Only Pro and above can extend that window, to 1 or 2 years, for content they'd rather keep recoverable.
- A constraint is required — the purge only applies to links with an expiration set. Links configured to never expire are never purged.
- It's an account-level setting, not a per-link one — changing the window changes it for every link you own. On Enterprise the window is set as org policy, so individual members won't see the control.
Why This Matters
Sales and recruiting teams regularly share content that's sensitive enough to warrant access controls but not sensitive enough to justify a full secure data room. Without a defined retention window, that means accepting risk: the content sits on a server, and you hope nothing goes wrong.
Configuring a Data Retention window changes the calculus. The compliance lead who sends a comp proposal now has a defensible answer when Legal asks about data persistence. The sales rep sharing custom pricing doesn't have to wonder whether that margin data will surface in a breach three years from now. And IT has an auditable, policy-enforceable posture to point to—not just a verbal assurance.
Ephemeral sharing on its own isn't new. Getting it alongside analytics, password protection, PII scanning, and white-labeling—inside a tool that IT already approved—is what makes it practical at scale.
