Retention policies #
How long uploaded files and extraction results are kept. Per-artifact, set at submission time.
Every artifact carries a retention_policy that controls how long the
uploaded file and its extraction results live in storage. The default is
30 days. Set it at submission time per-artifact, or globally per pipeline.
Available policies
retention_policy | Source file kept for |
|---|---|
immediate | Deleted as soon as extraction completes |
3h | 3 hours |
6h | 6 hours |
12h | 12 hours |
1d | 1 day |
3d | 3 days |
7d | 7 days |
30d | 30 days (default) |
90d | 90 days |
365d | 1 year |
never | Indefinite, manual delete only |
The artifact record (metadata, status, extracted JSON result) is retained longer than the source file in most policies; typically until you delete the artifact explicitly. Only the raw upload is purged on the schedule.
Setting a policy
Pass retention_policy on submit:
{
"filename": "passport-scan.png",
"artifact_type": "image/png",
"artifact_size": 921384,
"retention_policy": "immediate",
"template_id": "tpl_id_card"
}
Or as a form field on POST /artifacts/upload:
curl -u "$DD_KEY:$DD_SECRET" \ -X POST https://api.datadistillers.com/api/v1/artifacts/upload \ -F 'file=@./passport.png' \ -F 'retention_policy=immediate'
The chosen policy is stored on the artifact and visible in subsequent
GET /artifacts/{id} responses. It cannot be changed after submission;
delete and re-submit if you need a different policy.
Picking a policy
A useful starting point keyed by document sensitivity:
| Document type | Suggested policy | Rationale |
|---|---|---|
| Government IDs, passports | immediate | Reduce PII exposure window. Result JSON stays. |
| Medical records | 1d or 3d | Allows reprocessing within a workday for QA. |
| Standard invoices, receipts | 30d (default) | Covers most reconciliation cycles. |
| Audit / compliance source documents | 365d or never | Statutory retention windows usually exceed this. |
For regulated workloads (HIPAA, GDPR's "right to be forgotten"), prefer the
shortest policy that still allows your processing window, and pair it with
explicit DELETE /artifacts/{id} calls when a user requests removal.
Retention vs explicit delete
Retention is the safety net. Explicit DELETE /artifacts/{id} is the
authoritative removal; it deletes the source file, the result, and the
artifact record itself, all at once.
curl -u "$DD_KEY:$DD_SECRET" \ -X DELETE https://api.datadistillers.com/api/v1/artifacts/art_b4d8c0f1
Returns 204 No Content on success. There's no soft delete; the record is
gone the moment the call returns. Orchestrate this from your application
when a user-initiated deletion event fires (account closure, GDPR request,
etc.); don't rely on retention alone.
What happens after the policy expires
Once the source file is purged:
GET /artifacts/{id}/download?file_type=rawreturns404.GET /artifacts/{id}/download?file_type=jsonstill works as long as the artifact record exists.POST /artifacts/{id}/rerunreturns400; there's no source to re-process.- Job status APIs continue to return historical data.
If you anticipate needing to re-process, choose a longer retention policy upfront. There's no recovery once the file is gone.