How Long Should You Keep Read Data? Less Than You Think
Nobody deletes analytics. There is no moment in a working week when deleting last quarter’s read data feels urgent, and there is always a faint sense that it might be useful one day.
That faint sense is the problem. It is not a plan, it is the absence of one, and it is how a freelancer ends up as the custodian of two years of records describing when named people at named companies were at their desks reading things.
The useful life of read data is one deal cycle
Be specific about what this data is for. It answers one question: what should I do next about this document. Should I call, should I wait, should I rewrite the email, is this dead.
That question has an expiry date, and it is the moment the deal closes or dies. After that, a record saying somebody opened your proposal three times in March is not information. It is trivia with a name attached.
The only genuinely durable value in the pile is aggregate: how often does the first open happen, what does a document that wins look like compared with one that loses. And aggregates do not need the individual rows. You can write down the conclusion and delete the evidence.
What keeping it costs you
The costs are real and they are all invisible until the day they are not.
- It becomes something you have to secure. Data you hold is data you are responsible for. A file describing your clients’ reading habits is more sensitive than most of what is in your accounting software, and it is held with less thought.
- It becomes something you have to answer for. If a reader asks what you hold about them — a right under GDPR Article 15 for people it covers — the answer has to be assembled from whatever you kept. A short retention window makes that a two-minute email.
- It sits badly against storage limitation. GDPR Article 5(1)(e) requires personal data to be kept in identifiable form no longer than necessary for the purpose. "I might want it" is not a purpose; the purpose was the decision, and the decision was made.
- It quietly degrades. Old read data is not just useless, it is misleading. A location that was a guess in 2024 is still a guess, but by the time you look at it again the hedges that came with it have fallen off in your memory and it reads as a fact.
And on the other side of the ledger: in the entire time you have been sending proposals, how many times have you gone back to look at read data from a closed deal? For nearly everybody the honest answer is zero.
What Quixli keeps, and the default you should argue with
Vendor retention behaviour is usually described in a sentence designed not to be examined. Here it is in detail, including the part that is not flattering.
- The IP address is truncated after 30 days. The last portion of an IPv4 address and the host portion of an IPv6 one are discarded, so what remains describes a network rather than a machine. It happens on a schedule, without anyone asking for it.
- The raw event journal is deleted after 12 months. The underlying record of individual actions does not accumulate indefinitely.
- The visit records themselves are kept until you delete them. There is no automatic expiry on them. The reason is that a dashboard that silently empties itself is worse than useless — you would stop trusting it — but that is an argument about product behaviour, and a strict reading of storage limitation would not accept it. This default puts the decision on you, and you should make it rather than inherit it.
- There is a one-action erase, and it is complete. From a document’s analytics screen, the owner can delete every view session, every event and every gate capture held for that document, across every share of it — not just the link you happen to be looking at. It cannot be undone, and it cannot recall a notification or digest email that already went out. Saying otherwise would be a lie of the exact kind this article exists to avoid.
The one thing that survives everything is aggregate counts, which is the right trade: they are not about a person. The full picture of what exists in the first place is in what a tracked link collects and what it does not.
A retention routine that survives a busy month
The only routine that works is one attached to something you already do, because a calendar reminder to "review analytics retention" will be dismissed forever.
- Attach deletion to the outcome, not to the calendar. When you send the invoice, or when you mark a deal lost, erase the read data for that document. It is the moment the data stopped being able to change any decision.
- Write the conclusion down first if there is one. "Read twice, never replied, no meeting" is a sentence in your CRM. It carries everything you will ever use and none of the liability.
- Sweep quarterly for the ones that never closed. Most documents do not end with a clear event. Ninety days of no activity is a decent definition of over.
- Delete immediately if you were asked to. A client who says they would rather not be tracked has made a request, and the fastest possible compliance is the entire value of it. What to say when a client asks if you are tracking them covers the conversation around it.
- Do not keep it for a dispute. The temptation is to hold on to evidence that they read it. That data was never built to that standard, and the argument it produces is one you lose even when you are right.
The rule in one line
Keep read data for as long as it can still change what you do, and not one day longer. For almost every document that sentence resolves to weeks.
The obligations this sits inside — and the instruments they come from — are set out in consent, cookies and tracked links under GDPR, which is not legal advice and says so twice. What each plan includes covers who can see the data while you do hold it.