Data persistence and privacy
PubNub stores only the data your application publishes or writes to a feature you've enabled on your keyset. The storage systems themselves are described in Data storage. This page covers the policy side of that storage:
- where each data type lives
- how long it stays
- who can delete it
- what personal data to keep out of it
- how PubNub's certification, audit reports, compliance frameworks, and data-subject request process apply
It doesn't cover encryption or Access Manager. Those control confidentiality and access rather than storage or retention.
Storage, region, and retention by system
Storage can be locked to EU-only, US-only, or APAC-only regions. Each storage system has its own region and retention rules, and you control both per keyset.
| Storage system | Where it's stored | How long data stays |
|---|---|---|
| Message Persistence | Replicated across PubNub's regions for availability | Message Persistence retention is 1 or 7 days on the Free plan, 30 days, 3 months, or 6 months on Starter, and 1 year or Unlimited on Pro, set per keyset. Testing keysets default to 7-day retention. |
| App Context | A single region you choose when you enable the feature. You can't change the region after saving | No retention setting. A record persists until you remove it, or until a cascading delete removes it |
| Files | A single region you choose when you enable the feature. You can't change the region after saving | Set per keyset, independent of Message Persistence retention. See Files configuration for the available windows |
| Channel groups, mobile push registrations, Functions key-value data, and revoked Access Manager tokens | Not customer-selectable | Varies by system. See Data storage and Data deletion options |
Retention is a setting you control, not a cleanup schedule PubNub runs for you. Changing a keyset's retention only applies going forward. Data already in storage keeps the retention period it was stored under, and new data uses the updated one.
Deletion
Most data types support self-service removal. Use either an SDK method scoped to that data type, or the Admin Portal and BizOps Workspace. BizOps Workspace is the no-code console for managing the same user, channel, and membership records.
For example, you remove an App Context record with that entity's remove operation, one of the four operations every App Context entity supports. For the exact method or API call for each data type, refer to Data deletion options.
Some deletions take effect on a delay rather than immediately. A revoked token's deny-list entry persists until the token's original TTL would have expired. See Grant, change, and revoke permissions. For data you can't reach yourself through the SDK or Admin Portal, contact PubNub support.
Personal and sensitive data
Some fields are visible to other clients or to downstream features, so keep personal or confidential values out of them:
- User ID. Visible to other clients through Presence, message attribution, and App Context. Don't use an email address, a username, or other personally identifiable information as a User ID. Use a revocable, non-identifiable value instead. See User ID.
- App Context custom fields. If you map a
customfield on a user, channel, or membership record into Illuminate for analytics, avoid personal information such as an email address or an IP address. Illuminate reads and stores whatever you map into it.
Keep personal data out of the User ID and App Context fields in the first place, and you have less to locate and remove later.
Compliance
PubNub is ISO 27001 certified, SOC 2 Type II and SOC 3 audited, and HIPAA, GDPR, and CCPA compliant. PubNub also participates in the EU–U.S. Data Privacy Framework (DPF). For the certificate and audit reports, visit the PubNub Trust Center. Pro plan customers can access the most recent reports directly from the Admin Portal, under Organization settings. Other customers can request them from PubNub Compliance.
PubNub's certification, audit reports, and compliance frameworks describe PubNub's own infrastructure and controls. Whether your specific application meets a regulation such as HIPAA or GDPR also depends on choices you make on top of PubNub. These include your retention settings, your use of Access Manager, and your use of message and file encryption.
Data-subject and privacy requests
To ask about access to, correction of, or deletion of personal data processed through PubNub, or other privacy questions, contact PubNub Compliance.
Related resources
- Data storage. The four storage systems, what each one stores, and how to choose between them.
- Data deletion options. The exact method or API call to delete each data type.
- Security. Access Manager and encryption, which control who can reach your data and whether PubNub can read it.