LynBro Plugins
/ Data Retention
Most sites have a privacy policy that says data is kept “only as long as necessary”, and a database with contact form entries from 2018 in it. The policy is not the problem. The problem is that nobody can say where the data actually is — so nothing ever gets removed. This starts by telling you.
Free forever. No account, no card, no quota — scheduled runs included. Makes no external requests of any kind.
of the largest Danish data protection fines were for keeping data too long, not for collecting it.
Article 30 asks what personal data you hold. Almost nobody can answer, because it is spread across a dozen plugins’ tables under names their authors chose. The scan reads your database and answers it: what, where, how many records, and how old the oldest one is.
WooCommerce can clear old orders and inactive accounts. Nothing clears form entries from Contact Form 7, WPForms, Gravity, Fluent, Formidable, Forminator, Everest or Elementor; comments held as spam with the sender’s address and IP attached; the login and firewall logs of every security plugin; visit tables from analytics plugins; or the table left behind by a plugin uninstalled three years ago.
So nothing here happens by accident. Activation creates no rules. Saving a rule deletes nothing. Running one needs a dry run you have read, then a word typed by hand — and the first time a rule deletes, everything it removes is written to a backup file first. If that file cannot be written, the deletion is cancelled.
No "Pro" tier, no nag screens. The features other plugins paywall are here from day one.
Every place personal data was found, by column name and — where the name says nothing — by looking at a few recent values. E-mail, names, phones, addresses, IP, device, dates of birth, payment details, Danish CPR numbers and the special categories of Article 9.
Nothing sampled during the scan is stored. Only the conclusion that a column holds, say, e-mail addresses.
“21 records in the anti-spam log are older than 3 September and would be removed. The oldest is from 28 August.” Five masked examples. Then, and only then, a confirmation.
Keep the row, the date and the count, and remove the person. The right answer for visit logs and statistics, where the numbers still matter and the visitor does not.
What, when, under which rule, how many records, how old the oldest was, and who started it — dry runs and refusals included. Each entry carries the hash of the one before it, so a later edit shows. Export as CSV.
Danish bookkeeping law keeps accounting records five years past the financial year. Rules shorter than that are refused on those sources. Satisfying one law by breaking another is not compliance.
Tools → Erase Personal Data only reaches what plugins registered themselves, and most never did. Everything the scan found is registered, so a request stops quietly reporting success while the messages stay put.
The scan fills in what it can see — the data, the volumes, the retention. You add the purpose and the legal basis. Export the whole thing as CSV.
What sites actually reach for when retention comes up, and where each one stops.
| Feature | Lynbro Data Retention | WooCommerce built-in | GDPR checklist plugins |
|---|---|---|---|
| Tells you where personal data actually is | ✓ | — | — |
| Covers form entries, comments, plugin logs, analytics | ✓ | — | — |
| Dry run with counts before anything is removed | ✓ | — | — |
| Backup written before the first deletion | ✓ | — | — |
| Tamper-evident deletion journal | ✓ | — | — |
| Scheduled automatic removal | ✓ | ✓ | — |
| Orders and accounts | — | ✓ | — |
| Article 30 record started from real data | ✓ | — | — |
Not without being told to, twice. Activation creates no rules. Saving a rule deletes nothing. Running one requires a dry run first, then a confirmation you have to type out — and the first time a rule deletes, everything it removes is written to a backup file. If that file cannot be written, the deletion is cancelled.
No. Orders are shown on the map and never swept. They are accounting records, and WooCommerce has its own retention settings for the parts that can be trimmed.
Deleting removes the record. Anonymising keeps the row, the date and the count and replaces the personal columns, so your statistics still add up and the person is gone. Use anonymising for visit logs; use deleting for messages somebody sent you.
Yes. It works in chunks with a time budget and picks up where it left off, and deletions never do more than a few hundred rows per pass. A very large table takes several scheduled runs to trim the first time, which is deliberate.
No. The backup here covers exactly the rows one rule is about to remove, for thirty days, and then deletes itself — because a backup of personal data is personal data. Keep your normal backups.
Yes, and this is not one. A banner is about what may be written to a visitor’s device before they agree. This is about what is already in your database and how long it stays there. Lynbro Cookie Consent is the other half.
No. It is a tool. It shows you what your database holds and removes what you tell it to. How long you may keep something is your decision, and for anything difficult, your lawyer’s.