Data Safety and Recovery
Two promises underpin everything else in this section: your data stays, and service comes straight back.
Nothing is deleted
An expired subscription pauses service. It does not remove anything.
| Preserved | |
|---|---|
| Your organization and its settings | Yes |
| All user accounts | Yes |
| All surveys | Yes |
| All published survey versions | Yes |
| All responses and answers | Yes |
| All uploaded files | Yes |
| All field tasks and their history | Yes |
| All public survey links and viewer links | Yes |
| All orders, invoices, and payments | Yes |
| Your full subscription history | Yes |
There is no deletion timer, no automatic archiving, and no point at which expiry alone starts discarding your content. Any contractual data-retention or deletion policy is a separate agreement with your platform provider and is never implied by expiry.
Blocked work leaves nothing half-finished
When an action is refused because the subscription has lapsed, Survanta checks the subscription before touching any data. A refused request therefore produces:
- No partly created response, and no answers left without a response
- No file record without a file, and no file left in storage without a record
- No field task marked complete, and no completion time or actor recorded
- No partial review step, no revision increase, and no audit entry
- No consumed idempotency key, so your queued work is still retryable
- No revoked or replaced links
This has been verified directly: a full snapshot of the database was taken while active, a round of file uploads, field task completions, review transitions, web submissions and public submissions was attempted while expired, and a second snapshot was taken. The two snapshots were identical.
Recovery is immediate
Once a renewal is applied, service resumes at once. There is no processing delay and no waiting period.
Nothing below is required just because the subscription lapsed and was renewed:
| Not required | |
|---|---|
| Restarting the application or asking your provider to restart a service | Not required |
| Signing out and signing back in on the website | Not required |
| Signing out and signing back in on the mobile app | Not required |
| Getting a new mobile app token | Not required |
| Creating a replacement public survey link | Not required |
| Creating a replacement viewer link | Not required |
| Waiting for a cache or timer to clear | Not required |
Verified in practice: a browser session, a mobile app token, a public survey link, and a viewer link — all created before the expiry — each resumed working immediately after the renewal was applied, in the same running system.
Ordinary credential expiry remains separate. If a sign-in session or a mobile token has passed its own lifetime, the usual sign-in rules apply — but that has nothing to do with the subscription.
What to tell your team
If your organization's subscription lapses:
- Nothing is lost. Keep working offline in the field if you were already doing so; queued responses are safe and will sync once service resumes.
- Do not sign anyone out and do not reinstall the mobile app. Neither helps, and both risk confusion.
- Do not recreate survey links. The ones you distributed will work again.
- Renew. An administrator, or a member with billing permission, can reach the renewal flow at any time — those pages stay open specifically so that recovery is always possible.
- Everything resumes the moment the renewal is applied.