Where it is: Settings → Privacy & Data for retention and the wording; visitors’ requests wait in ChatFlint → Inbox → Data requests.
Article 17 of the GDPR gives people the right to have their data erased, and Article 5 says you should not keep it longer than you need it. These two screens are how the plugin lets you honour both.
Visitor requests
A visitor can request erasure from inside the chat, by email address or for the current session only. Requests land in Data Requests for you to approve. Approving erases the transcript, the lead, ratings and any uploaded files.
Automatic retention
Set a retention period and conversations, ratings and leads older than that are deleted nightly. IP addresses are truncated before they are ever stored.