Read-only is not possession: what happens to your data when you stop paying
Most vendors keep your history readable and block new records, but only one documents export. The vendor-by-vendor record and the test to run on day one.
Subscription software gates writes long before it gates reads, so the first thing you lose when a payment stops is the ability to create records, not the ability to see them. That is the reassuring half. The unreassuring half is that seeing a signed contract inside someone else's product is not the same as holding it, and the difference only becomes expensive on the day a client disputes an invoice or a tax office asks for the file.
This post audits what eleven vendors publish about that moment, using their own help pages. It is not legal advice; the retention rules at the end are jurisdictional and you should check yours.
Where it is documented at all, the pattern is retain and restrict
Nobody in this set publishes a policy of deleting your history the moment you stop paying. The documented behaviour is consistent enough to state as a rule: new-record creation is blocked, existing records stay readable. Bonsai calls the resulting state "Limited" and describes it as "view-only for core business operations" — you cannot create or send new invoices, proposals or contracts, but you can still view every existing document, manage clients and projects, and track time. HoneyBook says the same thing in different words: after cancellation "you'll still have access to all existing projects and information, but you will no longer be able to create new files, projects, or send messages," and separately that "canceling won't delete your account." Harvest is blunter still: "Everything you've already tracked stays in your account. The limits apply to what's active."
So the common fear, that cancelling wipes five years of client history, is not what the documentation describes. Read that first, then read where the pattern breaks. It breaks in three places: what has to happen before the vendor will let you downgrade, whether there is a deletion clock running behind the read-only screen, and whether anything you can see can also be taken out.
What each vendor publishes, and what three of them don't
Vendor | Documented on downgrade or cancellation | Export addressed? | Source |
|---|---|---|---|
Bonsai | Drops to "Limited": no new invoices, proposals or contracts; all existing documents viewable; clients, projects, time and expenses still editable | Yes — settings include "exporting/importing account data" | |
HoneyBook | Read-only: existing projects and information accessible, no new files, projects or messages. "Canceling won't delete your account" | No | |
Harvest | Tracked data stays; limits apply to what is active. You must archive down to 1 person and 2 projects before the switch is allowed; integrations disconnect | No | |
Toggl Track | Over the free user quota with a lapsed subscription, the organization is suspended: new time tracking blocked, Reports and Team page still work. Free-plan data "automatically deleted after 6 months of inactivity" | No | |
FreshBooks | Reduce active and archived clients, remove team members and accountants, end retainers before downgrading. After cancellation data "will remain intact and preserved," but "accounts that are inactive for 30 days or more may be deactivated and deleted" | Partly — tells you to "save any data you need" and links out; the cancellation page itself sets out no route | |
Indy | Creation blocked once the monthly free allowance is used; limits do not roll over to the next cycle | No | |
Wave | Legacy free businesses: "As of June 1, 2026, your collaborators will not be able to access your account" without Pro | No | |
Dubsado | Not published | Not published | — |
Moxie | Not published | Not published | — |
Zoho (Invoice / Books) | Not published | Not published | — |
Worklyn | No published policy for what happens to records on downgrade to Free | Yes — the privacy policy documents a self-service Export Data ZIP: clients, projects, tasks, time logs, expenses, proposals, invoices, contracts, portal history and profile as JSON, plus every uploaded file. Account deletion is a hard delete |
Four things in that table are worth saying out loud.
Bonsai is the only vendor here that explicitly keeps export available after you stop paying. Everyone else either stays silent on export or, in FreshBooks' case, tells you to save your data and sends you elsewhere for the instructions.
Toggl is the only one publishing a deletion clock. Six months of inactivity on a free plan and the data goes. Every other vendor's silence on deletion is silence, not a promise.
Harvest and FreshBooks both make you destroy state before they let you downgrade. Harvest wants you archived down to one person and two projects; FreshBooks counts archived clients against the billable-client cap, so archiving is not the workaround it looks like. That is work done under time pressure, at the exact moment your attention is on the bill.
Dubsado, Moxie and Zoho publish nothing. No page describes post-trial or downgrade data access. That is what a buyer finds when they look, and three of eleven is a lot of the category.
Read-only access is not possession
The distinction vendors rarely draw is between access and possession. Read-only access means the record exists on a screen you can still log into, on terms the vendor sets and can change. Possession means the file is on your disk, in a format something other than that vendor can open.
They diverge in the ordinary cases. A client disputes a €4,800 invoice fourteen months after it was paid, and you need the signed acceptance and the original line items in something you can attach to an email. An accountant asks for last year's expense records as a file, not a login. In each of those, what settles it is a document you can produce. A record you can look at but not extract settles nothing.
Format matters as much as availability, and it is a live variable rather than a fixed one. Clockify's own update to its free plan, published 20 May 2026, removed CSV and Excel export from Free and left PDF only. PDF is a picture of your data. It satisfies "you can export" and fails "you can import this somewhere else," which is the property you actually needed. Migration paths run on the file, not the button: the Midday import route works from an export zip, and what makes that route possible is that the zip is structured enough for another product to read.
A related test applies to any document you might have to reproduce: can you generate it without an account at all? Worklyn's in-browser invoice generator and the rest of the free PDF tools run locally in the browser, no signup and no watermark. If producing a document requires an active subscription somewhere, your ability to produce it is a billing status.
Run the export on day one of the trial, not on the day you leave
Treat this as a procedure, not a worry. The test costs about twenty minutes of a trial that runs 7 to 30 days, and you want the answer before you have entered enough real data to be trapped by it.
DAY-ONE EXPORT TEST — run during the trial, before payment details go in1. Create one of each: client, invoice, contract, signed document, time entry.→ Tests the full record set, not just the easy one. Most tools exportinvoices cleanly and lose contracts.→ Bad answer: you cannot create a signed document without upgrading, soyou cannot test the thing most likely to matter later.2. Find the export without contacting support. Give yourself 10 minutes.→ Tests whether export is a product feature or a favour.→ Bad answer: the only route is a support ticket. A vendor that makes youask has told you the export is discretionary.3. Download it and open it outside the vendor's product.→ Tests format, not existence.→ Bad answer: PDF only, or a report rendered for printing. Good answer:CSV or JSON you can open in a spreadsheet or load into another tool.4. Check the attachments. Did the uploaded files come with it?→ Tests whether receipts, deliverables and scans travel with the records.→ Bad answer: a manifest listing files that are not in the archive.5. Check the signed contract. Is the signature and its audit trail included,or only the document text?→ Tests evidentiary value. A contract without the execution record is adraft, and a draft proves nothing in a dispute.6. Check history. Are superseded versions, edited invoices and paid/voidstatus in there, or only the current state?→ Tests whether you can reconstruct what happened, not just what is true now.→ Bad answer: current state only. Amendments are exactly what gets disputed.7. Search the help centre for "cancel" and "downgrade". Read what it saysabout data before you need it to say something.→ Bad answer: nothing comes up. See three of the eleven vendors above.8. Diary a repeat of steps 2-4 every six months while you are a customer.→ Free tiers and export formats get tightened, not loosened. Clockify'sFree plan lost CSV and Excel export in May 2026.
Line 2 predicts the rest. An export that lives in account settings is a feature the vendor maintains and tests. An export that arrives from a support agent within five business days is a manual process, and it will be slowest exactly when the most people want it, which is during a shutdown or a price change.
Your retention obligation does not pause when your subscription does
This is the part that turns a software question into a compliance one. You are required to keep business records for a fixed period regardless of which tool you used to create them, and no vendor's read-only screen is a defence.
In the UK, if you are self-employed, HMRC's position is that "you must keep your records for at least 5 years after the 31 January submission deadline of the relevant tax year." For a 2025/26 return filed by 31 January 2027, that runs to at least the end of January 2032. Five years is longer than most people stay with one piece of software.
In the EU there is no single figure, and the reason is structural. The VAT Directive requires taxable persons to ensure invoices are stored, but Article 247(1) states that "Each Member State shall determine the period throughout which taxable persons must ensure the storage of invoices" — see the consolidated directive on EUR-Lex. So the number is national and you have to look yours up. What is common across all of them is that the obligation is yours, sits with you rather than with your software, and outlasts the subscription.
Then there is GDPR Article 20, which gets cited in this discussion more confidently than it deserves. The actual text gives the data subject "the right to receive the personal data concerning him or her, which he or she has provided to a controller, in a structured, commonly used and machine-readable format," where the processing is based on consent or on a contract and is carried out by automated means. Read the qualifiers. It covers personal data concerning that individual that they provided; it is a right of a natural person, exercised against a controller. In a normal B2B SaaS arrangement you are the controller of your clients' data and the vendor processes it for you, which means Article 20 is more naturally something your clients can invoke against you than a lever you pull to extract a whole business account. Article 20(4) adds that the right "shall not adversely affect the rights and freedoms of others," which is directly relevant when the export you want is full of other people's personal data.
Article 20 reaches your own personal data as an account holder, on those conditions. It is not a statutory guarantee of a complete export of your invoices, contracts and client history. Plan on the product feature and the contract you signed, not on the regulation.
What to change this week
- Run the eight-line export test on the tool you already pay for. Not on a trial you are considering — on the one holding your live client history. If step 2 fails, you have found the problem while nothing is on fire.
- Put the export on a calendar, twice a year, and store it where your accountant can reach it. A structured export sitting in your own storage converts a retention obligation from a dependency into a file. It also makes the annual expense reconciliation described in the deductions post an exercise in reading your own records rather than logging into a former vendor's.
- Before your next renewal, read that vendor's cancellation page. If it does not exist, treat the export test result as the whole answer, and price the migration cost into the renewal. The companion audit of what free plans actually cap covers the same vendors from the other end, and what invoicing software actually changes covers what you are paying for in the first place.
Worklyn keeps signed documents in the same account as the invoices they support through its contracts and e-signature workspace, and the Export Data ZIP described in the privacy policy takes all of it out as JSON plus the original files. What happens to records specifically on a downgrade to Free is not documented on the site today, which is the honest answer and the same one this post asked of everyone else.