This is the current internal text while cofounder/legal review and missing operator/provider facts are completed. It is not an effective public policy.
Approved product-policy baseline; draft for cofounder and legal review; not approved for external publication Owner: Eugene Effective for implementation planning: 26 August 2026 Updated: 26 September 2026 Review cadence: before first external pilot, after provider/data-flow change, after material incident, and at least annually
1. Principles
- Keep identifiable data only for a documented product, security, financial, legal, or user-request purpose.
- A paid deliverable and the raw evidence needed to support it remain available while the account is open, including read-only periods.
- Verified account deletion removes product history; it does not erase the minimum records required for payment, tax, disputes, opt-out, eligibility enforcement, or deletion audit.
- Do not preserve redundant captures, unrestricted logs, or contact fields merely because storage is available.
- A shorter mandatory period controls. A documented legal hold extends only the affected records and is reviewed at least every six months.
- Pseudonymised data is still personal data when re-identification remains reasonably possible. Only irreversible aggregation/anonymisation leaves the personal-data schedule.
2. Schedule
| Record class | Trigger | Retention | End action | Minimum retained fields / notes |
|---|---|---|---|---|
| Free-only account and clinic input | Last user activity, no paid order | 12 months + 30-day notice | Delete unless reactivated | Preserve only keyed eligibility/suppression token if needed |
| Paid account and clinic ground truth | Account open | No inactivity auto-deletion in MVP | Delete after verified account deletion | Paid outputs must remain accessible while account is open |
| Delivered Quick Scan/Baseline/Fix Pack/Monitoring output | Account open | Life of account | Delete from active systems within 30 days after verified deletion | Legal/financial records remain separate |
| Canonical raw evidence supporting a delivered output | Output retained | Same as output | Delete with output | Required for traceability and correction |
| Duplicate capture, cache, temporary screenshot, working export | Delivery/QA complete | 30 days maximum | Delete | Promote only canonical evidence before expiry |
| Privacy export archive and signed link | Export generated | 7 days maximum | Delete/expire; earlier after first download where practical | Retain request audit, not archive contents |
| Support message/metadata | Ticket closed | 24 months | Delete or anonymise | Ticket ID, status, timestamps, category |
| Support attachment | Latest support response | 30 days | Delete | A later response restarts the clock |
| Auth/session record | Session/provider lifecycle | Provider-defined minimum | Expire/revoke | Exact provider rule required before launch |
| Security/access log | Event created | 180 days | Delete or irreversibly aggregate | No report content or PHI in logs |
| Rate-limit, retry, idempotency, queue-delivery trace | Event completed | 30 days | Delete | Keyed identifiers only where possible |
| Abandoned/failed checkout trace | Last activity | 30 days | Delete | Payment provider may have its own disclosed period |
| Transactional-email delivery, bounce, complaint metadata | Event created | 180 days | Delete or aggregate | No detailed report finding in email |
| Marketing opt-out/suppression | Opt-out or complaint | Life of service + 12 months | Delete when no longer needed | Minimum email or keyed hash and reason/date |
| One-free-scan eligibility token | Scan accepted | Life of Quick Scan programme + 12 months | Delete | Keyed non-reversible email token; no report/content |
| Event-level product analytics | Event created | 180 days | Delete or irreversibly aggregate | No URL/email/payment/PHI/free-text payloads |
| Genuinely anonymous funnel/quality/cost aggregate | Irreversible aggregation | No fixed expiry | Periodic usefulness review | Must not permit account/person reconstruction |
| Payment, invoice, tax, refund, dispute, chargeback record | Later of transaction or account closure | 7 years | Delete unless hold applies | Internal deleted-user ID; identifying invoice fields only when needed |
| Contract/order/Terms/Privacy acceptance and material consent | Contract/order ends | 6 years | Delete unless hold applies | Version, timestamp, account/order, price/interval where relevant |
| Active dispute or legal hold | Hold opened | Until final resolution/release | Resume normal schedule | Written purpose, scope, owner, next review date |
| Privacy-request correspondence | Request completed | 3 years | Delete | Request type, verification, decision, timestamps |
| Deletion audit | Deletion completed | 6 years | Delete | Internal request ID, keyed account hash, timestamps, systems/processors, status; no reports |
| Sanitised security incident record | Incident closed | 3 years | Delete unless hold applies | Facts, scope, actions, outcome; unnecessary payload removed |
| Confirmed accidental PHI | Confirmation | Target: within 72 hours | Delete or irreversibly redact | Never use in reports, analytics, or model processing |
| Sanitised accidental-PHI incident record | Incident closed | 3 years | Delete unless hold applies | No patient identity or original content |
| Provider-managed backup | Backup created | 30 days maximum rolling | Automatic expiry | Deletion tombstones reapplied after restore |
3. Account deletion
Deletion requires two in-product confirmations and one emailed one-time link or code. After final verification:
- disable access immediately;
- queue deletion across product database, evidence storage, generated exports, support attachments, analytics identifiers, email systems, and applicable processors;
- complete active-system deletion within 30 days;
- detach retained finance/contract records from reports and ordinary contact history;
- retain only the minimal deletion audit and permitted purpose-specific exceptions;
- send completion confirmation without sensitive content;
- allow rolling backups to expire within 30 days and reapply deletion tombstones if a backup is restored.
There is no recovery window. A new account does not restore deleted history.
4. Free-account inactivity
At 12 months without user activity and without a paid order:
- send a 30-day inactivity-deletion notice;
- treat sign-in or an explicit keep-account action as reactivation;
- delete the account if no reactivation occurs;
- keep only the minimum keyed record needed for the one-free-scan and opt-out rules.
Paid accounts are not auto-deleted for inactivity in the MVP because the product promises continuing read-only access to purchased outputs.
5. Accidental PHI
When suspected patient-identifiable information is found:
- stop normal processing of the affected item;
- restrict access to the minimum incident handler;
- do not send it to AI, analytics, email templates, logs, or reports;
- confirm scope without duplicating the content;
- delete or irreversibly redact it as soon as reasonably possible, targeting 72 hours after confirmation;
- preserve only a sanitised incident record for three years;
- assess whether notification, security, provider, or legal escalation is required.
The 72-hour target is an internal minimisation target, not a universal statutory deadline.
6. Implementation controls
- Each data entity has a retention class, trigger timestamp, deletion status, and legal-hold flag.
- Automated jobs run at least daily for 7-day and 30-day classes and at least monthly for longer classes.
- Deletion jobs are idempotent, retry safely, and generate a content-minimised audit record.
- Processor contracts and configuration must support the schedule or document a stricter provider limitation.
- Supabase database backup evidence and private Storage object recovery are tested separately because database backups do not include Storage objects; neither recovery path may exceed the approved retention or resurrect a verified deletion.
- Restore tests verify that deletion tombstones are reapplied.
- Quarterly sampling checks overdue deletion, orphaned storage, provider divergence, and accidental PII in logs/analytics.
- Any exception records purpose, affected fields, owner, expiry/review date, and approval.
7. Provider matrix required before release
For hosting, database, object storage, authentication, email, payment, analytics, observability, and each consumer-AI measurement surface, record:
- controller/processor/independent-controller role;
- data categories and purpose;
- processing region and transfer mechanism;
- provider default retention and configurable retention;
- export, deletion, backup, and account-closure behaviour;
- security access and subprocessor link;
- verified test showing the product schedule is achievable.