Limited pilot · legal v1.0
Retention
The maximum lifetime and deletion behavior for active content, derived state, logs, receipts, exports and encrypted recovery objects.
Maximum retention schedule
| Data or artifact | Maximum | Deletion behavior |
|---|---|---|
| Full raw interaction or transcript | None | Never persisted |
| Ephemeral admitted extraction buffer | 15 minutes | Removed after the terminal job or deadline |
| Active limited-pilot canonical Memory | 30 days | Earlier user deletion or pilot end wins |
| Derived index or cache after canonical deletion | 5 minutes | Tombstones first, then incremental repair |
| Export staging | 24 hours | Object and access capability removed |
| Content-free Vercel runtime and request logs | 30 days | Provider expiry |
| Content-minimized append-only audit | 365 days | Controlled retention purge |
| Content-free tombstone or receipt | 365 days | Removed with final account purge unless law requires otherwise |
| Encrypted off-site recovery object | At least 56, at most 60 days | Bucket lifecycle deletion at day 60 |
| Active data after pilot or account end | 24 hours | Access revoked first; active content purged |
| Content-free operational request-log buffer | 30 days | Written by the application itself after each response (route, outcome, status code, duration class only); ingest-time and daily deletion |
Deletion invariants
- A user deletion immediately removes content from retrieval and creates only a content-free tombstone or receipt.
- Correction, deletion, account deletion, restore and revocation cascade to derived indexes, cached contexts, exports and active sessions.
- A stale backup, repair replay or provider restore cannot resurrect a tombstoned record.
- Secrets and recovery material are excluded rather than retained under an ordinary Memory or log schedule.
Supabase provider PITR is not relied upon by this policy. The verified recovery boundary is the encrypted two-channel off-site object and its isolated restore receipt.