Security & ComplianceData retention
Retention periods and deletion policies for Perceive8 data categories.
Data retention
Version: 1.0
Last Updated: 2026-03-07
Owner: Privacy & Compliance Team
Classification: Internal — Confidential
Related Docs: Data Inventory · Consent Model · Deletion & Export Workflow · Subprocessors
1. Overview
This document defines the data retention periods for all data classes within the Perceive8 platform. Retention periods are based on business necessity, legal requirements, and privacy-by-design principles. Data should not be retained longer than necessary for its stated purpose.
Guiding Principles
- Data Minimization — Retain only what is necessary for the stated purpose
- Purpose Limitation — Do not repurpose data beyond its original collection purpose
- Storage Limitation — Enforce maximum retention periods with automated deletion
- Transparency — Users must be informed of retention periods at the point of collection
- User Control — Users can request early deletion at any time (see Deletion & Export Workflow)
2. Data Class Definitions
| Data Class |
Description |
Database Tables |
Classification |
| Audio |
Raw and enhanced audio recordings uploaded by users |
audio_files, MinIO object storage |
L4 — Restricted |
| Transcripts |
Verbatim speech-to-text output with speaker labels |
transcript_segments |
L3–L4 — Confidential/Restricted |
| Diarization |
Speaker turn boundaries and identification data |
diarization_segments, speakers |
L3 — Confidential |
| Voiceprints |
Speaker voice embeddings (biometric data) |
voiceprint_profiles, ChromaDB |
L4 — Restricted |
| Analysis Results |
Emotion, sentiment, entities, content moderation, topics |
audio_intelligence_segments |
L3–L4 — Confidential/Restricted |
| Reports |
Generated scenario reports and findings |
reports, report_findings, scenarios, scenario_questions |
L3 — Confidential |
| Conversations |
AI chat history and artifacts |
conversations, conversation_messages |
L3 — Confidential |
| Embeddings |
Vector embeddings for semantic search |
ChromaDB |
L3 — Confidential |
| Streaming |
Real-time session data and alerts |
stream_sessions, stream_alerts |
L3 — Confidential |
| Billing |
Subscription, usage, and payment references |
subscriptions, usage_records, minute_packs |
L3 — Confidential |
| Auth & API |
API keys, OAuth clients, webhooks |
api_keys, oauth_clients, webhooks |
L3 — Confidential |
| Audit Logs |
User actions, IP addresses, timestamps |
audit_log |
L3 — Confidential |
3. Retention Schedule
3.1 Audio Recordings
| Attribute |
Value |
| Data Class |
Audio |
| Tables / Storage |
audio_files, MinIO (original_path, enhanced_path) |
| Retention Period |
90 days from upload date |
| Justification |
Audio is needed for reprocessing and quality verification. 90 days balances utility with privacy risk. Users may request earlier deletion. |
| Deletion Method |
Hard delete — remove files from MinIO, remove database records |
| Cascade |
Deletion of audio does NOT cascade to derived data (transcripts, analysis). Users must separately request full deletion. |
| Who Can Trigger |
User (on-demand), Admin (on-demand), Automated (scheduled) |
| Implementation Status |
❌ Not Implemented |
⚠️ Gap: 90-day audio retention is policy only — no automated enforcement exists yet. Audio files persist indefinitely until manually deleted. An automated cleanup job must be implemented.
Proposed Implementation:
3.2 Transcripts
| Attribute |
Value |
| Data Class |
Transcripts |
| Tables |
transcript_segments |
| Retention Period |
Duration of account + 30 days grace period |
| Justification |
Transcripts are the core product deliverable. Retained as long as the user's account is active. |
| Deletion Method |
Hard delete — remove all transcript segments for the analysis |
| Cascade |
Deleted when parent analyses record is deleted, or on account deletion |
| Who Can Trigger |
User (per-analysis or account deletion), Admin, Automated (account cleanup) |
| Implementation Status |
⚠️ Policy Only — per-analysis deletion available via API; no automated account cleanup |
3.3 Diarization & Speaker Data
| Attribute |
Value |
| Data Class |
Diarization |
| Tables |
diarization_segments, speakers |
| Retention Period |
Duration of account + 30 days grace period |
| Justification |
Speaker data supports ongoing analysis features. |
| Deletion Method |
Hard delete — remove segments and speaker records |
| Cascade |
diarization_segments deleted with parent analysis; speakers deleted on account deletion |
| Who Can Trigger |
User, Admin, Automated (account cleanup) |
| Implementation Status |
⚠️ Policy Only — no automated enforcement |
3.4 Voiceprint Profiles (Biometric Data)
| Attribute |
Value |
| Data Class |
Voiceprints |
| Tables |
voiceprint_profiles, ChromaDB collections |
| Retention Period |
Until consent is withdrawn or account deletion, whichever comes first |
| Justification |
Biometric data requires explicit consent. Must be deleted immediately upon consent withdrawal. BIPA requires destruction within 3 years of last interaction or when purpose is fulfilled. |
| Deletion Method |
Hard delete — remove database records AND ChromaDB embeddings |
| Cascade |
Must delete from both PostgreSQL and ChromaDB simultaneously |
| Who Can Trigger |
User (consent withdrawal or account deletion), Admin |
| Implementation Status |
❌ Not Implemented |
🔴 Critical Gap: No mechanism exists to delete voiceprint data from ChromaDB. No consent withdrawal flow is implemented. This is a high-priority compliance risk for BIPA and GDPR Art. 9.
Proposed Implementation:
3.5 Analysis Results (Emotion, Sentiment, Entities, Moderation)
| Attribute |
Value |
| Data Class |
Analysis Results |
| Tables |
audio_intelligence_segments, analyses |
| Retention Period |
Duration of account + 30 days grace period |
| Justification |
Analysis results are the core product deliverable. |
| Deletion Method |
Hard delete — remove all intelligence segments for the analysis |
| Cascade |
Deleted when parent analyses record is deleted |
| Who Can Trigger |
User (per-analysis or account deletion), Admin, Automated |
| Implementation Status |
⚠️ Policy Only — per-analysis deletion available; no automated cleanup |
3.6 Reports & Scenarios
| Attribute |
Value |
| Data Class |
Reports |
| Tables |
reports, report_findings, scenarios, scenario_questions |
| Retention Period |
Duration of account + 30 days grace period |
| Justification |
Reports are user-generated analysis outputs. Scenarios are reusable templates. |
| Deletion Method |
Hard delete — cascade from report to findings |
| Cascade |
report_findings deleted with parent reports; user-created scenarios deleted on account deletion; system templates retained |
| Who Can Trigger |
User (per-report), Admin, Automated (account cleanup) |
| Implementation Status |
⚠️ Policy Only |
3.7 Conversations & Chat History
| Attribute |
Value |
| Data Class |
Conversations |
| Tables |
conversations, conversation_messages |
| Retention Period |
Duration of account + 30 days grace period |
| Justification |
Chat history provides ongoing value for users reviewing past analyses. |
| Deletion Method |
Hard delete — cascade from conversation to messages |
| Cascade |
conversation_messages deleted with parent conversations |
| Who Can Trigger |
User (per-conversation or account deletion), Admin |
| Implementation Status |
⚠️ Policy Only |
3.8 Vector Embeddings
| Attribute |
Value |
| Data Class |
Embeddings |
| Storage |
ChromaDB |
| Retention Period |
Duration of account + 30 days grace period |
| Justification |
Embeddings power the RAG/chat feature. Derived from transcripts. |
| Deletion Method |
Hard delete — remove collections/documents from ChromaDB |
| Cascade |
Should be deleted when source analysis is deleted |
| Who Can Trigger |
User (account deletion), Admin, Automated |
| Implementation Status |
❌ Not Implemented |
⚠️ Gap: No mechanism exists to selectively delete embeddings from ChromaDB when an analysis is deleted. Embeddings may persist after source data deletion.
Proposed Implementation:
3.9 Streaming Data
| Attribute |
Value |
| Data Class |
Streaming |
| Tables |
stream_sessions, stream_alerts |
| Retention Period |
30 days for session metadata; Duration of account for alerts |
| Justification |
Session metadata is operational; alerts have ongoing analytical value. |
| Deletion Method |
Hard delete |
| Cascade |
stream_alerts deleted with parent session or on account deletion |
| Who Can Trigger |
Automated (session cleanup), User (account deletion), Admin |
| Implementation Status |
❌ Not Implemented |
3.10 Billing & Payment Data
| Attribute |
Value |
| Data Class |
Billing |
| Tables |
subscriptions, usage_records, minute_packs |
| Retention Period |
7 years after last transaction (tax/legal requirement) |
| Justification |
Financial records must be retained for tax compliance, audit, and dispute resolution. |
| Deletion Method |
Anonymization after 7 years — replace user_id with anonymized reference, retain aggregate financial data |
| Cascade |
Anonymized rather than deleted; Stripe records managed by Stripe's retention policy |
| Who Can Trigger |
Automated only (legal retention override) |
| Implementation Status |
❌ Not Implemented |
ℹ️ Note: Billing data is subject to legal retention requirements that override user deletion requests. Users will be informed that billing records are anonymized rather than deleted. See Deletion & Export Workflow.
3.11 Authentication & API Credentials
| Attribute |
Value |
| Data Class |
Auth & API |
| Tables |
api_keys, oauth_clients, webhooks |
| Retention Period |
Duration of account — deleted immediately on account deletion |
| Justification |
Credentials are only useful while the account is active. |
| Deletion Method |
Hard delete — revoke all keys, delete records |
| Cascade |
All credentials deleted on account deletion |
| Who Can Trigger |
User (individual key revocation or account deletion), Admin |
| Implementation Status |
⚠️ Partial — individual key revocation exists; no account-level cascade |
3.12 Audit Logs
| Attribute |
Value |
| Data Class |
Audit Logs |
| Tables |
audit_log |
| Retention Period |
2 years from event date |
| Justification |
Audit logs support security investigations, compliance audits, and incident response. 2-year period aligns with SOC 2 and common regulatory expectations. |
| Deletion Method |
Hard delete — remove records older than 2 years |
| Cascade |
Independent — not affected by account deletion (retained for compliance) |
| Who Can Trigger |
Automated only (scheduled cleanup) |
| Implementation Status |
❌ Not Implemented |
ℹ️ Note: Audit logs are retained even after account deletion for compliance and security purposes. IP addresses in audit logs older than 90 days should be anonymized (replace last octet with 0).
Proposed Implementation:
4. Retention Summary Table
| Data Class |
Retention Period |
Deletion Method |
Trigger |
Status |
| Audio Recordings |
90 days |
Hard delete (MinIO + DB) |
Auto / User / Admin |
❌ Not Implemented |
| Transcripts |
Account lifetime + 30d |
Hard delete |
User / Admin / Auto |
⚠️ Policy Only |
| Diarization / Speakers |
Account lifetime + 30d |
Hard delete |
User / Admin / Auto |
⚠️ Policy Only |
| Voiceprints (Biometric) |
Until consent withdrawn |
Hard delete (DB + ChromaDB) |
User / Admin |
❌ Not Implemented |
| Analysis Results |
Account lifetime + 30d |
Hard delete |
User / Admin / Auto |
⚠️ Policy Only |
| Reports |
Account lifetime + 30d |
Hard delete (cascade) |
User / Admin / Auto |
⚠️ Policy Only |
| Conversations |
Account lifetime + 30d |
Hard delete (cascade) |
User / Admin |
⚠️ Policy Only |
| Embeddings |
Account lifetime + 30d |
Hard delete (ChromaDB) |
User / Admin / Auto |
❌ Not Implemented |
| Streaming |
30d (sessions) / Account (alerts) |
Hard delete |
Auto / User |
❌ Not Implemented |
| Billing |
7 years |
Anonymization |
Automated only |
❌ Not Implemented |
| Auth & API |
Account lifetime |
Hard delete |
User / Admin |
⚠️ Partial |
| Audit Logs |
2 years |
Hard delete |
Automated only |
❌ Not Implemented |
5. Implementation Priorities
🔴 Critical (Must implement before processing EU/IL data)
- Voiceprint deletion mechanism — ChromaDB + PostgreSQL coordinated deletion
- Audio auto-deletion — 90-day enforcement with MinIO cleanup job
- Account deletion cascade — Full data deletion across all tables and storage systems
🟡 High Priority (Required for enterprise readiness)
- Embedding deletion — ChromaDB selective deletion by user/analysis
- Audit log lifecycle — 2-year retention with IP anonymization
- Billing data anonymization — 7-year retention with user de-identification
🟢 Standard Priority (Operational improvements)
- Streaming session cleanup — 30-day automated deletion
- User notification — Pre-deletion warnings for audio files
- Retention dashboard — Admin visibility into data retention status
6. Third-Party Data Retention
Data sent to third-party AI providers is subject to their own retention policies. See Subprocessors for details.
| Provider |
Data Sent |
Their Stated Retention |
Our DPA Status |
| OpenAI |
Audio, chat messages, text for embeddings |
30 days (API), 0 days (with opt-out) |
❌ Pending |
| Pyannote.ai |
Audio |
Unknown — must verify |
❌ Pending |
| Replicate |
Audio |
Transient (deleted after processing) |
❌ Pending |
| Hume AI |
Audio |
Unknown — must verify |
❌ Pending |
| AssemblyAI |
Audio |
Deleted after processing (default) |
❌ Pending |
| Stripe |
Payment data |
Per Stripe retention policy |
✅ Standard DPA |
| Supabase |
All database records |
Duration of service |
⚠️ Review needed |
⚠️ Action Required: Verify retention policies with all AI providers and ensure DPAs include data deletion obligations. See Subprocessors for full details.
7. Revision History
| Version |
Date |
Author |
Changes |
| 1.0 |
2026-03-07 |
Privacy & Compliance Team |
Initial retention schedule |