Skip to main content
Home›Docs›Security & Compliance›Data retention
Security & Compliance

Data retention

Retention periods and deletion policies for Perceive8 data categories.

Data retention

Version: 1.0
Last Updated: 2026-03-07
Owner: Privacy & Compliance Team
Classification: Internal — Confidential
Related Docs: Data Inventory · Consent Model · Deletion & Export Workflow · Subprocessors


1. Overview

This document defines the data retention periods for all data classes within the Perceive8 platform. Retention periods are based on business necessity, legal requirements, and privacy-by-design principles. Data should not be retained longer than necessary for its stated purpose.

Guiding Principles

  1. Data Minimization — Retain only what is necessary for the stated purpose
  2. Purpose Limitation — Do not repurpose data beyond its original collection purpose
  3. Storage Limitation — Enforce maximum retention periods with automated deletion
  4. Transparency — Users must be informed of retention periods at the point of collection
  5. User Control — Users can request early deletion at any time (see Deletion & Export Workflow)

2. Data Class Definitions

Data Class Description Database Tables Classification
Audio Raw and enhanced audio recordings uploaded by users audio_files, MinIO object storage L4 — Restricted
Transcripts Verbatim speech-to-text output with speaker labels transcript_segments L3–L4 — Confidential/Restricted
Diarization Speaker turn boundaries and identification data diarization_segments, speakers L3 — Confidential
Voiceprints Speaker voice embeddings (biometric data) voiceprint_profiles, ChromaDB L4 — Restricted
Analysis Results Emotion, sentiment, entities, content moderation, topics audio_intelligence_segments L3–L4 — Confidential/Restricted
Reports Generated scenario reports and findings reports, report_findings, scenarios, scenario_questions L3 — Confidential
Conversations AI chat history and artifacts conversations, conversation_messages L3 — Confidential
Embeddings Vector embeddings for semantic search ChromaDB L3 — Confidential
Streaming Real-time session data and alerts stream_sessions, stream_alerts L3 — Confidential
Billing Subscription, usage, and payment references subscriptions, usage_records, minute_packs L3 — Confidential
Auth & API API keys, OAuth clients, webhooks api_keys, oauth_clients, webhooks L3 — Confidential
Audit Logs User actions, IP addresses, timestamps audit_log L3 — Confidential

3. Retention Schedule

3.1 Audio Recordings

Attribute Value
Data Class Audio
Tables / Storage audio_files, MinIO (original_path, enhanced_path)
Retention Period 90 days from upload date
Justification Audio is needed for reprocessing and quality verification. 90 days balances utility with privacy risk. Users may request earlier deletion.
Deletion Method Hard delete — remove files from MinIO, remove database records
Cascade Deletion of audio does NOT cascade to derived data (transcripts, analysis). Users must separately request full deletion.
Who Can Trigger User (on-demand), Admin (on-demand), Automated (scheduled)
Implementation Status ❌ Not Implemented

⚠️ Gap: 90-day audio retention is policy only — no automated enforcement exists yet. Audio files persist indefinitely until manually deleted. An automated cleanup job must be implemented.

Proposed Implementation:

  • Add expires_at column to audio_files table (default: created_at + 90 days)
  • Create scheduled task (procrastinate job) to delete expired audio from MinIO
  • Update audio_files records to mark as deleted
  • Send user notification 7 days before auto-deletion
  • Allow users to extend retention via API/UI

3.2 Transcripts

Attribute Value
Data Class Transcripts
Tables transcript_segments
Retention Period Duration of account + 30 days grace period
Justification Transcripts are the core product deliverable. Retained as long as the user's account is active.
Deletion Method Hard delete — remove all transcript segments for the analysis
Cascade Deleted when parent analyses record is deleted, or on account deletion
Who Can Trigger User (per-analysis or account deletion), Admin, Automated (account cleanup)
Implementation Status ⚠️ Policy Only — per-analysis deletion available via API; no automated account cleanup

3.3 Diarization & Speaker Data

Attribute Value
Data Class Diarization
Tables diarization_segments, speakers
Retention Period Duration of account + 30 days grace period
Justification Speaker data supports ongoing analysis features.
Deletion Method Hard delete — remove segments and speaker records
Cascade diarization_segments deleted with parent analysis; speakers deleted on account deletion
Who Can Trigger User, Admin, Automated (account cleanup)
Implementation Status ⚠️ Policy Only — no automated enforcement

3.4 Voiceprint Profiles (Biometric Data)

Attribute Value
Data Class Voiceprints
Tables voiceprint_profiles, ChromaDB collections
Retention Period Until consent is withdrawn or account deletion, whichever comes first
Justification Biometric data requires explicit consent. Must be deleted immediately upon consent withdrawal. BIPA requires destruction within 3 years of last interaction or when purpose is fulfilled.
Deletion Method Hard delete — remove database records AND ChromaDB embeddings
Cascade Must delete from both PostgreSQL and ChromaDB simultaneously
Who Can Trigger User (consent withdrawal or account deletion), Admin
Implementation Status ❌ Not Implemented

🔴 Critical Gap: No mechanism exists to delete voiceprint data from ChromaDB. No consent withdrawal flow is implemented. This is a high-priority compliance risk for BIPA and GDPR Art. 9.

Proposed Implementation:

  • Add consent tracking for voiceprint collection (see Consent Model)
  • Implement ChromaDB deletion API for voiceprint embeddings
  • Add consent withdrawal endpoint that triggers voiceprint deletion
  • Implement BIPA-compliant 3-year maximum retention
  • Add automated check for voiceprint profiles without valid consent

3.5 Analysis Results (Emotion, Sentiment, Entities, Moderation)

Attribute Value
Data Class Analysis Results
Tables audio_intelligence_segments, analyses
Retention Period Duration of account + 30 days grace period
Justification Analysis results are the core product deliverable.
Deletion Method Hard delete — remove all intelligence segments for the analysis
Cascade Deleted when parent analyses record is deleted
Who Can Trigger User (per-analysis or account deletion), Admin, Automated
Implementation Status ⚠️ Policy Only — per-analysis deletion available; no automated cleanup

3.6 Reports & Scenarios

Attribute Value
Data Class Reports
Tables reports, report_findings, scenarios, scenario_questions
Retention Period Duration of account + 30 days grace period
Justification Reports are user-generated analysis outputs. Scenarios are reusable templates.
Deletion Method Hard delete — cascade from report to findings
Cascade report_findings deleted with parent reports; user-created scenarios deleted on account deletion; system templates retained
Who Can Trigger User (per-report), Admin, Automated (account cleanup)
Implementation Status ⚠️ Policy Only

3.7 Conversations & Chat History

Attribute Value
Data Class Conversations
Tables conversations, conversation_messages
Retention Period Duration of account + 30 days grace period
Justification Chat history provides ongoing value for users reviewing past analyses.
Deletion Method Hard delete — cascade from conversation to messages
Cascade conversation_messages deleted with parent conversations
Who Can Trigger User (per-conversation or account deletion), Admin
Implementation Status ⚠️ Policy Only

3.8 Vector Embeddings

Attribute Value
Data Class Embeddings
Storage ChromaDB
Retention Period Duration of account + 30 days grace period
Justification Embeddings power the RAG/chat feature. Derived from transcripts.
Deletion Method Hard delete — remove collections/documents from ChromaDB
Cascade Should be deleted when source analysis is deleted
Who Can Trigger User (account deletion), Admin, Automated
Implementation Status ❌ Not Implemented

⚠️ Gap: No mechanism exists to selectively delete embeddings from ChromaDB when an analysis is deleted. Embeddings may persist after source data deletion.

Proposed Implementation:

  • Tag ChromaDB documents with analysis_id and user_id metadata
  • Implement deletion by metadata filter when analysis/account is deleted
  • Add reconciliation job to detect orphaned embeddings

3.9 Streaming Data

Attribute Value
Data Class Streaming
Tables stream_sessions, stream_alerts
Retention Period 30 days for session metadata; Duration of account for alerts
Justification Session metadata is operational; alerts have ongoing analytical value.
Deletion Method Hard delete
Cascade stream_alerts deleted with parent session or on account deletion
Who Can Trigger Automated (session cleanup), User (account deletion), Admin
Implementation Status ❌ Not Implemented

3.10 Billing & Payment Data

Attribute Value
Data Class Billing
Tables subscriptions, usage_records, minute_packs
Retention Period 7 years after last transaction (tax/legal requirement)
Justification Financial records must be retained for tax compliance, audit, and dispute resolution.
Deletion Method Anonymization after 7 years — replace user_id with anonymized reference, retain aggregate financial data
Cascade Anonymized rather than deleted; Stripe records managed by Stripe's retention policy
Who Can Trigger Automated only (legal retention override)
Implementation Status ❌ Not Implemented

ℹ️ Note: Billing data is subject to legal retention requirements that override user deletion requests. Users will be informed that billing records are anonymized rather than deleted. See Deletion & Export Workflow.


3.11 Authentication & API Credentials

Attribute Value
Data Class Auth & API
Tables api_keys, oauth_clients, webhooks
Retention Period Duration of account — deleted immediately on account deletion
Justification Credentials are only useful while the account is active.
Deletion Method Hard delete — revoke all keys, delete records
Cascade All credentials deleted on account deletion
Who Can Trigger User (individual key revocation or account deletion), Admin
Implementation Status ⚠️ Partial — individual key revocation exists; no account-level cascade

3.12 Audit Logs

Attribute Value
Data Class Audit Logs
Tables audit_log
Retention Period 2 years from event date
Justification Audit logs support security investigations, compliance audits, and incident response. 2-year period aligns with SOC 2 and common regulatory expectations.
Deletion Method Hard delete — remove records older than 2 years
Cascade Independent — not affected by account deletion (retained for compliance)
Who Can Trigger Automated only (scheduled cleanup)
Implementation Status ❌ Not Implemented

ℹ️ Note: Audit logs are retained even after account deletion for compliance and security purposes. IP addresses in audit logs older than 90 days should be anonymized (replace last octet with 0).

Proposed Implementation:

  • Create scheduled job to delete audit logs older than 2 years
  • Create scheduled job to anonymize IP addresses in logs older than 90 days
  • Ensure audit logs are excluded from DSAR deletion requests (with legal justification)

4. Retention Summary Table

Data Class Retention Period Deletion Method Trigger Status
Audio Recordings 90 days Hard delete (MinIO + DB) Auto / User / Admin ❌ Not Implemented
Transcripts Account lifetime + 30d Hard delete User / Admin / Auto ⚠️ Policy Only
Diarization / Speakers Account lifetime + 30d Hard delete User / Admin / Auto ⚠️ Policy Only
Voiceprints (Biometric) Until consent withdrawn Hard delete (DB + ChromaDB) User / Admin ❌ Not Implemented
Analysis Results Account lifetime + 30d Hard delete User / Admin / Auto ⚠️ Policy Only
Reports Account lifetime + 30d Hard delete (cascade) User / Admin / Auto ⚠️ Policy Only
Conversations Account lifetime + 30d Hard delete (cascade) User / Admin ⚠️ Policy Only
Embeddings Account lifetime + 30d Hard delete (ChromaDB) User / Admin / Auto ❌ Not Implemented
Streaming 30d (sessions) / Account (alerts) Hard delete Auto / User ❌ Not Implemented
Billing 7 years Anonymization Automated only ❌ Not Implemented
Auth & API Account lifetime Hard delete User / Admin ⚠️ Partial
Audit Logs 2 years Hard delete Automated only ❌ Not Implemented

5. Implementation Priorities

🔴 Critical (Must implement before processing EU/IL data)

  1. Voiceprint deletion mechanism — ChromaDB + PostgreSQL coordinated deletion
  2. Audio auto-deletion — 90-day enforcement with MinIO cleanup job
  3. Account deletion cascade — Full data deletion across all tables and storage systems

🟡 High Priority (Required for enterprise readiness)

  1. Embedding deletion — ChromaDB selective deletion by user/analysis
  2. Audit log lifecycle — 2-year retention with IP anonymization
  3. Billing data anonymization — 7-year retention with user de-identification

🟢 Standard Priority (Operational improvements)

  1. Streaming session cleanup — 30-day automated deletion
  2. User notification — Pre-deletion warnings for audio files
  3. Retention dashboard — Admin visibility into data retention status

6. Third-Party Data Retention

Data sent to third-party AI providers is subject to their own retention policies. See Subprocessors for details.

Provider Data Sent Their Stated Retention Our DPA Status
OpenAI Audio, chat messages, text for embeddings 30 days (API), 0 days (with opt-out) ❌ Pending
Pyannote.ai Audio Unknown — must verify ❌ Pending
Replicate Audio Transient (deleted after processing) ❌ Pending
Hume AI Audio Unknown — must verify ❌ Pending
AssemblyAI Audio Deleted after processing (default) ❌ Pending
Stripe Payment data Per Stripe retention policy ✅ Standard DPA
Supabase All database records Duration of service ⚠️ Review needed

⚠️ Action Required: Verify retention policies with all AI providers and ensure DPAs include data deletion obligations. See Subprocessors for full details.


7. Revision History

Version Date Author Changes
1.0 2026-03-07 Privacy & Compliance Team Initial retention schedule