← crewbrief.co
Version 1.0 · Effective 2026-05-28

Data Retention & Deletion Policy

Plain-language summary: We keep your data while your account is active. Logs roll off after 90 days. Backups roll off after 30 days. You can delete everything at any time from inside the app or by email; we complete deletion within 30 days.

1. Purpose

This policy defines how long CrewBrief retains personal data, when and how data is deleted, and the procedures for honoring deletion requests in compliance with GDPR (Articles 5(1)(e), 17) and the California Consumer Privacy Act (CCPA §1798.105).

2. Retention schedule

Data categoryRetentionTrigger for deletion
Account profile (email, name, personalization)Indefinitely while account is activeDeletion request or 24 months of inactivity
Health data (Apple Health, bloodwork, body composition)Indefinitely while account is activeDeletion request or category-specific withdrawal
Financial data (Plaid-linked accounts, transactions, manual entries)Indefinitely while account is activeDeletion request or Plaid revocation
Operational data (schedules, logbook, credentials)Indefinitely while account is activeDeletion request
Communication data (Bob/Joe chat, Telegram history)90 days from each messageAutomatic rolling deletion
AI insights30 days from generationAutomatic rolling deletion
Access logs90 daysAutomatic rolling deletion
Application error logs90 daysAutomatic rolling deletion
Database backups30 daysAutomatic rolling deletion
Vault uploads (raw files)Indefinitely while account is activeDeletion request or per-document deletion

3. Inactivity-based deletion

After 24 months without any user activity:

4. User-initiated deletion (right to erasure)

Users may request deletion of all or specific data categories:

We acknowledge receipt within 7 days and complete the request within 30 days (sooner where feasible).

5. Deletion procedure

  1. Day 0 (request received): confirmation email sent; deletion job queued.
  2. Within 7 days: live database rows for the user are deleted via cascade DELETE statements respecting all foreign keys. Vault files for the user are securely overwritten and the directory removed.
  3. Within 30 days: all references in caches, derived tables, and aggregate stores are purged.
  4. Within 60 days: all backups containing the user's data have rolled off the 30-day backup window and are unrecoverable.
  5. Confirmation: final email sent with the date and scope of completion.

6. Exceptions

We may retain limited data beyond a deletion request when required:

When an exception applies, the user is informed in the deletion confirmation.

7. Third-party data deletion

When a user deletes their account, we also:

Some third-party deletions may take up to 60 days; status reported in the final confirmation email.

8. Backup retention

Backups are kept for 30 days for disaster recovery. After 30 days, backup data is no longer recoverable. We do not maintain longer-term archival backups of user data.

9. Anonymization vs deletion

CrewBrief does not currently retain anonymized derivatives of deleted user data. All deletion requests result in complete erasure (subject to the exceptions in §6).

10. Policy review

This policy is reviewed annually and updated when retention requirements or system architecture change materially.

11. Contact

security@crewbrief.co for any retention or deletion question.