This policy defines how long CrewBrief retains personal data, when and how data is deleted, and the procedures for honoring deletion requests in compliance with GDPR (Articles 5(1)(e), 17) and the California Consumer Privacy Act (CCPA §1798.105).
| Data category | Retention | Trigger for deletion |
|---|---|---|
| Account profile (email, name, personalization) | Indefinitely while account is active | Deletion request or 24 months of inactivity |
| Health data (Apple Health, bloodwork, body composition) | Indefinitely while account is active | Deletion request or category-specific withdrawal |
| Financial data (Plaid-linked accounts, transactions, manual entries) | Indefinitely while account is active | Deletion request or Plaid revocation |
| Operational data (schedules, logbook, credentials) | Indefinitely while account is active | Deletion request |
| Communication data (Bob/Joe chat, Telegram history) | 90 days from each message | Automatic rolling deletion |
| AI insights | 30 days from generation | Automatic rolling deletion |
| Access logs | 90 days | Automatic rolling deletion |
| Application error logs | 90 days | Automatic rolling deletion |
| Database backups | 30 days | Automatic rolling deletion |
| Vault uploads (raw files) | Indefinitely while account is active | Deletion request or per-document deletion |
After 24 months without any user activity:
Users may request deletion of all or specific data categories:
We acknowledge receipt within 7 days and complete the request within 30 days (sooner where feasible).
We may retain limited data beyond a deletion request when required:
When an exception applies, the user is informed in the deletion confirmation.
When a user deletes their account, we also:
Some third-party deletions may take up to 60 days; status reported in the final confirmation email.
Backups are kept for 30 days for disaster recovery. After 30 days, backup data is no longer recoverable. We do not maintain longer-term archival backups of user data.
CrewBrief does not currently retain anonymized derivatives of deleted user data. All deletion requests result in complete erasure (subject to the exceptions in §6).
This policy is reviewed annually and updated when retention requirements or system architecture change materially.
security@crewbrief.co for any retention or deletion question.