Data Retention Policy
Last reviewed 2026-07-24
This policy defines retention periods for personal data and operational records HiringCoachAI stores, the backup posture supporting recovery and disaster preparedness, and how account deletion interacts with active storage and backups.
Retention by data class
| Data class | Storage | Retention | Notes |
|---|---|---|---|
| Application audit log | Firestore auditLog (append-only) | 2 years | Forensics, compliance, access reviews |
| AI call audit metadata (no prompts or completions) | Firestore aiCallAudit | 1 year | AI governance, anomaly detection |
| Security audit monitor run records | Firestore securityAuditMonitorRuns | 365 days | Hourly anomaly-monitor evidence |
| Retention run logs | Firestore dataRetentionRuns | 90 days | Operating-control evidence |
| Deleted-user audit record | Firestore deleted_users | 365 days | Name and email are available to restricted administrators for up to 30 days after deletion to identify a recent deletion and respond personally to optional deletion feedback. At day 30 lookup hides them and the daily retention job removes the fields. The remaining audit metadata supports deletion confirmation, security, billing reconciliation, and legal claims. |
| Account-deletion challenges | Firestore account_deletion_challenges | 15 minutes | TTL on write |
| Deleted-account recovery snapshots | Firestore deleted_account_snapshots + restricted storage object | 30 days | Recovery from accidental self-deletion |
| Deleted-account feedback | Firestore deleted_account_feedback | 365 days | Optional; collected only after deletion completes |
| LinkedIn integration cookies | Firestore linkedinCookies | 1 hour | TTL on write |
| Short-lived auto-login tokens | Firestore authTokens | 5 minutes | TTL on write |
| Public booking and appointments-feed rate-limit counters | Firestore coachBookingRateLimits | Twice the configured fixed window; at most 2 hours for current buckets | Firestore TTL on expiresAt; credential and source keys are hashed |
| Public booking email-verification records | Firestore coachBookingEmailVerifications | 8-minute verification window; expired unused records remain deletion-eligible until asynchronous TTL cleanup completes | The application rejects a token after eight minutes. After successful use, the service immediately attempts to clear personal and staged-assent fields; the TTL policy is the cleanup fallback if that best-effort write encounters a transient failure. Firestore TTL is deployed on expiresAt, but TTL deletion is not instantaneous and typically completes within 24 hours after expiry. npm run firestore:indexes:check fails when the deployed TTL policy drifts from the manifest. |
| Coach profile review notification and delivery records | Firestore coachProfileReviewNotifications | 30 days | Firestore TTL on expiresAt; administrative delivery/retry record may include the submitted profile snapshot, highlighted findings, automated analysis, and reviewer-routing metadata |
| Coach automation webhook events and delivery attempts | Firestore coachWebhookEvents, coachWebhookDeliveries | 90 days | Firestore TTL on expiresAt; account deletion removes them earlier. Queued delivery reauthorizes the coach account immediately before any external send. |
| Removed custom-domain verification records | Firestore coachCustomDomains | 30 days after removal | Firestore TTL on expiresAt; active records persist only while the coach keeps the forwarding domain configured, and account deletion immediately removes ownership and the hashed verification token. |
| Coach-client SMS message records | Firestore coachSmsMessages | 30 days after scheduled delivery | Firestore TTL on retentionUntil. The record contains message content and delivery metadata but not the raw destination number. Account deletion removes it earlier. Each provider request asks Twilio to discard message content and obfuscate the non-Twilio phone number; Twilio may still retain limited-access compliance data under its terms. |
| Coach-client SMS consent and revocation evidence | Firestore coachSmsConsentEvents | Six years from each event under the current conservative policy | Firestore TTL on retentionUntil. Exact event identity, phone hash/last four digits, disclosure version/hash, source and time are preserved after account deletion until the TTL date because alteration would weaken proof of consent or revocation. No raw phone number or message body is retained. Qualified counsel must ratify the final jurisdiction-specific period before relying on this as a legal conclusion. |
| Testimonial submissions | Google Workspace / Sheets | Until deletion request or manual removal | No automated retention schedule is currently configured; submissions may include name, email, testimonial, permission choices, and case-study interest |
| Billing records | Stripe + Firestore subscriptions, subscriptionHistory, relationship engagements and nested payment obligations, subscription bindings, and coachClientPaymentAuditEvents with billing_records retention | Up to 7 years | Legal obligation (tax records), billing integrity, refunds and disputes; raw card data is not stored in Firestore |
| Client Payments restricted routing and idempotency bindings | coachPaymentProfiles, coachConnectAccountOwners, coachClientPaymentStripeLookups, ordinary clientPaymentOperations, relationship deletion tombstones | Through unresolved provider events and the applicable financial, refund, dispute, or claims period; up to seven years where applicable; holds extend retention | Deletion disables access and redacts product identity but retains the minimum server-only direct or pseudonymous binding needed to authenticate late events. Pseudonymization is not anonymization. |
| High-assurance electronic-contract operation evidence | High-assurance clientPaymentOperations identified by hc-high-assurance-operation-v3, plus the locked GCS evidence package it references; earlier v1/v2 operations are isolated for assisted manual review and are never upgraded in place | Related contract, limitations, or claims period, plus holds; no automatic deletion TTL under the founder-approved schedule | Preserve the exact queryable subject routing, signed replay descriptor, signed domain-pending-patch hash, reservation, HSM seal, RFC 3161 token, immutable-generation receipt, prerequisite chain, and final receipt. Account deletion and generic restricted-record redaction must not mutate these hash-bound records. Restricted assisted DSR only. |
| Recurring-billing emergency/provider-reconciliation evidence | coachRecurringBillingIncidents, coachRecurringBillingControl, coachRecurringBillingAttempts | Seven years from completion; unresolved incidents, an active control, and legal holds extend retention; no automatic TTL under the founder-approved schedule | Preserve exact hash-bound authorization, operator, provider cutoff, action, and outcome evidence. Assisted DSR only; the active singleton is never deleted on account deletion. |
| Refund approval and maker-checker evidence | coachRefundApprovalRequests | Seven years from disposition or transaction, plus holds | Preserve immutable routing, request, and decision evidence; redact nonessential deleted-subject content; assisted DSR only. |
| Authenticated client refund-case evidence | Nested clientRefundRequests under relationship payment obligations | With the related financial record and for the applicable refund, dispute and claims period; up to seven years under the founder-approved conservative schedule; legal holds extend retention | Preserve the exact authenticated requester/payment snapshot, request hash, hash-chained lifecycle and provider attribution needed to prove and reconcile the case. Free text is limited at collection and must not be copied into ordinary analytics. Because changing the statement or identity would invalidate the evidence hash, disclosure, correction and deletion requests require restricted assisted review. |
| Platform and consumer legal acceptance evidence | coachLegalAcceptances, consumerLegalAcceptances | Applicable contract, limitations, or claims period, plus holds; no automatic deletion TTL under the founder-approved schedule | Preserve exact append-only identity and assent evidence unchanged because identity is necessary to prove acceptance; restricted assisted DSR only. |
| Anonymous purchase acceptance evidence | anonymousPurchaseLegalAcceptances | Applicable contract, financial, limitations, or claims period, plus holds; no automatic deletion TTL under the founder-approved schedule | Preserve normalized purchaser email, exact legal release, acknowledgment labels, provider/amount binding, operation ID, hashes, timestamp, and HMAC seal unchanged. Restricted assisted DSR only; verify control of the purchase email before disclosure. |
| Verified public-booking acceptance evidence | anonymousBookingLegalAcceptances | Applicable contract, limitations, or claims period, plus holds; no automatic deletion TTL under the founder-approved schedule | Created only after the visitor proves control of the claimed booking email. Preserve the verified email, exact legal release and acknowledgment labels, booking-link/hold binding, operation ID, timestamps, hashes, and HMAC seal unchanged. Restricted assisted DSR only; reverify control of the booking email before disclosure. |
| Anonymous gift fulfillment exceptions | anonymousPurchaseFulfillmentExceptions | With the related refund and billing record, up to seven years where applicable; holds extend retention | Reconciles legacy or unverifiable gifts that were automatically refunded without fulfillment. Contains provider/refund references and no plaintext purchaser email. |
| Coaching contract templates and undelivered drafts | Firestore coachContractTemplates, relationship engagement agreement versions | Until owner account deletion or earlier deletion/voiding | User-authored working records that have not been delivered or signed |
| Supplemental agreement signing packages and sealed manifests | Immutable agreement envelope and locked archive object storage | Delivered or signed packages retain the seven-year agreement floor. A surviving party retains access, and legal holds extend retention. | Server-derived exact-generation/hash custody only; no client-supplied authoritative digest. Coach library and source-object cleanup does not alter this evidence. |
| Bound supplemental agreement view receipts | Firestore coachContractDocumentViews | With the related delivered or signed agreement, normally at least seven years; legal holds extend retention | Preserve document/version and outer manifest bindings plus viewed timestamps as restricted evidence. Restricted assisted DSR handling omits network, browser, storage, upload, scanner, and key-management internals. |
| Coach supplemental document library and deterministic binding index | Firestore coachContractDocuments, nested versions, coachContractDocumentOperations, and coachContractDocumentBindings; private quarantine/source objects | Expired or abandoned uploads follow workflow cleanup. Coach account deletion removes all source and quarantine generations, then the coach library, versions, operations, and binding index. A warning or unknown storage outcome blocks deletion for retry. | The immutable agreement envelope, locked archive artifact, and coachContractDocumentViews evidence are separate retained records and remain available to surviving parties under the agreement retention schedule. |
| Delivered or signed coaching agreements and evidence certificates | Relationship engagement agreement versions | Ordinary non-renewing evidence is retained for at least seven years from the latest verified delivery, signature, completion, or later verified engagement termination; active or unverifiably terminated signed engagements fail closed to review. Automatic-renewal consent evidence is retained at least three years from consent or one year after verified subscription termination, whichever is later. Legal holds extend either schedule. | Preserves a surviving party's immutable record and the minimum evidence needed for disputes and inquiries under the exact founder-approved v2 policy snapshots; related financial records follow their separate schedule. |
| Contract-delivery evidence | Firestore coachContractNotifications | With the related delivered/signed agreement evidence | Queued recipient data is canceled/redacted on account deletion; provider-accepted evidence follows the agreement; known failures dead-letter; unknown provider outcomes remain blocked until traceable administrative resolution |
| Automatic-renewal reminder evidence | Firestore coachPaymentReminders | At least three years from the recorded consent or one year after verified subscription termination, whichever is later | Applies to provider-accepted, in-flight, and unknown-outcome renewal notices and their signed-agreement binding; legal holds extend retention |
| Contract legal holds and deletion locks | Firestore contractEvidenceLegalHolds (including events), contractEvidenceDeletionLocks, and related coachClientPaymentAuditEvents | Evidence remains throughout an active hold; control history remains for the applicable legal-claim/audit period; no automatic TTL is currently configured | Holds require authorized release. If both parties have deleted, release creates an explicit purge requirement; unreadable hold state and remaining applicable holds fail closed. Expired purge workers are recovered through leased ownership, and every evidence deletion transaction rechecks the current fencing token. Statutory-retention integrity failures remain blocked from automatic purge and appear in the paginated admin review queue (GET /api/admin/contract-evidence-legal-holds?view=retention_reviews). An authorized reviewer must investigate the recorded reason code, correct source data only through an audited remediation process, and rerun purge; the queue never overrides retention automatically. |
| Applicant and intern records | Google Workspace / Gmail hiring and accommodations mailboxes | Minimum 4 years from application date or related personnel action; litigation holds retained until lifted | Accommodation requests are stored separately from hiring decision records and are not used in hiring decisions |
| Hiring-portal applicant records | Firestore hiringJobs/{jobId}/applications + private GCS hiring-resumes bucket | Minimum 4 years from application date or related personnel action; litigation holds retained until lifted | Careers-site applications (contact details, resume, cover note, status history, admin screening notes, sent decision-email records); same record class as the Gmail applicant-records row, spanning three systems |
User-controlled content (including resumes, applications, contacts, notes, drafts, public and private coach profiles, inbox messages, real-time chats, comments, replies, support communications, coaching-session agendas and notes, intake templates and responses, goals, milestones, check-ins, files, attachments, uploaded coach/client materials, collaborative HiringCoachAI Docs, reviews, testimonials, and AI-assisted outputs) is retained while the account is active and removed or redacted during the account-deletion workflow or earlier when the owner permanently deletes it. Shared records involving another user may remain where needed to preserve that user's records, complete a transaction, prevent fraud or abuse, comply with law, or establish, exercise, or defend legal claims; the departing user's identifiers and authored content are removed or redacted as applicable. Material share grants may remain after a coach-client relationship ends so already-shared items stay available, but the owner can revoke access and account deletion removes the related grant. The full personal-data inventory is documented in the data map.
Delivered or signed coaching agreements are a narrow shared-record exception: deleting one party does not destroy the surviving party's immutable contract record. An ordinary non-renewing record is retained for at least seven years from its latest verified delivery, signature, or completion event, extended through seven years after a later verified engagement termination. A signed record whose engagement remains active or whose termination cannot be verified is not automatically purged when that floor is reached. The exact schedule is embedded in each new agreement as a hash-bound retention snapshot; a missing or altered snapshot and any evidence-integrity failure require manual review. Legacy records without a trustworthy schedule fail closed instead of being deleted. Automatic-renewal evidence uses a separate minimum: retain each consent record and its bound subscription/reminder evidence until the later of (a) three years after that consent was recorded or (b) one year after the subscription's termination was verified. If termination is unknown, the record is not eligible for purge. A replacement or amended consent has its own clock, and legal holds always extend it. Payment, tax, fraud, and security-audit records follow their own independent schedules; retaining those records does not by itself extend the agreement-version schedule.
Automatic renewal and its renewal-reminder delivery path remain feature-gated and default disabled. The retention floor applies to test or live records whenever those paths are used; disabling the feature does not shorten an existing record's period. The exact v2 policies are founder-approved and remain bound to production release manifests and operational readiness evidence.
Moderation status, findings, analysis, and reviewer decisions embedded in a coach profile remain with that profile until the record is replaced or deleted, subject to legal holds. Transactional email bodies sent through SendGrid are processed transiently for delivery; provider-held event and security records follow the provider's documented retention and applicable account configuration. Copies delivered to Google Workspace / Gmail mailboxes follow the applicable mailbox or legal-record retention schedule.
Non-promotional coaching texts are available only after relationship-specific client consent for a U.S. or Canadian number. Opt-out immediately blocks new sends, clears the raw number from the relationship, and preserves only the limited revocation evidence above. Application scheduling enforces 8:00 p.m. to 8:00 a.m. quiet hours in the client's timezone. Provider-side message redaction is requested per message; Twilio's separate limited-access compliance retention remains governed by its terms and configured account controls.
Backups
| Backup layer | Retention | Notes |
|---|---|---|
| Firestore point-in-time recovery (PITR) | 7 days | Short-horizon recovery from operator error |
| Firestore scheduled daily backups | 98 days | Managed by Google Cloud |
| Backup/export bucket soft delete | 90 days | Object versioning enabled |
| Backup/export bucket retention policy | 90 days | Unlocked retention policy |
Backup/export buckets use object versioning, 90-day soft delete, and a 90-day retention policy.
Account deletion and backups
- Self-service account deletion is final in active product systems once the required checks complete.
- A deleted account's name and email remain visible in the restricted deletion lookup for no more than 30 days so an administrator can identify the recent deletion and personally respond to optional feedback. The daily retention job then removes those fields while preserving non-content deletion audit metadata for its separate 365-day period.
- A 30-day encrypted recovery snapshot is created before destructive work begins, supporting recovery from accidental self-deletion only.
- User-controlled content is removed from active product systems during the deletion workflow.
- Coach contract templates and unheld, never-delivered drafts are removed during account deletion. Delivered or signed ordinary evidence remains available to a surviving counterparty and then follows its versioned seven-year minimum; active, unterminated, legacy-unscheduled, or integrity-failed records remain blocked for review. Automatic-renewal consent and reminder-delivery evidence is not purged before its separate minimum period or while held, even after both accounts are deleted. Subscription bindings, payment obligations, and related financial/audit evidence follow their separate schedules; direct identifiers are redacted where that does not break evidence integrity.
- Queued contract and payment-reminder delivery is canceled and recipient data is redacted. In-flight or ambiguous provider outcomes are preserved for traceable administrative resolution rather than treated as unsent.
- Contract-evidence deletion is serialized against legal-hold changes. Releasing the last applicable hold after both parties delete creates an explicit purge task; registry failures or another active hold keep the purge blocked.
- Coach calendar deletion attempts to revoke the Google grant, then removes the encrypted local connection and private appointments-feed credential even when provider revocation is unavailable.
- Pilot-program usage records are retained only after direct user identifiers and direct contact, name, and free-text fields are replaced with non-reversible deleted-participant identifiers, so historical program reporting can continue without identifying the deleted account.
- The deletion audit record retains counts only and does not copy the original content arrays.
- Direct email correspondence is a separate business record and is not automatically removed by product-account deletion. It is retained only while reasonably needed for support, security, legal compliance, or legal claims, remains subject to applicable privacy requests, and is not used for marketing unless separately authorized.
- Account-deletion takes effect in active storage promptly. Older copies in backup snapshots and PITR windows roll off as the backup window rotates. Backup restore operations include controls to avoid restoring deleted accounts into active product state.
- Billing, tax, and other legally required financial records are retained for the period required by applicable law, independent of account deletion.
- Pseudonymous deletion keys and billing-owner tombstones are retained server-side only for retry, financial-lifecycle authentication, reconciliation, claims, and holds. They remain linkable or re-identifiable by authorized systems and are not anonymous. The deletion workflow must not describe them as anonymized or include them in ordinary product views. Exact legal-acceptance identity is a separate narrow exception retained unchanged to preserve proof of assent.
Institutional / customer bulk requests
Where an institutional or sponsor-program agreement provides for it, the Customer administrator may request bulk deletion or bulk export of a sponsored cohort by writing to [email protected]. Bulk requests are handled within the response window applicable to the underlying agreement (typically aligned with the data-subject-request 30-day response window under GDPR Art. 12(3), extendable for complex requests where permitted by law).
Enforcement
Pseudonymous coachOfferAnalytics events expire after approximately 25 months using Firestore TTL. coachReportPreferences holds an opt-in flag and weekly delivery lease only. The canonical privacy lifecycle deletes both collections when the coach account is deleted, includes preferences in self-service export, and exposes analytics only through a privacy-reviewed assisted DSR projection that excludes visitor session hashes. Weekly dispatch also disables orphaned preferences when the coach account or email no longer exists.
- Retention is enforced through Firestore TTL policies and a scheduled daily job that deletes records past their retention window for configured collections. The scheduled job emits per-collection counts and is retained as operating-control evidence.
- Backup retention is configured at the Google Cloud platform layer and is verified during quarterly internal audit.
- The retention policy is reviewed at least annually and on any material data-flow change.