HiringCoach.ai

Data Retention Policy

Last reviewed 2026-07-24

This policy defines retention periods for personal data and operational records HiringCoachAI stores, the backup posture supporting recovery and disaster preparedness, and how account deletion interacts with active storage and backups.

Retention by data class

Data classStorageRetentionNotes
Application audit logFirestore auditLog (append-only)2 yearsForensics, compliance, access reviews
AI call audit metadata (no prompts or completions)Firestore aiCallAudit1 yearAI governance, anomaly detection
Security audit monitor run recordsFirestore securityAuditMonitorRuns365 daysHourly anomaly-monitor evidence
Retention run logsFirestore dataRetentionRuns90 daysOperating-control evidence
Deleted-user audit recordFirestore deleted_users365 daysName and email are available to restricted administrators for up to 30 days after deletion to identify a recent deletion and respond personally to optional deletion feedback. At day 30 lookup hides them and the daily retention job removes the fields. The remaining audit metadata supports deletion confirmation, security, billing reconciliation, and legal claims.
Account-deletion challengesFirestore account_deletion_challenges15 minutesTTL on write
Deleted-account recovery snapshotsFirestore deleted_account_snapshots + restricted storage object30 daysRecovery from accidental self-deletion
Deleted-account feedbackFirestore deleted_account_feedback365 daysOptional; collected only after deletion completes
LinkedIn integration cookiesFirestore linkedinCookies1 hourTTL on write
Short-lived auto-login tokensFirestore authTokens5 minutesTTL on write
Public booking and appointments-feed rate-limit countersFirestore coachBookingRateLimitsTwice the configured fixed window; at most 2 hours for current bucketsFirestore TTL on expiresAt; credential and source keys are hashed
Public booking email-verification recordsFirestore coachBookingEmailVerifications8-minute verification window; expired unused records remain deletion-eligible until asynchronous TTL cleanup completesThe application rejects a token after eight minutes. After successful use, the service immediately attempts to clear personal and staged-assent fields; the TTL policy is the cleanup fallback if that best-effort write encounters a transient failure. Firestore TTL is deployed on expiresAt, but TTL deletion is not instantaneous and typically completes within 24 hours after expiry. npm run firestore:indexes:check fails when the deployed TTL policy drifts from the manifest.
Coach profile review notification and delivery recordsFirestore coachProfileReviewNotifications30 daysFirestore TTL on expiresAt; administrative delivery/retry record may include the submitted profile snapshot, highlighted findings, automated analysis, and reviewer-routing metadata
Coach automation webhook events and delivery attemptsFirestore coachWebhookEvents, coachWebhookDeliveries90 daysFirestore TTL on expiresAt; account deletion removes them earlier. Queued delivery reauthorizes the coach account immediately before any external send.
Removed custom-domain verification recordsFirestore coachCustomDomains30 days after removalFirestore TTL on expiresAt; active records persist only while the coach keeps the forwarding domain configured, and account deletion immediately removes ownership and the hashed verification token.
Coach-client SMS message recordsFirestore coachSmsMessages30 days after scheduled deliveryFirestore TTL on retentionUntil. The record contains message content and delivery metadata but not the raw destination number. Account deletion removes it earlier. Each provider request asks Twilio to discard message content and obfuscate the non-Twilio phone number; Twilio may still retain limited-access compliance data under its terms.
Coach-client SMS consent and revocation evidenceFirestore coachSmsConsentEventsSix years from each event under the current conservative policyFirestore TTL on retentionUntil. Exact event identity, phone hash/last four digits, disclosure version/hash, source and time are preserved after account deletion until the TTL date because alteration would weaken proof of consent or revocation. No raw phone number or message body is retained. Qualified counsel must ratify the final jurisdiction-specific period before relying on this as a legal conclusion.
Testimonial submissionsGoogle Workspace / SheetsUntil deletion request or manual removalNo automated retention schedule is currently configured; submissions may include name, email, testimonial, permission choices, and case-study interest
Billing recordsStripe + Firestore subscriptions, subscriptionHistory, relationship engagements and nested payment obligations, subscription bindings, and coachClientPaymentAuditEvents with billing_records retentionUp to 7 yearsLegal obligation (tax records), billing integrity, refunds and disputes; raw card data is not stored in Firestore
Client Payments restricted routing and idempotency bindingscoachPaymentProfiles, coachConnectAccountOwners, coachClientPaymentStripeLookups, ordinary clientPaymentOperations, relationship deletion tombstonesThrough unresolved provider events and the applicable financial, refund, dispute, or claims period; up to seven years where applicable; holds extend retentionDeletion disables access and redacts product identity but retains the minimum server-only direct or pseudonymous binding needed to authenticate late events. Pseudonymization is not anonymization.
High-assurance electronic-contract operation evidenceHigh-assurance clientPaymentOperations identified by hc-high-assurance-operation-v3, plus the locked GCS evidence package it references; earlier v1/v2 operations are isolated for assisted manual review and are never upgraded in placeRelated contract, limitations, or claims period, plus holds; no automatic deletion TTL under the founder-approved schedulePreserve the exact queryable subject routing, signed replay descriptor, signed domain-pending-patch hash, reservation, HSM seal, RFC 3161 token, immutable-generation receipt, prerequisite chain, and final receipt. Account deletion and generic restricted-record redaction must not mutate these hash-bound records. Restricted assisted DSR only.
Recurring-billing emergency/provider-reconciliation evidencecoachRecurringBillingIncidents, coachRecurringBillingControl, coachRecurringBillingAttemptsSeven years from completion; unresolved incidents, an active control, and legal holds extend retention; no automatic TTL under the founder-approved schedulePreserve exact hash-bound authorization, operator, provider cutoff, action, and outcome evidence. Assisted DSR only; the active singleton is never deleted on account deletion.
Refund approval and maker-checker evidencecoachRefundApprovalRequestsSeven years from disposition or transaction, plus holdsPreserve immutable routing, request, and decision evidence; redact nonessential deleted-subject content; assisted DSR only.
Authenticated client refund-case evidenceNested clientRefundRequests under relationship payment obligationsWith the related financial record and for the applicable refund, dispute and claims period; up to seven years under the founder-approved conservative schedule; legal holds extend retentionPreserve the exact authenticated requester/payment snapshot, request hash, hash-chained lifecycle and provider attribution needed to prove and reconcile the case. Free text is limited at collection and must not be copied into ordinary analytics. Because changing the statement or identity would invalidate the evidence hash, disclosure, correction and deletion requests require restricted assisted review.
Platform and consumer legal acceptance evidencecoachLegalAcceptances, consumerLegalAcceptancesApplicable contract, limitations, or claims period, plus holds; no automatic deletion TTL under the founder-approved schedulePreserve exact append-only identity and assent evidence unchanged because identity is necessary to prove acceptance; restricted assisted DSR only.
Anonymous purchase acceptance evidenceanonymousPurchaseLegalAcceptancesApplicable contract, financial, limitations, or claims period, plus holds; no automatic deletion TTL under the founder-approved schedulePreserve normalized purchaser email, exact legal release, acknowledgment labels, provider/amount binding, operation ID, hashes, timestamp, and HMAC seal unchanged. Restricted assisted DSR only; verify control of the purchase email before disclosure.
Verified public-booking acceptance evidenceanonymousBookingLegalAcceptancesApplicable contract, limitations, or claims period, plus holds; no automatic deletion TTL under the founder-approved scheduleCreated only after the visitor proves control of the claimed booking email. Preserve the verified email, exact legal release and acknowledgment labels, booking-link/hold binding, operation ID, timestamps, hashes, and HMAC seal unchanged. Restricted assisted DSR only; reverify control of the booking email before disclosure.
Anonymous gift fulfillment exceptionsanonymousPurchaseFulfillmentExceptionsWith the related refund and billing record, up to seven years where applicable; holds extend retentionReconciles legacy or unverifiable gifts that were automatically refunded without fulfillment. Contains provider/refund references and no plaintext purchaser email.
Coaching contract templates and undelivered draftsFirestore coachContractTemplates, relationship engagement agreement versionsUntil owner account deletion or earlier deletion/voidingUser-authored working records that have not been delivered or signed
Supplemental agreement signing packages and sealed manifestsImmutable agreement envelope and locked archive object storageDelivered or signed packages retain the seven-year agreement floor. A surviving party retains access, and legal holds extend retention.Server-derived exact-generation/hash custody only; no client-supplied authoritative digest. Coach library and source-object cleanup does not alter this evidence.
Bound supplemental agreement view receiptsFirestore coachContractDocumentViewsWith the related delivered or signed agreement, normally at least seven years; legal holds extend retentionPreserve document/version and outer manifest bindings plus viewed timestamps as restricted evidence. Restricted assisted DSR handling omits network, browser, storage, upload, scanner, and key-management internals.
Coach supplemental document library and deterministic binding indexFirestore coachContractDocuments, nested versions, coachContractDocumentOperations, and coachContractDocumentBindings; private quarantine/source objectsExpired or abandoned uploads follow workflow cleanup. Coach account deletion removes all source and quarantine generations, then the coach library, versions, operations, and binding index. A warning or unknown storage outcome blocks deletion for retry.The immutable agreement envelope, locked archive artifact, and coachContractDocumentViews evidence are separate retained records and remain available to surviving parties under the agreement retention schedule.
Delivered or signed coaching agreements and evidence certificatesRelationship engagement agreement versionsOrdinary non-renewing evidence is retained for at least seven years from the latest verified delivery, signature, completion, or later verified engagement termination; active or unverifiably terminated signed engagements fail closed to review. Automatic-renewal consent evidence is retained at least three years from consent or one year after verified subscription termination, whichever is later. Legal holds extend either schedule.Preserves a surviving party's immutable record and the minimum evidence needed for disputes and inquiries under the exact founder-approved v2 policy snapshots; related financial records follow their separate schedule.
Contract-delivery evidenceFirestore coachContractNotificationsWith the related delivered/signed agreement evidenceQueued recipient data is canceled/redacted on account deletion; provider-accepted evidence follows the agreement; known failures dead-letter; unknown provider outcomes remain blocked until traceable administrative resolution
Automatic-renewal reminder evidenceFirestore coachPaymentRemindersAt least three years from the recorded consent or one year after verified subscription termination, whichever is laterApplies to provider-accepted, in-flight, and unknown-outcome renewal notices and their signed-agreement binding; legal holds extend retention
Contract legal holds and deletion locksFirestore contractEvidenceLegalHolds (including events), contractEvidenceDeletionLocks, and related coachClientPaymentAuditEventsEvidence remains throughout an active hold; control history remains for the applicable legal-claim/audit period; no automatic TTL is currently configuredHolds require authorized release. If both parties have deleted, release creates an explicit purge requirement; unreadable hold state and remaining applicable holds fail closed. Expired purge workers are recovered through leased ownership, and every evidence deletion transaction rechecks the current fencing token. Statutory-retention integrity failures remain blocked from automatic purge and appear in the paginated admin review queue (GET /api/admin/contract-evidence-legal-holds?view=retention_reviews). An authorized reviewer must investigate the recorded reason code, correct source data only through an audited remediation process, and rerun purge; the queue never overrides retention automatically.
Applicant and intern recordsGoogle Workspace / Gmail hiring and accommodations mailboxesMinimum 4 years from application date or related personnel action; litigation holds retained until liftedAccommodation requests are stored separately from hiring decision records and are not used in hiring decisions
Hiring-portal applicant recordsFirestore hiringJobs/{jobId}/applications + private GCS hiring-resumes bucketMinimum 4 years from application date or related personnel action; litigation holds retained until liftedCareers-site applications (contact details, resume, cover note, status history, admin screening notes, sent decision-email records); same record class as the Gmail applicant-records row, spanning three systems

User-controlled content (including resumes, applications, contacts, notes, drafts, public and private coach profiles, inbox messages, real-time chats, comments, replies, support communications, coaching-session agendas and notes, intake templates and responses, goals, milestones, check-ins, files, attachments, uploaded coach/client materials, collaborative HiringCoachAI Docs, reviews, testimonials, and AI-assisted outputs) is retained while the account is active and removed or redacted during the account-deletion workflow or earlier when the owner permanently deletes it. Shared records involving another user may remain where needed to preserve that user's records, complete a transaction, prevent fraud or abuse, comply with law, or establish, exercise, or defend legal claims; the departing user's identifiers and authored content are removed or redacted as applicable. Material share grants may remain after a coach-client relationship ends so already-shared items stay available, but the owner can revoke access and account deletion removes the related grant. The full personal-data inventory is documented in the data map.

Delivered or signed coaching agreements are a narrow shared-record exception: deleting one party does not destroy the surviving party's immutable contract record. An ordinary non-renewing record is retained for at least seven years from its latest verified delivery, signature, or completion event, extended through seven years after a later verified engagement termination. A signed record whose engagement remains active or whose termination cannot be verified is not automatically purged when that floor is reached. The exact schedule is embedded in each new agreement as a hash-bound retention snapshot; a missing or altered snapshot and any evidence-integrity failure require manual review. Legacy records without a trustworthy schedule fail closed instead of being deleted. Automatic-renewal evidence uses a separate minimum: retain each consent record and its bound subscription/reminder evidence until the later of (a) three years after that consent was recorded or (b) one year after the subscription's termination was verified. If termination is unknown, the record is not eligible for purge. A replacement or amended consent has its own clock, and legal holds always extend it. Payment, tax, fraud, and security-audit records follow their own independent schedules; retaining those records does not by itself extend the agreement-version schedule.

Automatic renewal and its renewal-reminder delivery path remain feature-gated and default disabled. The retention floor applies to test or live records whenever those paths are used; disabling the feature does not shorten an existing record's period. The exact v2 policies are founder-approved and remain bound to production release manifests and operational readiness evidence.

Moderation status, findings, analysis, and reviewer decisions embedded in a coach profile remain with that profile until the record is replaced or deleted, subject to legal holds. Transactional email bodies sent through SendGrid are processed transiently for delivery; provider-held event and security records follow the provider's documented retention and applicable account configuration. Copies delivered to Google Workspace / Gmail mailboxes follow the applicable mailbox or legal-record retention schedule.

Non-promotional coaching texts are available only after relationship-specific client consent for a U.S. or Canadian number. Opt-out immediately blocks new sends, clears the raw number from the relationship, and preserves only the limited revocation evidence above. Application scheduling enforces 8:00 p.m. to 8:00 a.m. quiet hours in the client's timezone. Provider-side message redaction is requested per message; Twilio's separate limited-access compliance retention remains governed by its terms and configured account controls.

Backups

Backup layerRetentionNotes
Firestore point-in-time recovery (PITR)7 daysShort-horizon recovery from operator error
Firestore scheduled daily backups98 daysManaged by Google Cloud
Backup/export bucket soft delete90 daysObject versioning enabled
Backup/export bucket retention policy90 daysUnlocked retention policy

Backup/export buckets use object versioning, 90-day soft delete, and a 90-day retention policy.

Account deletion and backups

  • Self-service account deletion is final in active product systems once the required checks complete.
  • A deleted account's name and email remain visible in the restricted deletion lookup for no more than 30 days so an administrator can identify the recent deletion and personally respond to optional feedback. The daily retention job then removes those fields while preserving non-content deletion audit metadata for its separate 365-day period.
  • A 30-day encrypted recovery snapshot is created before destructive work begins, supporting recovery from accidental self-deletion only.
  • User-controlled content is removed from active product systems during the deletion workflow.
  • Coach contract templates and unheld, never-delivered drafts are removed during account deletion. Delivered or signed ordinary evidence remains available to a surviving counterparty and then follows its versioned seven-year minimum; active, unterminated, legacy-unscheduled, or integrity-failed records remain blocked for review. Automatic-renewal consent and reminder-delivery evidence is not purged before its separate minimum period or while held, even after both accounts are deleted. Subscription bindings, payment obligations, and related financial/audit evidence follow their separate schedules; direct identifiers are redacted where that does not break evidence integrity.
  • Queued contract and payment-reminder delivery is canceled and recipient data is redacted. In-flight or ambiguous provider outcomes are preserved for traceable administrative resolution rather than treated as unsent.
  • Contract-evidence deletion is serialized against legal-hold changes. Releasing the last applicable hold after both parties delete creates an explicit purge task; registry failures or another active hold keep the purge blocked.
  • Coach calendar deletion attempts to revoke the Google grant, then removes the encrypted local connection and private appointments-feed credential even when provider revocation is unavailable.
  • Pilot-program usage records are retained only after direct user identifiers and direct contact, name, and free-text fields are replaced with non-reversible deleted-participant identifiers, so historical program reporting can continue without identifying the deleted account.
  • The deletion audit record retains counts only and does not copy the original content arrays.
  • Direct email correspondence is a separate business record and is not automatically removed by product-account deletion. It is retained only while reasonably needed for support, security, legal compliance, or legal claims, remains subject to applicable privacy requests, and is not used for marketing unless separately authorized.
  • Account-deletion takes effect in active storage promptly. Older copies in backup snapshots and PITR windows roll off as the backup window rotates. Backup restore operations include controls to avoid restoring deleted accounts into active product state.
  • Billing, tax, and other legally required financial records are retained for the period required by applicable law, independent of account deletion.
  • Pseudonymous deletion keys and billing-owner tombstones are retained server-side only for retry, financial-lifecycle authentication, reconciliation, claims, and holds. They remain linkable or re-identifiable by authorized systems and are not anonymous. The deletion workflow must not describe them as anonymized or include them in ordinary product views. Exact legal-acceptance identity is a separate narrow exception retained unchanged to preserve proof of assent.

Institutional / customer bulk requests

Where an institutional or sponsor-program agreement provides for it, the Customer administrator may request bulk deletion or bulk export of a sponsored cohort by writing to [email protected]. Bulk requests are handled within the response window applicable to the underlying agreement (typically aligned with the data-subject-request 30-day response window under GDPR Art. 12(3), extendable for complex requests where permitted by law).

Enforcement

Pseudonymous coachOfferAnalytics events expire after approximately 25 months using Firestore TTL. coachReportPreferences holds an opt-in flag and weekly delivery lease only. The canonical privacy lifecycle deletes both collections when the coach account is deleted, includes preferences in self-service export, and exposes analytics only through a privacy-reviewed assisted DSR projection that excludes visitor session hashes. Weekly dispatch also disables orphaned preferences when the coach account or email no longer exists.

  • Retention is enforced through Firestore TTL policies and a scheduled daily job that deletes records past their retention window for configured collections. The scheduled job emits per-collection counts and is retained as operating-control evidence.
  • Backup retention is configured at the Google Cloud platform layer and is verified during quarterly internal audit.
  • The retention policy is reviewed at least annually and on any material data-flow change.

Related


← Back to the trust center

showUpgradeModal: false, modalType: migration, planName: