Draft — to be reviewed by a lawyer specialized in privacy law before launch. Periods marked "to be confirmed" depend on legal obligations (tax law in particular) still to be verified.
Principles
- We keep information only as long as needed for the purpose it was collected for; afterwards it is destroyed or anonymized (no possible link to a person).
- Destruction is automatic: every day the database computes what has expired (scheduled job) and a server process deletes the files, then records it in the audit log.
- The shortest periods apply by default; only a paid option chosen by the organization extends retention of original videos.
Periods
| Information | Retention period | End of retention |
|---|---|---|
| Original uploaded video | 7 days after analysis (Discovery, Player premium), 14 days (Tournament pass), 30 days (Team, Pro, Club, Institution); never-analyzed upload: same period from upload (at least 30 days while analysis is running) | file deleted; date recorded (original_deleted_at) |
| "Keep originals" option | until the date paid by the organization | back to the rule above |
| Viewing copy (HLS) | 30 days (Discovery), 1 year (Tournament pass, Team), 2 years (Pro, Club), per contract (Institution), from match creation | folder deleted; date recorded (playback_deleted_at) |
| Viewing copy of an account without an active subscription | the later of: 90 days after the subscription ends, or the last plan's period | folder deleted |
| Statistics, events, trajectories, roster | as long as the organization's account exists | destroyed with the organization |
| Player entry removed on request | immediately | entry and individual statistics deleted; team statistics remain |
| Closed organization (account deletion by its only owner) | none: immediate destruction | all match files, then all of the organization's rows |
| Deleted user account | 7-day cancellation window after the request (30 days at most) | account, memberships and authentication factors deleted |
| Database backups | 7 days (daily Supabase backups; longer if point-in-time recovery is enabled) | automatic expiry |
| Audit log (video access, exports, settings, destructions) | 12 months | automatic monthly purge |
| Web server logs (truncated IP address) | 14 days; system journal: 30 days at most | automatic rotation |
| Rights requests (register) | as long as needed to demonstrate how they were handled (proposal: 3 years, to be confirmed) | deletion |
| Confidentiality incident register | at least 5 years after the incident became known (to be verified) | deletion |
| Billing records (Stripe, accounting) | as required by tax law (to be confirmed, often 6 years) | deletion |
| Transient computing data (frames sent to the GPU, appearance embeddings) | duration of a match's processing | erased when the job ends |
Exceptions
- Litigation or investigation: information covered by a proceeding may be kept until it ends; the decision is recorded by the privacy officer.
- Model training (only with the team's agreement): retained images are deleted when the team withdraws its agreement; non-identifying derived data may be kept.
Destruction methods
- Object or disk storage: objects deleted (providers then wipe media under their own procedures).
- Database: rows deleted; backups expire per the table.
- Founder's computers and devices: no copy of client videos outside the planned environments; secure wiping on disposal.
Technical implementation
Database: retention_sweep() (pg_cron, 04:23 UTC daily), process_due_privacy_requests() (04:41), retention_queue table. Server: python -m ufs.retention (--dry-run simulation mode). See docs/PRIVACY.md.