Back to Hytribe
Enterprise onboarding · Appendix

Data Retention & Deletion Policy

How long we keep each category of member data, what triggers deletion, and how quickly deletion completes across primary storage, derived data, backups and sub-processors.

Section 1

Principles

  • Purpose limitation. Member data is retained only while it serves tribe formation and facilitation.
  • Behavioural signals only. Interests, goals, participation, engagement, connection depth — no medical or psychological assessment data.
  • Customer as controller. You decide what to send and when it should be deleted. Hytribe acts on documented instructions.
  • Derived data follows source data. Vector embeddings are deleted whenever the source profile is deleted.
  • Deletion is real. Deactivation removes a member from matching. Erasure removes the record. Different operations, different treatment.
  • Backups expire; they are not edited. Deleted records may persist in encrypted backups until the backup window rolls off. We disclose the window rather than hide it.
Section 2

Retention schedule

Default retention by category. "Active" means for as long as your community remains a customer.

CategoryRetentionNotes
Member profile (name, interests, goals, availability, timezone)Active + 30 days after terminationDeleted earlier on erasure request.
Platform user IDActive + 30 daysPseudonymous upsert key.
Vector embeddingSame as source profileDeleted whenever the profile is deleted or materially changes.
Onboarding responsesActive + 30 daysStructured fields survive; raw text can be shortened on request.
Psychological profile / WHO-5 / UCLA-3Not processed (enterprise)Disabled at tenant level.
Tribe recordsActive + 30 daysMembership and formation metadata.
Health scores & survey outcomesActive + 30 daysRetained only in aggregated form after tribe retires.
Audit logs12 monthsRetained for security investigation; minimal personal data.
API keysUntil revokedStored hashed. Revocation is immediate.
Database backupsRolling backup windowDeleted records persist until PITR window rolls off.
Application logs30 daysProfile content is not logged.
Sandbox — customer data30 days rollingPurged regardless of contract status.
Sandbox — demo dataPermanentSeeded synthetic profiles. No real personal data.
Section 3

Deletion triggers

01
Member deactivation

DELETE /members/{platform_user_id}. The member is soft-deactivated and excluded from future matching. Profile and embedding are retained so they can be reinstated. This is not erasure.

Effect: immediate · data retained
02
Member erasure request

On a right-to-erasure request, the member record, onboarding responses, derived profile, vector embedding and tribe membership references are permanently deleted.

Target: 30 days from request
03
Contract termination

On termination you elect export or deletion. All member data, embeddings, tribe records and community configuration for that community_id are deleted, and API keys revoked.

Target: 30 days from termination
04
Scheduled expiry

Categories with fixed windows — audit logs, application logs, backups — expire automatically on the schedule in Section 2.

Automated
05
Sandbox purge

Customer-created data in the sandbox environment is deleted on a rolling 30-day cycle, independent of any contract event. Seeded synthetic demo data is preserved.

Automated · 30 days
Section 4

Where deletion has to reach

LocationCompletesNotes
Primary database (Neon)ImmediateRecord and embedding removed.
Database backups / PITRBackup windowCannot be selectively purged; window disclosed on request.
Application logsLog retention windowProfile content is not logged in the first place.
OpenAI (embeddings)Provider windowAPI inputs retained briefly for abuse monitoring per OpenAI's published policy.
Anthropic (enrichment / Anton)Provider windowAs above, per Anthropic's published policy.
Resend (email)Provider windowDelivered email content and addresses.
Messaging platformsNot applicableMessages delivered into your own Slack, Discord or Telegram tenancy remain under your control.
The honest framing
We cannot promise instant deletion from a third-party model provider's transient logs. Hytribe deletes from its own systems within its stated window, and sub-processors delete API inputs on their own published schedules, which we name.
Section 5

Summary of customer-facing commitments

CommitmentTarget
Member erasure request completed30 days
Full customer data deleted after termination30 days
Data export provided before termination14 days
API key revocationImmediate
Residual copies in encrypted backups expireBackup window
Customer-created sandbox data purged30 days
Notice before adding a sub-processor30 days

Related: Security & Data Handling · Data Processing Agreement

Enterprise sales

Privacy review + pilot, in the same 30 days

DPA, retention appendix, sub-processor list and DPIA support — bundled with a scoped pilot for your privacy office.

30-day paid pilot Enterprise DPA ready
Enterprise pilot · DPA + sandbox + solutions engineer
Book pilot call