PLACEHOLDER — not yet reviewed by counsel. The periods below are engineering defaults (
ops.retention_policies, shipped disabled); counsel sets the final schedule (LEG-1) and it is enabled in the database only then.Retention schedule
| Data | Kept for | Then |
|---|---|---|
| Account, phone number | While the account exists | Deleted on account deletion |
| Twin photo, portrait, voice sample, voice reference, rendered clips | While the twin exists | Deleted on twin or account deletion; retrain replaces the old assets |
| Call transcripts | [365 days, draft] | Purged; recaps kept without the transcript |
| What your twin remembers about a caller | While the caller keeps memory on | Deleted when the caller turns memory off or either account is deleted |
| Per-call cost and usage rows | [400 days, draft] | Aggregated into daily totals, rows purged |
| Hashed contact numbers | While contact matching is on | Deleted when turned off or on account deletion |
| Crash and error reports (Sentry) | 90 days | Expire automatically |
| Server logs | 3–30 days depending on the provider | Expire automatically; contain no transcript text and only hashed user ids |
| Takedown and data-request records | [3 years, draft] | Kept as a compliance record |
Backups are retained for 7 days (point-in-time recovery) and are overwritten on that cycle; deleted data can persist in a backup for up to that long.