# Biometric Data Retention and Destruction Schedule

**Status:** DRAFT for attorney review. **Version:** 2026-08-29. **Source:** AI Human Connection full solution design, section 9.3.

This schedule is published on the website before the Privacy Policy and is referenced by it. It states, for each kind of biometric or recorded data the Platform holds, where it is stored and when it is destroyed. The retention job (`retention-sweep`) enforces every row of this table daily and reads the numbers from `config/retention.json`, so the published schedule and the code cannot drift.

| Data | Where it is stored | When it is destroyed |
|---|---|---|
| Face photo, voice sample (raw uploads) | `member-media` (private storage) | 30 days after the intro video is approved, or 30 days after the member switches to a recorded intro |
| Voice clone | ElevenLabs | On account deletion, or 30 days after cancellation with no rejoin |
| AI avatar | HeyGen | Same as the voice clone |
| Intro render, recorded intro, thumbnails | `avatar-renders`, `invite-thumbs` (private storage) | On account deletion; on cancellation the invite link stops resolving immediately |
| Meeting recordings (audio) | `ahc-recordings` (private storage) | 30 days after the transcript is stored |
| Meeting transcripts | `meeting_transcripts` | Retained while the member is active; anonymized (member id replaced with a tombstone) on deletion |

Every deletion performed under this schedule is logged to the Company's administrative audit record (`admin_actions`) with the data type, the storage location, and the time of destruction.

The attorney may change any number in this table. Changes are made in `config/retention.json` in the application and republished here in the same change.
