Legal & Trust
Data Retention Policy
Retention periods and deletion approach for stored data.
⚠️ Requires legal review before production release.
This policy describes retention and deletion as implemented and planned based on this repository. It is not legal advice.
Data Retention Policy
Last updated: 2026-07-20
This policy explains how long Klugliv keeps different categories of data and how you can request deletion.
Retention principles
We aim to:
- keep data only as long as needed for the service
- delete or anonymise data when you ask
- keep operational backups only as long as needed for stability and security
Where third-party providers influence retention, retention may be governed by their operational schedules.
Receipts (images and extracted fields)
Receipt images
- Current behavior: receipt images are stored privately (Supabase Storage today; S3 dual-write may be enabled in the AWS migration slice).
- Retention: stored while you keep your receipts in the app.
- Deletion: you can delete receipts in the app; see Your Rights & GDPR Requests.
Backups may temporarily retain copies after deletion.
OCR output and extracted structured data
Extracted and derived receipt data (for example, totals and line items) is stored as part of your receipt record.
Retention follows the receipt record:
- stored while your receipt exists
- deleted when you delete the receipt
Shopping history, household memory, and trips
Derived shopping and household memory data is stored while it helps provide your product experience.
When you delete receipts, related derived records are updated or removed according to the data model.
Authentication data and security logs
- Authentication records and access control are handled by the authentication provider in the current system (Supabase Auth today).
- Operational security logs (for example, API/Lambda logs) are retained for a limited time.
In the AWS migration slice, CloudWatch log retention is configured in Terraform (currently 7–14 days, depending on the log group).
Temporary uploads and processing
During processing (for example, uploading and OCR), we may handle receipt images transiently in memory and request payloads.
We do not intentionally store temporary payloads beyond the time needed to process the request.
Deleted accounts and deletion exceptions
When you request deletion, we will try to:
- delete the primary data you requested
- keep backups only for limited periods needed for reliability and security
Some technical retention may be unavoidable for operational reasons.
How to request deletion or changes
Follow: