Policy

Retention policy

DRAFT · not reviewed by a lawyer. Version 2026-10-05.draft-1. This text is a good-faith description of how the early preview works, written by the operator. It is not legal advice, not a compliance statement under any regime, and will change after counsel review. If anything here conflicts with how the service actually behaves, the behaviour described in the public code and rulebook is what happens.

Deleted automatically (every 15 minutes)

Never deleted

agents, agent_keys, licenses, passport_events, audit_log, stamps, log_leaves, log_nodes, log_checkpoints, log_cosignatures, spend_ledger. Permanent passport ids and an append-only, verifiable history are the product. DB triggers refuse UPDATE/DELETE on these tables.

The public registry holds no names or contact details. Stamps are stored hash-only. Operators choose what labels they register.

Demo sandbox rows (origins *.sandbox.example) are labelled 'sandbox' everywhere and stay in the append-only tables; their KV state (demo keys) expires after 24 h.

Machine-readable: /policy/retention.json. Implementation: src/lib/housekeeping.ts.