Skip to content

Retention and destruction policy

Last updated: October 1, 2026

Draft — to be reviewed by a lawyer specialized in privacy law before launch. Periods marked "to be confirmed" depend on legal obligations (tax law in particular) still to be verified.

Principles

  • We keep information only as long as needed for the purpose it was collected for; afterwards it is destroyed or anonymized (no possible link to a person).
  • Destruction is automatic: every day the database computes what has expired (scheduled job) and a server process deletes the files, then records it in the audit log.
  • The shortest periods apply by default; only a paid option chosen by the organization extends retention of original videos.

Periods

InformationRetention periodEnd of retention
Original uploaded video7 days after analysis (Discovery, Player premium), 14 days (Tournament pass), 30 days (Team, Pro, Club, Institution); never-analyzed upload: same period from upload (at least 30 days while analysis is running)file deleted; date recorded (original_deleted_at)
"Keep originals" optionuntil the date paid by the organizationback to the rule above
Viewing copy (HLS)30 days (Discovery), 1 year (Tournament pass, Team), 2 years (Pro, Club), per contract (Institution), from match creationfolder deleted; date recorded (playback_deleted_at)
Viewing copy of an account without an active subscriptionthe later of: 90 days after the subscription ends, or the last plan's periodfolder deleted
Statistics, events, trajectories, rosteras long as the organization's account existsdestroyed with the organization
Player entry removed on requestimmediatelyentry and individual statistics deleted; team statistics remain
Closed organization (account deletion by its only owner)none: immediate destructionall match files, then all of the organization's rows
Deleted user account7-day cancellation window after the request (30 days at most)account, memberships and authentication factors deleted
Database backups7 days (daily Supabase backups; longer if point-in-time recovery is enabled)automatic expiry
Audit log (video access, exports, settings, destructions)12 monthsautomatic monthly purge
Web server logs (truncated IP address)14 days; system journal: 30 days at mostautomatic rotation
Rights requests (register)as long as needed to demonstrate how they were handled (proposal: 3 years, to be confirmed)deletion
Confidentiality incident registerat least 5 years after the incident became known (to be verified)deletion
Billing records (Stripe, accounting)as required by tax law (to be confirmed, often 6 years)deletion
Transient computing data (frames sent to the GPU, appearance embeddings)duration of a match's processingerased when the job ends

Exceptions

  • Litigation or investigation: information covered by a proceeding may be kept until it ends; the decision is recorded by the privacy officer.
  • Model training (only with the team's agreement): retained images are deleted when the team withdraws its agreement; non-identifying derived data may be kept.

Destruction methods

  • Object or disk storage: objects deleted (providers then wipe media under their own procedures).
  • Database: rows deleted; backups expire per the table.
  • Founder's computers and devices: no copy of client videos outside the planned environments; secure wiping on disposal.

Technical implementation

Database: retention_sweep() (pg_cron, 04:23 UTC daily), process_due_privacy_requests() (04:41), retention_queue table. Server: python -m ufs.retention (--dry-run simulation mode). See docs/PRIVACY.md.