Data Retention & Deletion Policy
Last updated: January 2025
How long different data types are kept, what can be removed, and how deletion works.
TL;DR
- •Account data: retained for life of account, deleted upon account deletion
- •User-uploaded content: deleted immediately upon request (unless incorporated into immutable records)
- •Provenance metadata: retained permanently (cannot be deleted)
- •Operational logs: retained 12-36 months depending on jurisdiction
- •Immutable data is excluded from deletion rights under GDPR Article 17(3)
1. Purpose of This Policy
SOVEREIGN\PROVENANCE exists to preserve digital truth through cryptographic hashing, timestamping, lineage logging, archival storage, provenance manifests, dataset and model passports, and integrity records.
Some data must be retained permanently for provenance integrity. Other data may be deleted, anonymized, or sealed. This policy explains the difference.
2. Categories of Data and Retention Periods
A. Account & Profile Data
Includes name, email, organization, optional profile details.
Retention: Retained for the life of the account. Deleted upon account deletion (unless needed for an ongoing legal claim).
B. User-Uploaded Content (Non-Immutable)
Includes primary files you upload: text, media, code, datasets, documents, models.
Retention: Stored until you delete them. Removed immediately upon deletion request. Cached workflow copies deleted after task completion.
Exception: If the content was hashed, timestamped, or anchored, the immutable metadata persists even if the content is deleted.
C. Provenance Metadata (Immutable)
Includes cryptographic hashes, timestamp receipts, provenance manifests, lineage logs, archival references (CIDs, OTS commitments), dataset/model passport entries, and synthetic visibility indicators.
Retention: Retained permanently. Cannot be deleted, altered, or purged. Persists even after account deletion. Corrections create new logs, not retroactive edits.
D. Operational Logs
Includes authentication logs, access logs, workflow execution logs, error logs, security incident logs.
Retention: Retained for 12–36 months depending on jurisdiction and security requirements. Logs tied to provenance proofs may be retained indefinitely for integrity.
Logs used for abuse detection or legal defense may be retained longer when required.
E. Analytics Data (Non-Personal)
Includes aggregated usage analytics, system performance metrics, anonymized workflow statistics.
Retention: Retained indefinitely in anonymized format. Never tied back to a personal profile.
3. Deletion Process
When a user requests deletion, the system performs three coordinated actions:
A. Delete All Mutable Data
Account profile, uploaded content, non-essential logs, workflow-generated temporary files.
B. Preserve Immutable Data
Per the Immutable Data Policy, we cannot delete cryptographic hashes, timestamp receipts, manifests, lineage logs, archival proofs, sovereignty & jurisdiction tags, or synthetic visibility metadata. These remain permanently part of the provenance chain.
C. Pseudonymize Historical References
When possible, the system will remove direct identifiers, replace names with pseudonyms, and retain structural metadata without personal details. This is possible only when it does not compromise provenance integrity.
4. Account Deletion vs Artifact Deletion
Deleting an Artifact: The artifact file is removed, mutable metadata is removed, but immutable metadata persists.
Deleting an Account: All mutable personal data is removed, all artifacts you uploaded are deleted (unless shared in a multi-user context), and immutable provenance records persist but identifiers may be pseudonymized.
5. Enterprise, Government & Research Retention Requirements
Enterprise and institutional customers may have special requirements under SOC 2, HIPAA (for metadata only), FedRAMP, GDPR, CCPA/CPRA, LGPD, Department of Defense/DFARS, NSF/NIH research programs.
Modern Ancients supports extended retention for audit, sealed or redacted metadata views, regional sovereign storage zones, compliance-locked retention rules, and contractually governed deletion timelines.
6. Legal Holds
If Modern Ancients receives a court order, legal notice, subpoena, or preservation request, we may place a legal hold on specific account or workflow data.
During the hold period, deletion, anonymization, and pseudonymization are suspended. Immutable proofs remain unaffected. Legal holds end once obligations are fulfilled.
7. Special Cases
- Abuse or Fraud Investigations: Data relevant to abuse investigations may be retained beyond normal timelines
- Guardian Nodes / Sovereign Zones: Institutional nodes may enforce custom regional retention rules
- Shared or Collaborative Artifacts: If multiple users co-own or co-author an artifact, deletion may be restricted to maintain lineage
- Public Registry Entries: Artifacts published with public visibility cannot be retracted from immutably anchored registries
8. How Users Can Request Deletion
Users may request deletion or pseudonymization by emailing weare@modernancients.com.
Requests must include account email, list of artifacts (if applicable), confirmation of identity, and jurisdiction (to determine applicable legal framework).
We respond within 30 days (global standard), 45 days (CCPA/CPRA maximum), or 60 days for complex high-volume requests.