Deletion policy

What clears, when, and how we prove it.

A deletion promise is a timestamp and a receipt. Anything without both stays NOT ASSESSED.

Effective draft: 2026-07-25Last updated: 2026-07-25Product: Phraseless / phraseless.ink

Deletion matrix

DataDelete actionDeadlineProof
Pasted or imported writingClear the writing field or close the browser sessionImmediate in the appNo Phraseless server copy in the free lane
Local Writer ProfileUse Clear profileImmediate in that browserBrowser storage only
Queued free feedbackPause and clearImmediate before submissionUI reports queue scope
Accepted free feedbackAutomatic expiry14 daysProduction cron receipt NOT ASSESSED
Account dataVerified privacy request / account controlPublished after provider and counsel reviewNOT ASSESSED
Paid calibration excerptReview close or automatic expiryNo later than 30 daysProgram blocked until production receipt passes

Why accepted free events cannot be individually located

Free feedback intentionally carries no account or stable cross-session identifier. That prevents the service from locating one person’s accepted events later. The tradeoff is disclosed before collection: clear can remove only signals still queued in the browser; accepted records expire as a cohort.

Overdue deletion stops intake

The calibration queue contract refuses new excerpt submissions while any raw excerpt is overdue. A deletion receipt retains only the Field Note identifier, due and deletion timestamps, reason, and whether deletion was on time. It may not retain a quote, paraphrase, embedding, reversible summary, or source-derived artifact.

Account and legal records

Some payment, fraud, tax, dispute, or security records may need to be retained when required by law or needed to protect the service. Requests will use privacy@phraseless.ink. The mailbox, identity-verification process, and final response deadlines remain public-launch gates.