Deletion policy
What clears, when, and how we prove it.
A deletion promise is a timestamp and a receipt. Anything without both stays NOT ASSESSED.
Deletion matrix
| Data | Delete action | Deadline | Proof |
|---|---|---|---|
| Pasted or imported writing | Clear the writing field or close the browser session | Immediate in the app | No Phraseless server copy in the free lane |
| Local Writer Profile | Use Clear profile | Immediate in that browser | Browser storage only |
| Queued free feedback | Pause and clear | Immediate before submission | UI reports queue scope |
| Accepted free feedback | Automatic expiry | 14 days | Production cron receipt NOT ASSESSED |
| Account data | Verified privacy request / account control | Published after provider and counsel review | NOT ASSESSED |
| Paid calibration excerpt | Review close or automatic expiry | No later than 30 days | Program blocked until production receipt passes |
Why accepted free events cannot be individually located
Free feedback intentionally carries no account or stable cross-session identifier. That prevents the service from locating one person’s accepted events later. The tradeoff is disclosed before collection: clear can remove only signals still queued in the browser; accepted records expire as a cohort.
Overdue deletion stops intake
The calibration queue contract refuses new excerpt submissions while any raw excerpt is overdue. A deletion receipt retains only the Field Note identifier, due and deletion timestamps, reason, and whether deletion was on time. It may not retain a quote, paraphrase, embedding, reversible summary, or source-derived artifact.
Account and legal records
Some payment, fraud, tax, dispute, or security records may need to be retained when required by law or needed to protect the service. Requests will use privacy@phraseless.ink. The mailbox, identity-verification process, and final response deadlines remain public-launch gates.