Retention & Destruction Schedule
Version 2026-07-19.1
PLACEHOLDER — PENDING COUNSEL REVIEW. The timings below describe how the system is actually built and are enforced by automated sweeps. Counsel review may tighten the language but the product already honors these windows.
Photos
| Data | Where it lives | Kept for |
|---|---|---|
| Try-on selfies | Processed in memory only | Never written to our storage. Discarded when your preview renders. |
| Unsaved previews | Our private storage | Deleted within 24 hours by an automated sweep. |
| Saved previews | Our private storage | Until you delete them or your account. |
| Barber catalog photos | Our private storage | Until the barber retires the style or leaves the platform. |
| Client visit photos (taken by your barber) | Our private storage | Until the barber or client deletes them, or account deletion. |
Everything else
| Data | Kept for |
|---|---|
| Account profile | Until account deletion (then anonymized). |
| Consent records | Retained permanently as legal evidence, de-identified on account deletion (no photos are ever part of a consent record). |
| Appointments & payment records | Retained per tax/accounting requirements. |
| Data-export bundles | Download link expires after 24 hours; the bundle is deleted after that. |
| Audit logs | Retained for security and compliance review. |
Vendor copies
Our AI vendor (Google Gemini API) processes try-on photos under API terms that do not retain them for training. Where a vendor exposes a deletion API, our sweep calls it.
How deletion happens
Automated hourly sweeps enforce the photo windows above and every deletion is recorded in an audit log — that log is the proof this schedule is real.