Data Disposal Policy
Purpose
Section titled “Purpose”The purpose of this policy is to establish guidelines and procedures for the secure disposal of customer data stored in cloud environments, ensuring compliance with data protection regulations and maintaining the confidentiality of customer information.
This policy applies to all customer data stored in cloud environments, specifically:
- Amazon S3 (Simple Storage Service)
- Fly.io platform volumes
- Google Drive
Policy
Section titled “Policy”Data Storage Locations
Section titled “Data Storage Locations”Customer data is exclusively stored in the following cloud environments:
- Amazon S3 buckets
- Fly.io platform volumes
- Google Drive
No customer data is permitted to be stored on employee laptops or any other local devices.
Data Retention
Section titled “Data Retention”- We retain customer data for as long as customers maintain an active subscription to our services.
- Upon request from a customer or user, we will delete their personally identifiable data in accordance with our Data Disposal Procedures.
- For customers who have churned (cancelled their subscription), we may delete their data after a specified period, typically 90 days after the end of their subscription, unless otherwise specified in their contract or by applicable laws and regulations. This is not required, and data may be retained indefinitely if useful for analytics, or for any other reason.
- In cases where regulatory requirements or contractual obligations necessitate longer retention periods, we will comply with those requirements.
Data Disposal Procedures
Section titled “Data Disposal Procedures”Amazon S3
Section titled “Amazon S3”- Data deletion:
- Use S3’s object deletion API or console to remove individual objects.
- For bulk deletions, use S3 batch operations or lifecycle policies.
- Bucket deletion:
- Empty the bucket of all objects and delete the bucket itself when no longer needed.
- Versioning:
- If versioning is enabled, ensure all versions of objects are deleted.
Fly.io Volumes
Section titled “Fly.io Volumes”- Data Deletion:
- Use Fly.io’s API or CLI to securely delete data from volumes.
- Volume Destruction:
- Destroy volumes that are no longer needed using Fly.io’s volume destruction feature.
Backups
Section titled “Backups”- We do not delete customer data from backups, and instead allow the backup rotation to take care of this for us.
Verification
Section titled “Verification”After deletion, verify that data has been successfully removed from all locations.
Maintain logs of all data disposal actions for audit purposes.
Employee Responsibilities
Section titled “Employee Responsibilities”- Employees are prohibited from storing customer data on local devices, including laptops.
- All data access and disposal must be done through secure, authorized cloud interfaces.
Disposal Triggers
Section titled “Disposal Triggers”- Customer Request: Promptly dispose of data upon customer request, subject to legal and contractual obligations.
- End of Retention Period: Automatically dispose of data that has reached the end of its defined retention period.
- Contract Termination: Dispose of customer data upon termination of services, as per contractual agreements.
Documentation and Auditing
Section titled “Documentation and Auditing”- Maintain detailed logs of all data disposal activities.
- Conduct regular audits to ensure compliance with this policy.
- Review and update this policy annually or when significant changes occur in data storage practices.
Compliance
Section titled “Compliance”- This policy is designed to comply with relevant data protection regulations, including but not limited to GDPR, CCPA, and other applicable laws.
- Any violations of this policy may result in disciplinary action, up to and including termination of employment.
Policy Review
Section titled “Policy Review”- This policy will be reviewed annually and updated as necessary to reflect changes in technology, business needs, or regulatory requirements.
- Last reviewed/updated: 2026-08-25
Internal & Confidential: This page is only available in the internal handbook and contains confidential information.
