# Briard-AI data lifecycle and retention status

Version 1.0 — reviewed August 11, 2026

This page separates current behavior from contract terms that are not yet approved.

| Data class | Current lifecycle | Deletion/export path | Contractual period |
| --- | --- | --- | --- |
| Account and organization records | Retained while the workspace is active and as needed for security, billing, dispute, and legal records | Verified requests are initiated from Account or privacy@briard-ai.app | No fixed public deletion SLA is currently committed |
| Governance metadata and attestations | Retained with the active tenant workspace | Workspace export or verified deletion request; append-only integrity records may require de-identification rather than destructive rewriting | No fixed public deletion SLA is currently committed |
| Evidence objects | Private and organization-scoped while retained | Eligible objects are included in verified export/deletion review | No fixed public deletion SLA is currently committed |
| Ledger events and timestamp receipts | Append-only integrity history | Preserved, de-identified, or access-restricted as needed to retain chain integrity and legal/security evidence | No fixed public deletion SLA is currently committed |
| Billing records | Retained as required for payment, tax, dispute, and fraud controls | Stripe Portal plus a verified support/privacy request | Determined by provider and applicable recordkeeping obligations |
| Consent-gated analytics | Collected only after analytics permission | Privacy choices withdraw future analytics collection; privacy requests address eligible retained identifiers | Provider retention applies; Briard-AI does not currently promise a shorter contractual period |
| Provider backups and logs | Subject to provider-managed rolling retention and security operations | Age out through provider lifecycle or verified operational deletion where available | No customer-specific public backup-deletion period is currently committed |

## Incident communication status

Security reports are accepted at security@briard-ai.app. Briard-AI has an internal escalation path, but no public contractual breach-notification deadline is currently approved. Any deadline in a future order or DPA must be reviewed and accepted by the contracting parties.

This document is a factual status sheet, not a DPA, service-level agreement, or legal opinion.
