Data Retention Policy

Last updated: June 2026

⚠️ Placeholder — Retention periods not yet defined. Data retention periods must be determined in consultation with legal counsel, privacy counsel, and customers' regulatory requirements (e.g., PHMSA record retention rules for pipeline operators).

Overview

[PLACEHOLDER] NuroTrack retains data for as long as necessary to provide the service and meet applicable legal, regulatory, and contractual obligations.

Retention Periods

Data TypeRetention PeriodNotes
User accounts and profiles[TBD]Retained while account is active; deleted upon verified deletion request
Project and weld records[TBD — consider PHMSA/DOT retention requirements]Retained for organization; configurable per organization agreement
Uploaded files and documents[TBD]Retained per project lifecycle; deleted on project/org deletion request
Audit logs[TBD — typically 3–7 years for compliance contexts]Audit logs cannot be deleted by users; legal hold applies
Authentication events[TBD]Via Supabase Auth logs

Deletion Requests

[PLACEHOLDER] Users may request deletion of their account and associated personal data by submitting a deletion request through their account settings or by contacting [PRIVACY CONTACT — TBD]. Organization data (project records, weld logs) will be handled per the organization agreement. Audit logs may be subject to legal holds and regulatory retention requirements.

Regulatory Context

[PLACEHOLDER] Pipeline operators using NuroTrack may have regulatory data retention requirements under PHMSA, DOT, or other agencies. NuroTrack supports data retention readiness but does not guarantee compliance with any specific regulation. Organizations are responsible for verifying that their use of NuroTrack meets their own regulatory retention obligations.

Backup and Recovery

[PLACEHOLDER] Automated backups are performed by our infrastructure provider (Supabase). Backup retention periods and recovery objectives will be documented here when finalized.