Skip to content

Data lifecycle inventory ​

This inventories the persisted collections in apps/api/src/db/persistence.ts and the separately persisted settings record. It describes implemented behavior; it does not establish a lawful retention policy or certify GDPR compliance. The source of truth for deletion is lifecycle.ts, household.ts, retention.ts and the assistant/upload cleanup functions.

Scope: the live API database. Browser/native caches, third-party providers, object-store versions, logs and backups have separate lifecycles below. Logical expiry is not physical deletion. Database deletion reaches durable storage only after a successful persistence flush.

Identity and service records ​

CollectionExportDeletion and expiry
accountsPublic account fields, preferences, subscription metadata and grants; no password hash, provider subject or sealed receiptAccount deletion removes the row after owned open families are transferred or closed
sessionsNot in account exportLogout/account deletion; hourly cleanup at absolute expiry, including sessions never used again
emailCodesNot in account exportVerification/reset use, attempt exhaustion, account deletion and hourly cleanup after expiry
apiTokensOwner's metadata, excluding rate windows/request keys; hashes are map keys and not exportedExplicit revocation, suspension/account deletion; expired token metadata has no scheduled deletion
pushTokensNot in account exportExplicit unregistration, invalid-provider-token handling, account deletion; no age-based expiry
inviteTokensNot in account exportInvite lifecycle/member removal/family purge; no independent age-based sweep
operatorsNot in family-account exportOperator CLI removal; password hashes, sealed MFA seeds and recovery hashes are restricted to administration
adminSessionsNot in account exportLogout/operator removal; authentication rejects idle/absolute expiry; hourly cleanup removes absolute-expired rows
adminAuditNot in family-account exportAccount deletion clears matching target/reason/IP fields; no age-based purge. Operator IDs and action/timestamp remain
settingsNot in account exportGlobal operator configuration; remains across account/family removal

The authentication sweep does not change sign-in or code validity windows. It removes already unusable records without waiting for the user to return. API-token metadata, audit records and global configuration are intentionally outside that sweep; deciding their retention requires a separate policy.

Family records ​

All family-scoped collections in the following table are removed when a closed family's 30-day recovery period ends. The hourly retention job performs that purge. Closing a family does not immediately delete its records.

“Visible” refers to the existing account-export filters. This inventory does not replace cross-account authorization tests, including per-kind week records and legacy/temporary membership variants.

CollectionAccount exportMember/account removal while family remains
familiesAccessible family metadataFamily persists; creator must transfer or close before account deletion
familyGovernanceEventsAuthorized family ownership auditActor references anonymized; pending requests canceled when matching members are removed
membersCalling member's row for each exported membershipMember row removed; other members' visibility references cleaned
eventsVisible eventsRemoved-member calendar subscription events deleted; shared events lose member references and attribution
listsVisible listsMember's personal lists deleted; shared lists lose ownership/creator attribution
itemsItems belonging to exported listsPersonal-list items deleted; shared items lose creator/completer/shopper references
listCategoriesCategories belonging to exported listsDeleted with removed personal lists
purchasesShopping history belonging to exported listsDeleted with removed personal lists; shared-list history retained
calendarFeedsCalling member's metadata, excluding secret hashRemoved with member
calendarSubscriptionsCalling member's metadata, excluding URL and last errorRemoved with member, including imported events
specialDaysVisible special daysAttendee/creator and deleted-list references cleaned
routinesRoutines within member visibilitySole-assignee routines deleted; rotations reassign to remaining members; creator reference cleared
routineCompletionsCompletions belonging to exported routinesRemoved when credited to removed member or when routine was deleted
recipesFamily recipesCreator attribution cleared; content retained
mealsFamily mealsCreator attribution cleared; content retained
timetablesTimetables within member visibilityRemoved member's timetable deleted; updater attribution cleared elsewhere
placesFamily placesCreator attribution cleared; content retained
locationSharesCalling member's current recordRemoved with member; no age-based deletion sweep
arrivalAlertsAlerts notifying calling memberRecipient removed; alert deleted when no recipients remain
messagesFamily messagesAuthored messages deleted; member removed from other messages' read receipts
albumsVisible albumsMember-owned private albums deleted; shared ownership reference cleared
photosVisible photo metadataAuthored photos and photos in deleted private albums removed; object deletion queued
foldersVisible foldersMember-owned private folders deleted; shared ownership reference cleared
filesVisible file metadataAuthored files and files in deleted private folders removed; attachments of deleted photos/messages removed; object deletion queued
contactsFamily contactsCreator attribution cleared; content retained
budgetAccountsFamily budget accountsCreator attribution cleared
budgetCategoriesFamily budget categoriesCreator attribution cleared
transactionsFamily budget transactionsMember/creator attribution cleared; shared financial record retained
feedPostsFamily feed postsAuthored posts deleted
weekFamily week records, excluding sitter-link secret hashesPer-kind cleanup: private child/member records removed, shared planning records cleaned/reassigned; see deleteMemberData
conversationsCalling member's conversationsRemoved with member; inactivity retention also applies
chatMessagesCalling member's conversation messages and orphan messagesRemoved with conversation/member
assistantDraftsCalling member's conversation drafts and orphan draftsRemoved with conversation/member
assistantMemoriesCalling member's memoriesRemoved with member; separate from conversation inactivity cleanup
assistantCreditsEntries paid by account or attributable to its membersPayer/member references cleared on removal; family ledger removed at family purge
remindersReminders created by or addressed to calling memberAuthored reminders deleted; other recipient lists cleaned; empty reminders deleted

Content retained after attribution is removed can still contain names or personal details in free text. Clearing identifiers is not a guarantee of anonymization. The shared-content retention policy must address that before public launch.

The operator-owned creditPacks catalog contains no payment credentials. It is not family-scoped and remains across family deletion. Granted pack snapshots (packId and packCredits) follow the assistantCredits ledger lifecycle.

Delivery and object-cleanup records ​

CollectionExportCleanup
pushDeliveriesNot in account exportRemoved with relevant account/member/family; terminal records older than 30 days are swept hourly; pending records follow delivery/source expiry rules
sentRemindersNot in account exportDeduplication history; event/member lifecycle removes relevant keys; no general age-based purge
orphanBlobsNot in account exportContains object keys awaiting deletion; removed on successful object-store deletion; ten failed attempts make the record terminal for operator review

The upload sweep also removes unposted message-attachment rows older than 24 hours and queues their objects for deletion. A queued deletion is not proof that the provider deleted the object. Monitor pending and terminal orphan records. Bucket versioning, incomplete uploads and backup copies need storage-side lifecycle rules and real-provider verification.

Data outside these collections ​

  • Assistant providers: conversation deletion does not call a provider deletion API. Provider processing/retention and BYOK choices need documented terms and consent. Conversation inactivity cleanup does not remove saved memories.
  • Original-media exports: ZIP parts are produced on demand, not persisted by the API. Downloaded copies remain on the recipient's device.
  • Local app storage: session/family fencing and sign-out cleanup are separate from server deletion. An offline device cannot learn of remote revocation until reconnecting. Verify native encryption, backup exclusions and widget cleanup on signed devices.
  • Backups and logs: live-store deletion does not erase snapshots, log archives or object versions. Define retention, access, encryption-key custody and an erasure-aware restore procedure. Do not reconnect a restored old database to production before reconciling later erasures.

Outstanding policy and evidence ​

Before public launch, approve shared-content retention, children's-data handling, audit/token metadata retention, location expiry, provider retention and backup erasure. Test export/deletion using independent accounts, real object storage and signed native builds. A passing local retention test proves the specified database cleanup behavior only.

Fellesly: the family, in one place.