Data lifecycle inventory
This inventories the persisted collections in apps/api/src/db/persistence.ts and the separately persisted settings record. It describes implemented behavior; it does not establish a lawful retention policy or certify GDPR compliance. The source of truth for deletion is lifecycle.ts, household.ts, retention.ts and the assistant/upload cleanup functions.
Scope: the live API database. Browser/native caches, third-party providers, object-store versions, logs and backups have separate lifecycles below. Logical expiry is not physical deletion. Database deletion reaches durable storage only after a successful persistence flush.
Identity and service records
| Collection | Export | Deletion and expiry |
|---|---|---|
accounts | Public account fields, preferences, subscription metadata and grants; no password hash, provider subject or sealed receipt | Account deletion removes the row after owned open families are transferred or closed |
sessions | Not in account export | Logout/account deletion; hourly cleanup at absolute expiry, including sessions never used again |
emailCodes | Not in account export | Verification/reset use, attempt exhaustion, account deletion and hourly cleanup after expiry |
apiTokens | Owner's metadata, excluding rate windows/request keys; hashes are map keys and not exported | Explicit revocation, suspension/account deletion; expired token metadata has no scheduled deletion |
pushTokens | Not in account export | Explicit unregistration, invalid-provider-token handling, account deletion; no age-based expiry |
inviteTokens | Not in account export | Invite lifecycle/member removal/family purge; no independent age-based sweep |
operators | Not in family-account export | Operator CLI removal; password hashes, sealed MFA seeds and recovery hashes are restricted to administration |
adminSessions | Not in account export | Logout/operator removal; authentication rejects idle/absolute expiry; hourly cleanup removes absolute-expired rows |
adminAudit | Not in family-account export | Account deletion clears matching target/reason/IP fields; no age-based purge. Operator IDs and action/timestamp remain |
settings | Not in account export | Global operator configuration; remains across account/family removal |
The authentication sweep does not change sign-in or code validity windows. It removes already unusable records without waiting for the user to return. API-token metadata, audit records and global configuration are intentionally outside that sweep; deciding their retention requires a separate policy.
Family records
All family-scoped collections in the following table are removed when a closed family's 30-day recovery period ends. The hourly retention job performs that purge. Closing a family does not immediately delete its records.
“Visible” refers to the existing account-export filters. This inventory does not replace cross-account authorization tests, including per-kind week records and legacy/temporary membership variants.
| Collection | Account export | Member/account removal while family remains |
|---|---|---|
families | Accessible family metadata | Family persists; creator must transfer or close before account deletion |
familyGovernanceEvents | Authorized family ownership audit | Actor references anonymized; pending requests canceled when matching members are removed |
members | Calling member's row for each exported membership | Member row removed; other members' visibility references cleaned |
events | Visible events | Removed-member calendar subscription events deleted; shared events lose member references and attribution |
lists | Visible lists | Member's personal lists deleted; shared lists lose ownership/creator attribution |
items | Items belonging to exported lists | Personal-list items deleted; shared items lose creator/completer/shopper references |
listCategories | Categories belonging to exported lists | Deleted with removed personal lists |
purchases | Shopping history belonging to exported lists | Deleted with removed personal lists; shared-list history retained |
calendarFeeds | Calling member's metadata, excluding secret hash | Removed with member |
calendarSubscriptions | Calling member's metadata, excluding URL and last error | Removed with member, including imported events |
specialDays | Visible special days | Attendee/creator and deleted-list references cleaned |
routines | Routines within member visibility | Sole-assignee routines deleted; rotations reassign to remaining members; creator reference cleared |
routineCompletions | Completions belonging to exported routines | Removed when credited to removed member or when routine was deleted |
recipes | Family recipes | Creator attribution cleared; content retained |
meals | Family meals | Creator attribution cleared; content retained |
timetables | Timetables within member visibility | Removed member's timetable deleted; updater attribution cleared elsewhere |
places | Family places | Creator attribution cleared; content retained |
locationShares | Calling member's current record | Removed with member; no age-based deletion sweep |
arrivalAlerts | Alerts notifying calling member | Recipient removed; alert deleted when no recipients remain |
messages | Family messages | Authored messages deleted; member removed from other messages' read receipts |
albums | Visible albums | Member-owned private albums deleted; shared ownership reference cleared |
photos | Visible photo metadata | Authored photos and photos in deleted private albums removed; object deletion queued |
folders | Visible folders | Member-owned private folders deleted; shared ownership reference cleared |
files | Visible file metadata | Authored files and files in deleted private folders removed; attachments of deleted photos/messages removed; object deletion queued |
contacts | Family contacts | Creator attribution cleared; content retained |
budgetAccounts | Family budget accounts | Creator attribution cleared |
budgetCategories | Family budget categories | Creator attribution cleared |
transactions | Family budget transactions | Member/creator attribution cleared; shared financial record retained |
feedPosts | Family feed posts | Authored posts deleted |
week | Family week records, excluding sitter-link secret hashes | Per-kind cleanup: private child/member records removed, shared planning records cleaned/reassigned; see deleteMemberData |
conversations | Calling member's conversations | Removed with member; inactivity retention also applies |
chatMessages | Calling member's conversation messages and orphan messages | Removed with conversation/member |
assistantDrafts | Calling member's conversation drafts and orphan drafts | Removed with conversation/member |
assistantMemories | Calling member's memories | Removed with member; separate from conversation inactivity cleanup |
assistantCredits | Entries paid by account or attributable to its members | Payer/member references cleared on removal; family ledger removed at family purge |
reminders | Reminders created by or addressed to calling member | Authored reminders deleted; other recipient lists cleaned; empty reminders deleted |
Content retained after attribution is removed can still contain names or personal details in free text. Clearing identifiers is not a guarantee of anonymization. The shared-content retention policy must address that before public launch.
The operator-owned creditPacks catalog contains no payment credentials. It is not family-scoped and remains across family deletion. Granted pack snapshots (packId and packCredits) follow the assistantCredits ledger lifecycle.
Delivery and object-cleanup records
| Collection | Export | Cleanup |
|---|---|---|
pushDeliveries | Not in account export | Removed with relevant account/member/family; terminal records older than 30 days are swept hourly; pending records follow delivery/source expiry rules |
sentReminders | Not in account export | Deduplication history; event/member lifecycle removes relevant keys; no general age-based purge |
orphanBlobs | Not in account export | Contains object keys awaiting deletion; removed on successful object-store deletion; ten failed attempts make the record terminal for operator review |
The upload sweep also removes unposted message-attachment rows older than 24 hours and queues their objects for deletion. A queued deletion is not proof that the provider deleted the object. Monitor pending and terminal orphan records. Bucket versioning, incomplete uploads and backup copies need storage-side lifecycle rules and real-provider verification.
Data outside these collections
- Assistant providers: conversation deletion does not call a provider deletion API. Provider processing/retention and BYOK choices need documented terms and consent. Conversation inactivity cleanup does not remove saved memories.
- Original-media exports: ZIP parts are produced on demand, not persisted by the API. Downloaded copies remain on the recipient's device.
- Local app storage: session/family fencing and sign-out cleanup are separate from server deletion. An offline device cannot learn of remote revocation until reconnecting. Verify native encryption, backup exclusions and widget cleanup on signed devices.
- Backups and logs: live-store deletion does not erase snapshots, log archives or object versions. Define retention, access, encryption-key custody and an erasure-aware restore procedure. Do not reconnect a restored old database to production before reconciling later erasures.
Outstanding policy and evidence
Before public launch, approve shared-content retention, children's-data handling, audit/token metadata retention, location expiry, provider retention and backup erasure. Test export/deletion using independent accounts, real object storage and signed native builds. A passing local retention test proves the specified database cleanup behavior only.