WorkingPolicy
Start a proposal
RECORDS AND RETENTION

Private work can be deleted. Public history cannot be silently rewritten.

records-retention-2026-07-20 · operator approved

Records are retained by purpose and classification, with explicit publication, scoped holds, deletion replay after restore, and permanent public lineage.

01

Publication is explicit

New work is private. Publishing previews what becomes public and creates an immutable named snapshot while later work continues in a new draft.

02

Private deletion is prompt

Active private account data, drafts, uploads, and ordinary records are removed within 30 days of a valid request unless a narrow hold applies.

03

Public lineage remains

Published versions, citations, participation, moderation, governance, and official records remain; deleted attribution becomes “Deleted User” or a persistent anonymous identifier where appropriate.

04

Retention is tiered

Analytics: 90 days. Raw proxy/security IP data: 30 days. Minimized security and privileged audit events: two years. Finance: seven years. Public policy and governance records: permanent.

05

Backups honor deletion

Immutable backups expire through the documented rotation. A protected deletion ledger is replayed before a restored service reopens.

Inspect and control your private account record.

Authenticated users can request an export or deletion through the privacy center after strong reauthentication.

Open privacy controlsRead the Privacy Notice