Renata protected retention and deletion planning

Retention and Deletion Policy Planning

Protected, read-only planning for future retention and deletion boundaries before storage, jobs, or audit logging exist.

This is a protected, read-only retention and deletion policy planning page. It does not store drafts, delete records, run retention jobs, create staff decisions, or write data.

Purpose

This page defines future retention and deletion policy before pull-up/push-up draft storage, staff review records, Morning Sheet visibility, or audit logging exists.

It is planning-only. It creates no live retention jobs, deletion jobs, records, controls, staff decisions, drafts, submissions, write endpoints, database writes, tables, migrations, or stored community content.

Current Storage Boundary

Product

Renata

The Sixth Sense at 6th Street

Draft storage

false

not implemented

Retention jobs

false

not implemented

Deletion jobs

false

not implemented

Retention and deletion policy is planning-only; no drafts, submissions, review decisions, staff approvals, rejections, Morning Sheet placements, retention jobs, deletion jobs, tables, migrations, or writes exist.

Why Retention/Deletion Comes Before Live Drafts

Future pull-up/push-up drafts may include sensitive accountability content. Retention and deletion policy must exist before collection so sensitive drafts do not become permanent files, searchable gossip, tracking records, or unresolved deletion liabilities.

No storage, retention job, deletion job, archive control, restore control, staff decision, data persistence, active migration, or executable SQL file is added.

Retention Principles

  • Data minimization comes first.
  • No live pull-up/push-up content is stored until retention/deletion policy is approved.
  • Sensitive drafts should not become permanent resident files.
  • Private feedback should have shorter retention than approved public Morning Sheet content.
  • Blocked unsafe drafts should not become searchable permanent records.
  • Deleted means unavailable to normal app workflows.
  • Permanent deletion rules require staff/privacy/legal review before implementation.
  • Retention must not become attendance tracking, participation tracking, scoring, ranking, compliance metrics, or resident performance analytics.
  • Retention must not preserve gossip, shaming, retaliation, or sensitive disclosures.
  • Audit metadata should be minimized and separated from sensitive draft content where possible.

Future Data Categories

Category Purpose Status Storage active Sensitivity Retention posture Deletion posture Allowed future use Prohibited use
draft-content pull-up/push-up draft body and prompts planning-only false future-sensitive no-storage until draft content, staff review, privacy, retention, deletion, and audit gates are approved future deletion rules required before storage Could support future draft review only after storage and privacy gates are approved. Must not become searchable gossip, permanent resident files, tracking, analytics, scoring, or compliance records.
draft-metadata draft type, status, timestamps, pseudonymous refs planning-only false planned-only review-window-retention candidate after actor and draft policy gates future deletion or deleted-marker-only posture required before storage Could support future workflow state after actor refs and role mapping are approved. Must not store email, real names, Cloudflare claims, attendance, participation, scoring, or identity details.
review-metadata review lane, review status, pseudonymous reviewer ref planning-only false planned-only review-window-retention candidate after staff review and audit policies future deletion and audit relationship required before storage Could support future staff review procedure after policy approval. Must not become staff surveillance, clinical interpretation, discipline automation, or performance scoring.
private-feedback content held for private conversation only planning-only false future-sensitive short-retention candidate future deletion required before storage Could support private repair or recognition conversation after staff/privacy approval. Must not be converted into public content, exported, indexed, or preserved as resident history.
morning-sheet-visible-content content approved for future public Morning Sheet visibility planning-only false planned-only morning-sheet-cycle-retention candidate after visibility policy approval future archive and deletion boundaries required before storage Could support future public reading only after staff review, visibility, consent, retention, and privacy gates. Must not create automatic placement, rankings, popularity scoring, resident performance analytics, or permanent dossiers.
blocked-content unsafe or privacy-risk draft content planning-only false future-sensitive, short-retention candidate short-retention or no-storage candidate future deletion required before storage Could support immediate safety review only under approved escalation and privacy policy. Must not remain searchable, become a permanent behavior file, or be used for discipline automation.
audit-metadata minimal event metadata without sensitive content where possible planning-only false planned-only audit-minimal-retention candidate future audit/deletion relationship required before storage Could support accountability for workflow changes after audit policy approval. Must not store sensitive draft content, raw identity, Cloudflare claims, staff notes, tracking, analytics, or scoring data.
deleted-record-marker future minimal deletion marker planning-only false planned-only deleted-marker-only candidate minimal marker only if approved by deletion and audit policy Could prevent restoration ambiguity after approved deletion policy exists. Must not preserve deleted draft content, identity details, resident profiles, or sensitive disclosures.

Planned Retention Categories

Category Status Active Retention timer Deletion behavior Storage
no-storage planning-only false false false false
session-only planning-only false false false false
short-retention planning-only false false false false
review-window-retention planning-only false false false false
morning-sheet-cycle-retention planning-only false false false false
audit-minimal-retention planning-only false false false false
deleted-marker-only planning-only false false false false
not-allowed planning-only false false false false

Deletion Policy Rules

  • draft author may request deletion only under approved identity/actor policy
  • staff may block or remove content under approved staff review policy
  • blocked unsafe content should not remain searchable
  • private-only content should have short retention
  • public Morning Sheet content requires separate visibility and retention rules
  • deletion should remove content from normal workflow views
  • permanent deletion requires audit/rollback/legal/privacy review
  • deletion must not erase required minimal audit metadata unless policy allows
  • deletion must not be used to hide staff misconduct or safety incidents; escalation policy must define exceptions
  • all deletion rules are planning-only
  • no deletion control exists
  • no records exist to delete

Archive and Restore Boundaries

Archive policy rules

  • archive behavior is planning-only
  • archive must not preserve searchable sensitive draft content without approved policy
  • archive must not become a resident dossier or behavior file
  • archive must be separate from Morning Sheet placement and public visibility
  • archive controls are not implemented in this phase

Restore policy rules

  • restore behavior is planning-only
  • restore requires retention, deletion, audit, privacy, and staff review policy before implementation
  • restore must not revive private-only or blocked content into public visibility
  • restore must not bypass staff review or Morning Sheet visibility gates
  • restore controls are not implemented in this phase

Permanent deletion boundaries

  • permanent deletion requires staff/privacy/legal review before implementation
  • permanent deletion must define what minimal audit metadata may remain
  • permanent deletion must not be used to hide staff misconduct or safety incidents
  • permanent deletion must not run as an automated job until approved
  • no permanent deletion behavior is active in this phase

Private, Staff Review, Morning Sheet, and Audit Boundaries

Private-only content

  • private feedback should have shorter retention than approved public Morning Sheet content
  • private-only content must not become public without approved policy
  • private-only content must not become searchable gossip or resident history
  • private-only content requires deletion rules before storage
  • private-only content is not stored in this phase

Morning Sheet visibility retention

  • Morning Sheet visible content requires separate visibility and retention rules
  • public visibility does not imply permanent retention
  • Morning Sheet cycle retention must be approved before any storage
  • approved public content must still avoid tracking, analytics, scoring, ranking, discipline, and compliance metrics
  • Morning Sheet placement is not active in this phase

Staff review retention

  • review metadata requires retention rules before staff review storage
  • review notes must not become clinical claims, resident performance files, or staff surveillance
  • review metadata must remain separate from sensitive draft content where possible
  • review metadata retention must not become attendance, participation, scoring, ranking, or compliance tracking
  • staff review storage is not active in this phase

Audit retention relationship

  • audit metadata should be minimized and separated from sensitive draft content where possible
  • audit policy must define what remains after deletion
  • audit metadata must not store raw identity, Cloudflare claims, draft body, staff notes, or sensitive disclosures unless explicitly approved
  • audit retention must not become tracking, analytics, scoring, compliance reporting, or staff surveillance
  • audit logging is not active in this phase

Prohibited Storage Categories

attendance dataparticipation dataparticipation analyticsresident performance scoresrecovery scoresrankingsdiscipline pointscompliance metricsclinical diagnosismedication detailslegal case detailsinsurance detailstrauma details unless explicitly approved under future policyCloudflare Access claimsJWTstokensraw identity headersemailsreal namesroom numberscase numbersresident profile detailsstaff profile details

Required Gates Before Implementation

  • Cloudflare Access boundary approved
  • identity policy approved
  • pseudonymous actor policy approved
  • account role mapping policy approved
  • draft content policy approved
  • staff review procedure approved
  • Morning Sheet visibility policy approved
  • retention policy approved
  • deletion policy approved
  • permanent deletion policy approved
  • audit policy approved
  • escalation policy approved
  • AI-use policy resolved
  • D1 schema reviewed
  • privacy approval complete
  • rollback plan approved
  • small pilot approved

What Remains Blocked

  • live retention jobs
  • deletion jobs
  • delete buttons
  • restore buttons
  • archive controls
  • save buttons
  • staff decision records
  • live draft storage
  • live review storage
  • Morning Sheet live placement
  • live pull-up forms
  • live push-up forms
  • input fields
  • textareas
  • submit/save controls
  • draft creation
  • draft editing
  • draft deletion
  • draft collection
  • draft storage
  • live submissions
  • submission collection
  • staff approval/rejection
  • staff decisions
  • app-level login
  • account creation
  • password fields
  • email capture
  • real user names
  • real resident names
  • real staff names
  • real emails
  • Cloudflare Access email display
  • Cloudflare Access name display
  • Cloudflare Access group display
  • Cloudflare Access JWT display
  • Cloudflare Access token display
  • Cloudflare Access header display
  • Cloudflare Access claim storage
  • actor records
  • actor storage
  • account records
  • account storage
  • identity mapping
  • role assignment
  • live role assignment
  • resident profiles
  • staff profiles
  • user admin CRUD
  • database writes
  • write endpoints
  • active migrations
  • executable SQL files
  • D1 account/user/actor/submission/draft/review/morning-sheet/retention tables
  • attendance tracking
  • participation tracking
  • participation analytics
  • scoring, ranking, discipline points, or compliance metrics
  • billing, lead capture, CRM, Stripe, or sales forms
  • AI for real submissions
  • sensitive community content storage

Recommended Next Phase

Phase 8.9 - Audit Logging Policy Planning

After retention and deletion boundaries are planned, the next safe step is planning audit logging policy before any draft, review, visibility, retention, deletion, or audit storage exists.

Boundaries: no live retention jobs in Phase 8.8; no deletion jobs; no draft storage; no live submissions; no staff decisions; no Morning Sheet placement; no database writes; no active migrations; no tracking; no analytics; no scoring.

recommended-next