# Content Retention and Deletion Policy

**Platform:** MyFinalVideo  
**Contact:** support@myfinalvideo.com  
**Draft revision:** 22 September 2026 — operator details, exceptional retention periods and deployed behavior require confirmation before publication.

## 1. Overview

Deleting an account, expiring a link and physically erasing every stored copy are different events. This policy describes the revised erasure workflow and the retention settings that have been verified. It does not promise immediate removal from every storage version, backup, offline device or recipient download.

## 2. Retention schedule

| Data / event | Revised behavior and limits |
|---|---|
| Active account videos, key metadata and associated contacts | Kept to provide the requested service, subject to deletion requests and the applicable account lifecycle; no guaranteed service duration |
| Expired free trial | Eligible for scheduled account cleanup 180 days after the trial expiry timestamp; not 180 days from signup |
| Completed posthumous delivery | Eligible for account cleanup 180 days after successful completion, when all videos have been dispatched |
| Annual message still awaiting its date or unresolved delivery | Protected from the completed-delivery cleanup rule; not proof of unlimited retention |
| Expired recipient access token and wrapped key | Access is denied after token expiry; records become eligible for scheduled cleanup. Current default link lifetime is 90 days, configurable before issue |
| Abandoned signed upload | Pending upload becomes eligible for cleanup after 24 hours; any valid upload authorization must expire before erasure can be completed |
| Explicit account/video deletion or destructive password recovery | Retryable erasure: stored objects are deleted before related metadata; failures remain pending |
| GCS object versions and soft-deleted data | Erasure includes live and noncurrent versions. The inspected video bucket has a 7-day soft-delete period, during which recoverable provider copies can remain |
| Audit, billing, abuse-prevention, provider records and backups | Each requires a documented purpose, applicable retention decision and verified expiry process. A universal 90-day, two-year or seven-year period is not established for these classes |
| Local drafts and recipient downloads | Controlled by the browser/device holding the copy; server deletion cannot reliably erase offline or independently downloaded copies |

Eligibility is assessed by scheduled work, not an exact deletion-time guarantee. Infrastructure failures, retention controls, legal requirements and retries can delay completion. Applicable exceptions must be identified and explained for a specific request.

## 3. Account and video deletion

Request deletion through the account controls or support@myfinalvideo.com. Keep copies you need before proceeding. Once erasure has completed, the platform does not promise to restore the account or its videos.

The workflow records pending cleanup, attempts storage erasure and removes related records after successful storage deletion. Linked family-account cleanup can require separate jobs. If the request reports an error or pending state, do not assume erasure has finished. Password recovery that requires vault erasure remains pending if that erasure fails.

A retained hash of an email address is pseudonymous data and may be matched to a known address; it is not inherently anonymous or impossible to identify. Any such abuse-prevention record needs a justified, verified retention period. This draft does not claim that a two-year hash-expiry job is implemented.

## 4. Expired trials

The free-trial period and the subsequent retention period are separate. The current pruner checks for trial expiry more than 180 days earlier. Cleanup then follows the same retryable erasure process. A promised seven-day warning is not established by the current cleanup code and cannot be relied on while email is disabled. Review trial status and export any wanted content before expiry rather than relying on a warning message.

## 5. Delivery links and original videos

### 5.1 Eligibility and access

Posthumous delivery requires an explicit emergency-contact death report, a 48-hour waiting period and the remaining account/upload/recipient checks. Annual messages also wait for their selected date. Silence alone does not release messages.

### 5.2 Encryption and recipient copies

The recipient browser decrypts the original stored ciphertext using a key re-wrapped by the server. Normal v2 delivery does not create a decrypted server-side video copy or a separate temporary delivery-bucket object. Recipients can download a copy; treat both the access link and any saved copy as sensitive.

### 5.3 Expiry and revocation

Use the expiry stated in the delivered message. The current default is 90 days, but access can end sooner through revocation, deletion or other account controls. Expiry or revocation prevents further authorized platform access; it cannot retract an email, video or key material already received. Links are not currently single-use exchanges.

### 5.4 Completed-delivery cleanup

The 180-day post-dispatch clock begins after successful account-level completion, with all videos dispatched. A message awaiting an annual date or unresolved delivery is not eligible under that rule. Object deletion, metadata cleanup and provider physical erasure can complete at different times.

## 6. Exceptional retention and preservation requests

Some records may require separate handling for a binding preservation request, dispute or applicable legal obligation. The accountable operator must assess the request, identify the specific records, record the reason and duration, and verify the operational means of preservation. This policy does not assert that an automatic legal-hold feature exists or that every provider copy is under direct platform control. Contact support with a specific request; do not include access tokens or video contents unnecessarily.

## 7. Backups and recovery

The inspected Firestore database had PITR disabled and no native backup or backup schedule in the queried location. This observation does not rule out other exports. No universal 90-day backup retention, automatic recovery or completed restore rehearsal has been verified.

The inspected GCS video bucket uses versioning and a 7-day soft-delete period. These controls are distinct from a complete, tested backup of videos, metadata and keys. The operator must confirm all backup locations and expiry behavior before publishing a definitive physical-erasure schedule.

## 8. Export and local copies

Use the account's video download/playback controls and data-export feature as appropriate, and verify that your saved files open correctly. A metadata JSON export is not itself a backup of playable video. Downloaded copies and local drafts remain on the devices where they were saved unless removed there. Clearing browser storage can destroy unsent local drafts.

## 9. Contact and completion of this draft

Contact support@myfinalvideo.com about deletion, pending cleanup or retained records. Verified operator/representative details and collection-specific legal retention decisions remain required before publication. This revision is not evidence that production has been updated or that all data classes have passed an end-to-end erasure test.
