gloss

Draft for legal review. Not yet in effect.

How long Gloss keeps data

Written for the privacy policy to copy. Plain English. Each line says what the data is, where Gloss keeps it, how long, what deletes it, and where in the code that happens. Line numbers are as of mission G9 (October 2026).

Two rules apply to everything below:

  • Deleting your account deletes all of it. Every row with your account id is deleted at once, and your personal encryption key is destroyed, so anything encrypted with it (including in old backups) can no longer be read. If a step fails, the deletion is retried every hour until it finishes. Proof: api/src/accounts/data-rights.ts:126-153 (the deletion), :156 and api/src/accounts/index.ts:43 (the hourly retry), api/src/accounts/routes-me.ts:278-280 (it starts the moment you ask).
  • The clocks run every hour. The "deleted after" periods below are checked by hourly jobs: workers/src/main.ts:61 (notifications), :62 (email), :65 (everything else in api/src/privacy/retention.ts).

The table

DataWhere it is storedHow long it is keptWhat deletes itProof
Account: login email, backup and school email, first name, adult confirmationGloss database, usersUntil you delete your accountAccount deletionapi/src/accounts/data-rights.ts:126-153
Email subject and bodyGloss database, email_messages, encrypted with your personal key30 days after Gloss downloads the emailHourly email purgeworkers/src/email/sync.ts:18,61 (30 days), :191-198 (purge), workers/src/main.ts:62
Email sender name and address, and the AI's one-line summary of the emailGloss database, email_messages, encrypted with your personal key30 days after download, the same as subject and bodyHourly email purgeencrypted: workers/src/email/sync.ts:57, workers/src/ai/pipeline.ts:274; purge: workers/src/email/sync.ts:194
What is left of an email after 30 days: when it arrived, its flags (important, event, sensitive, phishing) and which deadlines it created. No words from the emailGloss database, email_messagesUntil you disconnect that mailbox or delete your accountDisconnect (rows deleted with the mailbox) or account deletionapi/src/intake/migrations/0003_email.sql:32
Mailbox sign-in tokens (Google, Microsoft)Gloss database, email_connections, encrypted with your personal keyUntil you disconnect or delete your accountDisconnect or account deletion; the token is first revoked at Google or Microsoftapi/src/privacy/index.ts:23-37
Deadlines and events (items), including ones found in email, and their change historyGloss database, items and related tablesUntil the source removes them, you delete them, or you delete your account. Items that came only from a mailbox are deleted when you disconnect itYour action, disconnect, or account deletionapi/src/intake/email/service.ts:228-243
What an item keeps from an emailitemsOnly what you need on screen: title, date, place, course. No copy of the email's summary and never the sender's name: "changed by" says "your instructor's email" or the instructor's name from your own class schedule—workers/src/ai/pipeline.ts:120-125; old rows cleaned by api/src/intake/migrations/0008_email_sealed_envelope.sql
Course site calendar linkGloss database, feeds, encrypted with Gloss's system keyUntil you remove it or delete your accountYour action (its events go with it) or account deletionapi/src/intake/feeds/service.ts:33, api/src/intake/routes/feeds.ts:71
Class schedule screenshots and PDFsNever stored—Read once, not savedapi/src/imports/index.ts:186
Syllabus files and pasted syllabus textGloss server disk, encrypted with your personal keyUntil you remove it or delete your accountYour action or account deletionapi/src/imports/index.ts:270,277
Study library filesGloss server disk, encrypted with your personal keyUntil you remove them or delete your account. An upload that never arrived is cleared after 1 dayYour action, the 1 day cleanup, or account deletionapi/src/smart/library.ts:298-300
Lecture recordings (audio)Gloss server diskDeleted right after transcription, whether it works or not, and if you withdraw permission for GroqAutomaticapi/src/smart/library.ts:245-248,276,305-310
Lecture transcripts, tutor chatsGloss database, encrypted with your personal keyUntil you delete them or your accountYour action or account deletionmaterial_chunks.text_sealed, tutor_messages.text_sealed
Push notifications sent to your phoneGloss database, push_outbox7 days after sentHourly notification purgeapi/src/notifications/push.ts:218-224, workers/src/main.ts:61
Reminders that already fired (or were skipped or cancelled)Gloss database, reminders7 daysHourly notification purgeworkers/src/reminders/engine.ts:442-457
Device push tokensGloss database, devicesUntil you delete your accountAccount deletionapi/src/accounts/data-rights.ts:126-153
SessionsGloss database, stored only as hashes; a sign-in lasts at most 60 daysUntil you delete your accountAccount deletionapi/src/accounts/sessions.ts:18
Sign-in codes (the 6 digit codes)Gloss database, stored only as hashes; valid 10 minutes1 dayHourly retention jobapi/src/privacy/retention.ts:13,52
Sign-in safety counters (too many tries)Gloss database, hashes only1 dayHourly retention jobapi/src/privacy/retention.ts:54-55
"Link this sign-in to your account" requestsGloss database, pending_links1 dayHourly retention jobapi/src/privacy/retention.ts:53
Mailbox connection requests (OAuth states)Gloss database, oauth_states; valid 10 minutes1 dayHourly retention jobapi/src/privacy/retention.ts:58
Claude / ChatGPT connection requests and codesGloss database, oauth_requests, oauth_codes (codes as hashes), connector_preapprovals1 dayHourly retention jobapi/src/privacy/retention.ts:59-61
Claude / ChatGPT accessGloss database, tokens stored only as hashes. Access token 1 hour, refresh token 30 daysUntil you disconnect the app or delete your accountYour action or account deletion (revoked)api/src/connector/oauth.ts:22-23
Payments and planGloss database, entitlements, payments. No card numbers, everUntil you delete your accountAccount deletionapi/src/payments/migrations/0000_init.sql:29
Your customer record at Stripe (computer purchases)StripeUntil you delete your accountAccount deletion deletes it at Stripe (this also stops any Stripe subscription)api/src/payments/customer-deletion.ts:13-27, called from api/src/accounts/data-rights.ts:137-140. Shown working: reports/g9/stripe-delete-live.txt
Your customer record at RevenueCat (iPhone purchases)RevenueCatUntil you delete your accountAccount deletion deletes it at RevenueCat once Gloss's RevenueCat key is set (until then the deletion records that it was skipped). Apple keeps its own purchase records; cancel an App Store subscription in your Apple accountapi/src/payments/revenuecat.ts:191-197, called from api/src/accounts/data-rights.ts:140
Messages you send to support (email, name, school, message)Gloss database, support_requests. Not linked to your account180 daysHourly retention jobapi/src/privacy/retention.ts:9,28
Classmates' date and room corrections (counts, your opaque reporter code, the proposed date or room, and the item's official date, date only)Gloss database, correction_tallies, correction_voters, correction_votes. Not linked to your name; no email text30 days after the item's official date passesHourly retention jobapi/src/privacy/retention.ts:11,33-46; the date is saved at api/src/smart/corrections.ts (report)
Correction safety counters (reports per day, false reports)Gloss database, correction_reporter_stats, opaque code onlyDeleted once none of your corrections is left and you reported nothing for 30 daysHourly retention jobapi/src/privacy/retention.ts:47-49
Audit log (security events)Gloss database, IP addresses stored only as hashesUntil you delete your account; then one "account deleted" line remains with an unreadable code instead of your idAccount deletionapi/src/accounts/data-rights.ts:152
Website early access list (email)CloudflareUntil you unsubscribe (deleted at once) or we remove itUnsubscribe linksite/functions/api/unsubscribe.js:1-3
On your iPhoneYour phone: secrets in the Keychain (this device only), screens cached up to 7 daysUntil you sign out (wiped)Sign outapp/src/lib/storage.ts:22-27, app/src/data/query.tsx:21,25
On your computerYour computer: secrets encrypted by the operating systemUntil you sign out (wiped)Sign outdesktop/src/secureStore.ts
Server logsGloss server. Never contain email contentSystem journal 30 days (500 MB cap); log files 14 days; web server access logs are offAutomaticops/prod/files/journald-gloss.conf:3-4, ops/prod/files/logrotate-gloss:3
BackupsCloudflare R2, encrypted, nightly. Database and personal keys; uploaded files are not backed up30 days (3 days on the server)Automaticops/prod/backup.sh:31-32

What this means after you delete your account

  • At Gloss: everything above that belongs to you is deleted right away, and your personal key is destroyed.
  • At Stripe and RevenueCat: your customer record is deleted as part of the same deletion.
  • At Google, Microsoft and Apple: the sign-in tokens Gloss held are revoked.
  • In backups: backups made before the deletion still hold a copy of your data (and of your old personal key) for up to 30 days, then they are deleted.
  • Support messages and classmates' corrections are not linked to your account, so they follow their own clocks above (180 days; 30 days after the class date).