# Retention

Hosted media lives **30 days** after record, then we hard-delete the Stream object, derivatives, CDN, and media rows. The intro row stays as a **tombstone** (`dead`). Inbox play 404s.

**Backup TTL:** 30 days after that object delete, backups must forget it too. Stated here so an auditor does not have to guess.

Audit events: ~12 months. No media in the log.

Free/demo path: we upload nothing we keep.

The client can delete one intro **now** from inbox, or export JSON (name / time / place / prompts). File download is a short-TTL signed URL.

The person on camera has no login. They ask the client.
