This gateway keeps what it needs to COUNT and DEBUG: your email, a hashed key, and one row per call — timestamp, token count, amount. The content of your questions and documents PASSES THROUGH; it is not retained.
Retention: 24 months. Past that, the system RAISES A FLAG to an operator rather than deleting on its own — deletion cannot be undone, so a person decides.
We chose this number ourselves; it is not derived from any specific statute. It may change once we have legal advice.
We REMOVE THE IDENTITY and KEEP THE LEDGER ROWS: email, password hash and top-up code are stripped, and every key is revoked immediately. Rows recording tokens and amounts remain — but once the identity is gone, they POINT TO NO ONE.
Why not delete the rows too: this ledger is evidence. Deleting a row makes the invoice look cleaner, but anyone wrongly charged LOSES THE PROOF that they were charged.
The deletion itself also leaves a row — otherwise it would be an untraceable edit to the ledger, exactly what this ledger exists to prevent.
Where your books live depends on which edition you use — see the route table.
For where the data actually goes, see the route table — it is generated from the running configuration, not written by hand.
WE DO NOT YET HAVE AN ANSWER. Backups today are held in-country. The day personal data of people in other countries enters the system, where those backups sit must be decided again — that is a legal question, and we do not yet have professional advice on it. We say so rather than leave it blank.