Write docs/data-retention.md: for every category of data the system stores, what is retained, for how long, what deletes it, and what a user-initiated erasure can and cannot reach. Covers messages and envelopes, files (soft then hard delete), device and prekey records, audit logs, presence and resume streams in Redis, and push subscriptions.
Acceptance criteria:
- A table of data category → store → retention window → the job or action that removes it
- Documents the GC jobs that enforce each window and their schedules
- States plainly what erasure cannot reach: audit rows are deliberately append-only and not FK-linked, and on-chain transaction data is permanent
- Distinguishes content (E2E encrypted, unreadable by the server) from metadata (visible), cross-linking
docs/threat-model.md
Write
docs/data-retention.md: for every category of data the system stores, what is retained, for how long, what deletes it, and what a user-initiated erasure can and cannot reach. Covers messages and envelopes, files (soft then hard delete), device and prekey records, audit logs, presence and resume streams in Redis, and push subscriptions.Acceptance criteria:
docs/threat-model.md