FISCIVA DATA RETENTION AND DISPOSAL POLICY Document classification: Internal Policy owner: Founder and Security Lead Privacy contact: ingenuitylabs@gmail.com Version: 1.0 Effective date: August 18, 2026 Review cycle: At least annually and after a material legal, product, provider, or security change Next scheduled review: August 18, 2027 APPROVAL This policy is approved by the Fisciva Founder and Security Lead. It applies to all Fisciva personnel, contractors, systems, service providers, and information environments that create, receive, process, store, transmit, back up, or dispose of Fisciva information. Version 1.0, effective August 18, 2026, approved by the Founder and Security Lead. 1. PURPOSE This policy defines how Fisciva determines retention periods and securely disposes of information. Its purposes are to: - Retain information only while it is needed for an authorized business, consumer, security, contractual, or legal purpose. - Give consumers meaningful control over information they provide or authorize Fisciva to obtain. - Securely delete consumer-permissioned financial data, authentication information, receipts, tax information, and other sensitive information when retention is no longer justified. - Prevent information from remaining indefinitely by default. - Maintain documented evidence that deletion obligations were completed without retaining the deleted consumer information itself. 2. SCOPE This policy applies to: - Production, staging, development, backup, and recovery environments. - Databases, object storage, application logs, audit events, queues, caches, exports, local devices, and paper records. - Account, household, authentication, transaction, balance, debt, tax, income, receipt, mileage, budget, investment, asset, support, and security information. - Consumer-permissioned information received through Plaid or another connected provider. - Derived categories, forecasts, suggestions, calculation snapshots, and household learning rules. - Employees, contractors, administrators, service accounts, vendors, and subprocessors. 3. GOVERNING PRINCIPLES Fisciva follows these principles: - Purpose limitation: Information is retained only for the purpose disclosed to the consumer or another documented lawful purpose. - Data minimization: Fisciva collects and stores only information required for enabled features, security, support, and legal obligations. - No indefinite retention: Every information class has a retention rule, triggering event, or documented exception. - Consumer control: Consumers can disconnect providers and request access, correction, export, or deletion. - Secure disposal: Disposal must make information unreadable or impracticable to reconstruct using methods appropriate to the storage medium. - Defense in depth: Provider revocation, credential erasure, database deletion, object deletion, backup expiration, access control, and audit evidence operate together. - Least privilege: Only authorized systems or personnel can approve, execute, delay, or verify deletion. - Legal preservation: A documented legal hold overrides normal disposal only for the information and period required. - Verifiability: Completion is recorded using minimal, non-identifying evidence. A policy requirement alone is not treated as proof that deletion occurred. 4. ROLES AND RESPONSIBILITIES Founder and Security Lead The Founder and Security Lead: - Owns and approves this policy. - Determines whether a retention exception or legal hold is valid. - Reviews retention schedules, deletion evidence, vendors, and backup practices. - Ensures privacy requests are verified and completed on time. - Documents corrective action when information exceeds its approved retention period. System and data owners System and data owners: - Identify information stored by their systems and assign it to this schedule. - Implement deletion, expiration, anonymization, or cryptographic-erasure controls. - Prevent new features from creating information with no retention rule. - Validate that disposal covers replicas, caches, queues, exports, and attached files. Authorized personnel Authorized personnel must not retain local copies, exports, screenshots, or support attachments beyond their authorized purpose. Suspected excess retention or failed disposal must be reported to the Security Lead immediately. 5. INFORMATION CLASSIFICATION Restricted information includes provider access tokens, authentication information, financial account details, transactions, balances, tax profiles, receipts, identity data, document encryption keys, and precise mileage records. Confidential information includes household plans, budgets, learned preferences, support records, calculation snapshots, internal audit evidence, and nonpublic business records. Internal information includes system inventories, operational procedures, and security records that do not contain consumer information. Public information includes approved public policies, product information, and other information authorized for public release. Restricted and Confidential information require a documented retention rule and secure disposal. 6. RETENTION SCHEDULE The following periods are maximum standard periods. Information is deleted sooner when its purpose ends, a verified request requires deletion, or continued retention is not justified. A documented legal requirement, security investigation, dispute, or legal hold may require a limited exception under Section 11. Consumer identity and workspace membership - Standard period: While the account or household workspace is active. - Trigger: Verified account or workspace deletion request, loss of membership, or service termination. - Disposal deadline: Active copies within 30 days of verification. Fisciva's owner-initiated in-app workspace deletion is designed to complete active deletion immediately. Plaid and other provider access credentials - Standard period: Only while the authorized connection is active. - Trigger: Consumer disconnect, workspace deletion, expired authorization, provider revocation, or security event. - Disposal deadline: Provider revocation is attempted immediately when supported. Locally stored encrypted credentials are overwritten or deleted as part of the same controlled operation. Imported account, balance, transaction, liability, and investment information - Standard period: While the workspace is active and the records are needed for the consumer's ledger, reconciliation, planning, or requested history. - Trigger: Verified workspace deletion, a narrower verified deletion request where technically and legally appropriate, or termination of the service. - Disposal deadline: Active copies within 30 days of verification. A provider disconnect stops future collection but does not by itself rewrite historical ledger records. Provider source events and reconciliation records - Standard period: While the connected or imported records are needed to prevent duplicates, reconcile source activity, explain corrections, and maintain ledger integrity. - Trigger: Workspace deletion or the end of the supported reconciliation purpose. - Disposal deadline: Active copies within 30 days of the triggering event. Receipts, uploaded documents, and extracted fields - Standard period: While attached to an active household record or needed for a feature requested by the consumer. - Trigger: Verified document or workspace deletion request, or removal of the underlying record where retention is no longer requested or required. - Disposal deadline: Active database and private object-storage copies within 30 days. Owner-initiated workspace deletion removes active receipt objects immediately. Tax profiles, tax estimates, and evidence records - Standard period: While the workspace is active and the consumer uses the records for planning or historical reference. - Trigger: Verified deletion request or service termination. - Disposal deadline: Active copies within 30 days unless the consumer requests continued retention or a legal requirement applies. Fisciva does not prepare or file tax returns and does not retain records on behalf of a tax authority. Budgets, bills, debts, payoff plans, refinancing scenarios, assets, calculations, suggestions, and household learning - Standard period: While the workspace is active or until the consumer deletes or resets the supported information. - Trigger: Consumer deletion, learning reset, workspace deletion, or service termination. - Disposal deadline: Immediate for supported self-service reset controls and no later than 30 days for a verified request. AI processing payloads - Standard period: Transient processing only. Fisciva does not create a separate durable AI training dataset from household information. - Trigger: Completion or failure of the requested extraction or explanation. - Disposal deadline: Fisciva submits supported AI requests with provider storage disabled. The original receipt and verified extraction follow their respective retention rules. Authentication sessions, caches, short locks, and queued job messages - Standard period: Only for their short operational lifetime. - Trigger: Expiration, job completion, sign-out, revocation, or failure handling. - Disposal deadline: Automatic expiration according to the configured time to live. Queue messages contain opaque job identifiers rather than financial payloads. Workspace invitations - Standard period: Invitation validity is 72 hours. Expired invitation records may be retained for up to 30 additional days for abuse prevention and troubleshooting. - Trigger: Acceptance, expiration, cancellation, or workspace deletion. - Disposal deadline: No later than 30 days after the triggering event, except minimal security evidence under this schedule. Application and infrastructure logs - Standard period: Up to 30 days for ordinary operational logs. - Trigger: Log age or resolution of the operational purpose. - Disposal deadline: Automatic provider expiration. Logs must exclude financial payloads, provider tokens, identity tokens, tax answers, and receipt contents. - Exception: Security incident records may be isolated and retained for up to three years after closure when necessary to investigate, defend, or document the incident. Workspace audit events - Standard period: Up to one year while the workspace is active, unless a longer security or legal purpose is documented. - Trigger: Record age or workspace deletion. - Disposal deadline: Workspace-scoped audit events are removed during controlled workspace deletion. A minimal non-identifying completion receipt may be retained for three years. Privacy request and deletion completion evidence - Standard period: Three years after request completion. - Content limitation: Request date, completion date, outcome, and a one-way request hash. Completion evidence must not contain financial records, provider credentials, receipt contents, or the deleted workspace data. - Trigger: Expiration of the three-year evidence period. - Disposal deadline: At the next quarterly retention review, and no later than 90 days after expiration. Encrypted production database and object recovery copies - Standard period: Point-in-time recovery history up to 30 days. Encrypted logical recovery copies may include 35 daily and 12 monthly recovery points. - Trigger: Backup age, replacement, deletion of the protected environment, or destruction of the associated encryption key. - Disposal deadline: Automatic expiration through the configured recovery schedule. Deleted information may remain inaccessible in an encrypted recovery copy until that copy expires. - Restore control: Recovery copies are isolated from ordinary application use. If a recovery copy is restored, completed deletion requests and provider revocations must be reapplied before the restored environment can serve production traffic. Development and test information - Standard period: Synthetic data is preferred. Consumer production information is prohibited unless specifically approved, minimized, encrypted, and assigned a deletion date. - Trigger: Completion of the approved test, environment reset, or approval expiration. - Disposal deadline: No later than 30 days after the triggering event. Local administrative copies and removable media - Standard period: Restricted consumer information must not be stored locally except for an approved, time-limited investigation or recovery task. - Trigger: Completion of the approved task or approval expiration. - Disposal deadline: Immediate secure deletion after the approved task. 7. CONSUMER DELETION PROCESS Fisciva accepts deletion requests through supported in-app controls or the privacy contact listed in the Fisciva Privacy Policy. The process is: 1. Record the request date and scope. 2. Verify the requester's authenticated identity and authority over the household. Workspace deletion is restricted to the owner and requires a verified second authentication factor. 3. Confirm the exact scope and identify any narrow legal restriction or legal hold. 4. Revoke active provider connections when supported, including Plaid item removal. 5. Make locally stored provider credentials unusable. 6. Delete private receipt and document objects associated with the workspace. 7. Execute the controlled database deletion. Ledger mutation protections permit physical deletion only within this isolated workspace-deletion operation. 8. Remove workspace-scoped audit events, jobs, provider events, learning rules, calculations, and other records through explicit deletion or referential cascades. 9. Create only a non-identifying completion receipt that supports idempotent retries and evidence of completion. 10. Notify the requester of completion or explain a lawful delay or exception. Fisciva does not require a consumer to contact Plaid before requesting deletion from Fisciva. Consumers may separately manage eligible Plaid connections through Plaid Portal. 8. PROVIDER DISCONNECTION Disconnecting a provider and deleting a workspace are different operations. - Disconnecting stops future collection, requests provider revocation when supported, archives connected accounts, and makes the local provider credential unusable. - Historical records already incorporated into the consumer's ledger remain until the consumer requests their deletion or deletes the workspace. - Workspace deletion performs provider disconnection and then removes active household data and attached files. 9. SECURE DISPOSAL METHODS Approved disposal methods include: - Database deletion through an authorized, workspace-scoped transaction. - Object deletion using authenticated private-storage APIs. - Cryptographic erasure by destroying or making an encryption key unusable. - Overwriting encrypted provider-token fields before or during record deletion. - Provider API revocation or deletion when supported. - Automatic cache, queue, session, and log expiration. - Vendor-certified media sanitization or destruction for provider-managed physical media. - Secure operating-system deletion or full-device cryptographic erasure for an approved local device. - Cross-cut shredding or an approved destruction vendor for paper containing Restricted or Confidential information. Moving a file to an ordinary recycle bin, deleting only an application pointer, or removing a database row while leaving an active object or usable credential is not sufficient disposal. 10. BACKUPS AND RECOVERY Backups are encrypted, access-restricted, and used only for disaster recovery, continuity testing, or a required investigation. Selective deletion from immutable recovery copies may be technically infeasible. In that case: - The recovery copy remains isolated and expires according to the approved schedule. - The information is not restored for ordinary product use. - Access is limited to authorized recovery personnel. - Completed deletions and revocations are reapplied before any restored environment returns to service. - Expired recovery objects and associated encryption keys are destroyed by the provider or Fisciva-controlled lifecycle process. Recovery retention must not be extended without approval by the Security Lead and a documented purpose. 11. LEGAL HOLDS AND RETENTION EXCEPTIONS A legal hold or retention exception must be documented and approved by the Security Lead. The record must identify: - The specific information covered. - The legal, security, fraud-prevention, dispute, or operational reason. - The owner and approval date. - Access restrictions. - The review date and expected end condition. The exception must be limited to the smallest practical data set and duration. Information under a hold is isolated from ordinary product use where practical. It is securely deleted when the hold ends. An exception may not be used to retain information for advertising, unrelated analytics, or speculative future use. 12. SERVICE PROVIDERS Before a provider may store Fisciva information, Fisciva evaluates its retention, deletion, backup, security, and contract capabilities. Provider access is limited to enabled features and minimum necessary information. Contracts or applicable provider terms must require appropriate protection and disposal. When a relationship ends, Fisciva revokes access, removes credentials, requests return or deletion of information where applicable, and retains available confirmation. Critical providers are reviewed at least annually and after a material change or incident. A provider's inability to support required deletion must be documented, risk-assessed, and resolved before the provider receives production consumer information. 13. MONITORING AND EVIDENCE The Security Lead performs a retention review at least quarterly. The review covers: - Expired privacy-request evidence. - Active provider credentials and revoked connections. - Object-storage lifecycle and orphaned objects. - Database and backup retention settings. - Log-retention settings. - Expired invitations, failed jobs, exports, and temporary files. - Legal holds and approved exceptions. - Vendor retention or deletion changes. The review records the date, reviewer, systems examined, findings, evidence, corrective actions, owners, and due dates. A deletion is marked complete only after the applicable provider, object-storage, database, and credential actions succeed or a documented exception applies. Failed or partial deletion is treated as an operational and privacy incident. It is retried safely, escalated to the Security Lead, and tracked to completion. 14. POLICY REVIEW AND ENFORCEMENT This policy is reviewed at least annually and after: - A material change to Fisciva's data practices, architecture, providers, or supported jurisdictions. - A material security or privacy incident. - A significant legal or contractual change. - A failed deletion, backup, or restore control. Violations may result in immediate access restriction, corrective action, vendor suspension, contract termination, or personnel discipline as applicable. Material exceptions and overdue corrective actions are recorded in the security risk register. 15. REFERENCES - Fisciva Privacy Policy, version 1.0. - Fisciva Information Security Policy, version 1.0. - Fisciva Access Control Policy, version 1.0. - Plaid Developer Policy: https://plaid.com/legal/ - Plaid End User Privacy Policy: https://plaid.com/legal/#consumers - United States Federal Trade Commission Safeguards Rule guidance: https://www.ftc.gov/business-guidance/resources/ftc-safeguards-rule-what-your-business-needs-know - United States Federal Trade Commission Disposal Rule: https://www.ftc.gov/legal-library/browse/rules/disposal-consumer-report-information-records END OF POLICY