Data Deletion Policy
Effective Date: May 23, 2025
Last Updated: May 23, 2025
1. Introduction
This Data Deletion Policy outlines how Good Gov AI handles the deletion of user data in compliance with privacy laws and regulations. We are committed to providing users with clear, accessible methods to control and delete their personal information.
2. Types of Data Deletion
2.1 User-Initiated Deletion
- Account Deletion: Complete removal of user account and associated data
- Selective Data Deletion: Removal of specific data categories or content
- Content Deletion: Removal of user-generated content (testimony drafts, queries)
2.2 Automatic Deletion
- Inactive Account Deletion: Accounts inactive for extended periods
- Temporary Data Purging: Automatic removal of temporary files and cache
- Retention Period Expiry: Data deleted when retention periods end
2.3 Legal or Administrative Deletion
- Legal Compliance: Deletion required by court orders or regulations
- Terms Violation: Account deletion due to terms of service violations
- Security Breach: Precautionary deletion for security purposes
3. User Rights and Deletion Requests
3.1 Right to Deletion (Right to be Forgotten)
Users have the right to request deletion of their personal data when:
- The data is no longer necessary for the original purpose
- Consent is withdrawn and no other legal basis exists
- Data has been unlawfully processed
- Deletion is required for legal compliance
- The user was a minor when data was collected
3.2 Deletion Request Methods
Self-Service Options:
- Account settings deletion button
- In-app data management tools
- Profile and content deletion controls
Assisted Deletion:
- Email request to info@goodgov.ai
- Written request to our business address
- Phone request to (301) 531-4723
3.3 Request Processing Timeline
- Acknowledgment: Within 48 hours of request
- Processing: Within 30 days for standard requests
- Complex Requests: Up to 90 days with explanation
- Completion Notification: Confirmation when deletion is complete
4. Data Categories and Deletion Procedures
4.1 Account Information
Data Included:
- Name and email address
- Authentication credentials
- Profile information and preferences
- Account settings and configurations
Deletion Process:
- Immediate removal from active databases
- Login, authentication, and account deletion
- All document removal
- Backup system purging within 30 days
4.2 User-Generated Content
Data Included:
- Testimony drafts and saved content
- Chat history and AI interactions
- Bookmarks and favorites
- Notes and personal annotations
Deletion Process:
- Immediate removal from user interface
- Database record deletion within 24 hours
- AI query anonymization (already implemented)
- Content backup removal within 30 days
4.3 Usage and Analytics Data
Data Included:
- Service usage patterns
- Feature interaction data
- Performance metrics
- Error logs and diagnostics
Deletion Process:
- Personal identifiers removed immediately
- Anonymized data may be retained for analytics
- Raw usage logs deleted within 90 days
- Aggregated data remains anonymized
4.4 Technical Data
Data Included:
- IP addresses and device information
- Browser and system details
- Cookies and tracking data
- Session information
Deletion Process:
- Session data cleared immediately
- Device information removed within 7 days
- IP address logs deleted within 30 days
- Cookies expired or deleted
5. Firebase/Firestore Deletion Procedures
5.1 Authentication Data
- Firebase Authentication user deletion
- Associated tokens and credentials revoked
- Third-party authentication links removed
- Security keys and recovery information deleted
5.2 Database Records
- Firestore document deletion
- Subcollection and nested data removal
- Index updates and cleanup
- Reference integrity maintained
5.3 Storage Files
- Cloud Storage file deletion
- Media and document removal
- Backup file purging
- CDN cache clearing
5.4 Backup and Recovery Systems
- Backup data identification and removal
- Point-in-time recovery cleanup
- Disaster recovery system updates
- Archive system purging
6. Deletion Verification and Confirmation
6.1 Pre-Deletion Verification
- User identity confirmation
- Account ownership verification
- Request authenticity validation
- Legal basis assessment
6.2 Deletion Execution
- Systematic removal across all systems
- Database integrity maintenance
- Service functionality preservation
- Error handling and logging
6.3 Completion Confirmation
- User notification of completion
- Deletion report generation
- Audit trail documentation
- Quality assurance review
7. Exceptions and Limitations
7.1 Legal Retention Requirements
Data may be retained when required by:
- Federal or state legal obligations
- Court orders or legal proceedings
- Regulatory requirements
- Law enforcement requests
7.2 Technical Limitations
- Backup Systems: Up to 30 days for complete removal
- CDN Caching: Up to 72 hours for global propagation
- Third-Party Systems: Dependent on processor deletion timelines
- Anonymized Data: Cannot be deleted when truly anonymized
7.3 Business Necessity
Limited data retention for:
- Fraud prevention and security
- Financial record keeping
- Legal defense purposes
- Regulatory compliance
8. Third-Party Data Deletion
8.1 Google/Firebase
- Coordinate deletion with Google's retention policies
- Ensure compliance with Google Cloud data handling
- Verify deletion across Firebase services
- Maintain documentation of deletion requests
8.2 Authentication Providers
- Google Sign-In data unlinking
- Meta platform authentication removal
- Third-party profile disconnection
- Provider notification of account deletion
8.3 Analytics and Service Providers
- Request deletion from analytics platforms
- Remove data from customer support systems
- Clear marketing and communication databases
- Update third-party processor records
9. Data Recovery and Undeletion
9.1 Recovery Limitations
- Deleted data cannot be recovered after processing
- No backup restoration after deletion completion
- Irreversible nature of deletion process
- Clear communication of permanence
9.2 Grace Period
- 14-day grace period for account deletion requests
- User notification before final deletion
- Option to cancel deletion during grace period
10. Audit and Compliance
10.1 Deletion Auditing
- Regular audit of deletion procedures
- Compliance verification processes
- System integrity checks
- Documentation review and updates
10.2 Regulatory Compliance
- GDPR Article 17 (Right to Erasure)
- CCPA deletion provisions
- COPPA data deletion requirements
- Other applicable privacy law compliance
10.3 Record Keeping
- Deletion request logs
- Processing timeline documentation
- Completion verification records
- Audit trail maintenance
11. User Support and Assistance
11.1 Deletion Guidance
- Step-by-step deletion instructions
- FAQ and help documentation
- Live support for complex requests
11.2 Partial Deletion Options
- Selective data category deletion
- Content-specific removal
- Historical data preservation options
- Granular privacy controls
12. Contact Information
For data deletion requests or questions:
Primary Contact: support@goodgov.ai
Data Protection Officer: info@goodgov.ai
Phone: (301) 531-4723
Address: 5557 Baltimore Ave, Ste. 500-1022, Hyattsville, MD 20781
13. Policy Updates
This policy will be updated to reflect changes in legal requirements, technology and system updates, user feedback and needs, and best practice evolution.
We are committed to providing clear, accessible, and comprehensive data deletion services that respect user privacy and comply with applicable laws.