Help + Retention Matrix
How the platform works
1. Onboarding: 7-step wizard captures brand description, target audience, voice, sources. 2. Cycle: Platform generates carousel proposals on your configured schedule (Settings → Cycles & schedule). 3. Review: Operator reviews each proposal (Approve / Park) in the UI. 4. Render + Review: On Approve the carousel is rendered and marked ready. 5. Publish: An administrator explicitly releases the reviewed post via a publish confirmation; only then is it published to the connected tenant platforms (with the Art. 50 AI marker appended server-side to every caption). Nothing is published without that explicit release; scheduled posts pass through the same gate at dispatch.
Retention Matrix
| Data category | Location | Period | Legal basis |
|---|---|---|---|
| Auth user (email) | Supabase auth.users | Contract + 30d grace | Art. 6(1)(b) |
| Tenant content (brand.json etc.) | Supabase orgs + brands | Contract duration | Art. 6(1)(b) |
| Voice-anchor audio | R2 EU | Until C5 withdrawn or contract + 90d grace | Art. 6(1)(a) C5 |
| Cycle ledger | Supabase carousel_cycles | Contract duration — no automatic deletion runs on this table today | Art. 6(1)(f) statistics |
| Tenant consents | Supabase tenant_consents | Contract + 3 years (Art. 7(1) burden of proof) | Art. 5(2) + 7(1) |
| Tenant profile versions | Supabase tenant_profile_versions | Last 50 versions per tenant, pruned on write | Art. 5(1)(e) |
| Operator audit log | Supabase operator_actions | Contract + 6 years (§ 147 AO) | § 147 AO + Art. 5(1)(f) |
| Telegram chat_id | Supabase | Until C4 withdrawn or contract end | Art. 6(1)(b) C4 |
| Notification destinations (email address, Telegram chat ID, Slack webhook URL, webhook URL + HMAC secret, per-event routing) | Supabase tenant_credentials; secrets in Supabase Vault | Until you remove the channel, otherwise contract end | Art. 6(1)(b) |
| Notification delivery log (cycle_step_states: channel, status, timestamps — no destination URL, no payload) | Supabase | 12 months after the step's last update, deleted automatically by a nightly job | Art. 6(1)(f) |
| Worker diagnostic logs (tenant_id, cycle_id, error class) | Cloudflare Workers Logs | Cloudflare's retention window for our plan — we set no retention override and export no copy (no Logpush) | Art. 6(1)(f) security/diagnostics |
| MailerLite subscriber | MailerLite | Until C7 withdrawn or 24m no engagement | Art. 6(1)(a) C7 |
| IP addresses | pseudonymised, daily-rotating salt | 24h pseudonymised | Art. 5(1)(c) |
FAQ
How do I revoke a consent? Settings → Consents → toggle off.
How do I delete my account? You can delete your account at any time via Settings → Account → Delete my account (/app/settings/account/delete-my-account). Deletion is immediate (cascade across auth.users → memberships → auth_recovery_codes → MFA factors); consent provenance is pseudonymised-retained per Art. 7(1) GDPR / §147 AO. A confirmation email will be sent to your registered address.
What happens to my data at contract end? Export request: by email to contact@bykainsights.com. Hard-delete: after 30-day grace.
Last updated: 2026-08-02