Ruzzler.

Data Retention & Deletion Policy

Effective Date: August 22, 2026 · Last Updated: August 22, 2026 · Version 2026-08-22-personal-memory-v1

Effective Date: August 22, 2026

1. Purpose

This Policy explains how Ruzzler retains, recovers, deletes, and disposes of information.

2. No Universal ISO Retention Period

Ruzzler's retention periods are established according to its own operational, contractual, security, and legal needs.

The 30-day recoverability period and 7-day active-system deletion target are Ruzzler policy choices, not a representation that ISO standards universally require those specific periods.

3. Data Minimization

Ruzzler seeks to retain information only for as long as reasonably necessary for: providing Services; Customer instructions; security; legal obligations; dispute handling; billing; fraud prevention; or legitimate business purposes.

4. Active Customer Content

During an active account, Customer Content may be retained according to Customer settings and the functionality requested.

Customers may delete eligible information using available controls.

5. Private Vault Content

Personal Memory and private Vault content remain stored while authorized by the individual. Customer configuration, payment, administration, offboarding, or a Customer retention schedule does not transfer control of that content to Customer.

The individual may delete eligible content, undo a prior promotion, or replace an incorrect memory through available controls. A correction supersedes the prior derived fact for future retrieval; casual references, jokes, or repeated mentions do not override an explicit preference or correction unless the individual expressly changes it.

Undoing a promotion removes the promoted copy and its eligible derivatives from the destination without exposing or changing the private source. Deletion propagates to eligible indexes, summaries, caches, and derived records. Where supported, cryptographic erasure makes remaining encrypted copies inaccessible by destroying or disabling the applicable data key.

Private Chat content is ephemeral and is not retained in history, Personal Memory, indexes, summaries, or content logs. Limited content-free security and billing records may be retained for the periods otherwise described in this Policy.

6. Terminated Accounts

Unless another contractual or legal requirement applies:

• Customer Content may remain recoverable for up to 30 days following termination or an authorized deletion event.

• During that period, restoration may be possible.

• After the recovery period expires, Ruzzler will target deletion from active production systems within 7 additional days.

7. Immediate or Accelerated Deletion

Where legally required or technically supported, Ruzzler may process an accelerated deletion request.

Security, legal, billing, fraud-prevention, or backup requirements may prevent immediate deletion of every residual copy.

8. Backups

Deleted information may remain temporarily in encrypted or otherwise protected backups until normal backup rotation.

Backup systems are generally designed for disaster recovery rather than individual record retrieval.

Deleted information retained solely in backup should not be restored to active production except where required for legitimate disaster recovery or legal purposes.

9. Billing and Financial Records

Invoices, transaction records, tax records, fraud-prevention records, and similar information may be retained for periods required by law or legitimate accounting obligations even after Customer Content is deleted.

10. Security Logs

Security logs may be retained for a period reasonably necessary to detect, investigate, and document security events.

11. Operational Metadata

Workflow and system metadata may be retained according to operational need and Customer configuration.

Where feasible, Ruzzler may aggregate or de-identify metadata that no longer requires user-level association.

12. Employee Profiles

Work-related employee operational profiles remain subject to Customer configuration and applicable legal obligations.

Unrelated personal information should not intentionally be stored in such profiles.

13. AI Provider Retention

Some Customer Content may be transmitted to external AI providers.

Deletion from Ruzzler systems does not itself control copies lawfully retained by an independent provider.

Ruzzler will select and configure downstream providers in accordance with its contractual commitments and will disclose relevant subprocessors where required.

14. Legal Holds

Deletion may be suspended where information must be retained because of: litigation; investigation; legal process; regulatory obligations; security incidents; or another binding legal requirement.

Customer legal holds, workplace investigations, retention settings, and offboarding instructions do not apply to an individual's Personal Memory. A binding legal requirement directed to BEE RAD TECH may apply independently, subject to applicable law and the notice and narrowing commitments in the Privacy Policy.

15. Customer-Controlled Retention

Enterprise Customers may receive configurable retention controls where supported.

Customers are responsible for configuring retention consistently with their legal obligations.

16. Deletion Verification

Ruzzler may maintain limited records showing that a deletion request was processed without retaining the deleted content itself.

17. Secure Disposal

When information reaches the end of its retention period, Ruzzler will use deletion or disposal methods appropriate to the applicable system and data type.

18. Account Export

Where supported, Customers should export required data before termination or expiration of the recovery period.

19. Requests

Deletion requests may be sent to: privacy@ruzzler.com.

Identity or authority may need to be verified before deletion is completed.