Skip to content

Data retention

Data inventory

DataLocationClassification
Canvas content (strokes, text, images)S3 private/{ownerId}/{id}/{rev}.frondCustomer content (potentially PHI)
Document metadata (name, size, revision)DynamoDBCustomer content
Published copiesS3 published/{token}/latest.frondPublic (opt-in)
User account (email, verified status)CognitoPII
Access/audit logsCloudTrail S3 + CloudWatch Logs + CloudFront logsOperational

Retention periods

DataRetentionRationale
Document revisions (S3 versions)1 year hot, then IA, expire after 5 yearsRevision history + HIPAA audit needs
DynamoDB recordsUntil deletion; PITR 35 daysCustomer control
Cognito accountsUntil user deletes or requests deletionGDPR/CCPA right to erasure
CloudWatch logs1 yearSecurity monitoring window
CloudTrail1 year (S3), configurable longerCompliance

Deletion paths

  1. User deletes a document → API removes all S3 revisions and the DynamoDB row immediately (versions are expired via lifecycle; PITR copies age out within 35 days).
  2. User deletes account (support request) → Cognito deletion + document deletion for that owner (documented runbook).
  3. Unpublish → the published/ copy is deleted immediately; already shared links stop working.

Data minimization

  • Lambda logs never include document names, content, or tokens.
  • Presigned URLs expire in 10 minutes and are not stored.
  • The marketing site runs no third-party tracking.
  • Telemetry (future) is opt-in and excludes canvas content.

PHI-specific guidance

If a covered entity uses the product for PHI: minimize PHI in canvases, never publish those canvases, and note that PITR copies and S3 versions retain data for the windows above after deletion. Contact support for a deletion certificate after any bulk PHI removal.