Data inventory
| Data | Location | Classification |
|---|
| Canvas content (strokes, text, images) | S3 private/{ownerId}/{id}/{rev}.frond | Customer content (potentially PHI) |
| Document metadata (name, size, revision) | DynamoDB | Customer content |
| Published copies | S3 published/{token}/latest.frond | Public (opt-in) |
| User account (email, verified status) | Cognito | PII |
| Access/audit logs | CloudTrail S3 + CloudWatch Logs + CloudFront logs | Operational |
Retention periods
| Data | Retention | Rationale |
|---|
| Document revisions (S3 versions) | 1 year hot, then IA, expire after 5 years | Revision history + HIPAA audit needs |
| DynamoDB records | Until deletion; PITR 35 days | Customer control |
| Cognito accounts | Until user deletes or requests deletion | GDPR/CCPA right to erasure |
| CloudWatch logs | 1 year | Security monitoring window |
| CloudTrail | 1 year (S3), configurable longer | Compliance |
Deletion paths
- User deletes a document → API removes all S3 revisions and the
DynamoDB row immediately (versions are expired via lifecycle; PITR copies
age out within 35 days).
- User deletes account (support request) → Cognito deletion + document
deletion for that owner (documented runbook).
- Unpublish → the
published/ copy is deleted immediately; already
shared links stop working.
Data minimization
- Lambda logs never include document names, content, or tokens.
- Presigned URLs expire in 10 minutes and are not stored.
- The marketing site runs no third-party tracking.
- Telemetry (future) is opt-in and excludes canvas content.
PHI-specific guidance
If a covered entity uses the product for PHI: minimize PHI in canvases, never
publish those canvases, and note that PITR copies and S3 versions retain data
for the windows above after deletion. Contact support for a deletion
certificate after any bulk PHI removal.