Skip to content

No data retention policy engine #460

Description

@2witstudios

Problem

There is no automatic expiration or cleanup engine for any data category. While several tables have expiresAt fields, enforcement happens at the read layer only (filtering expired records from queries), with no periodic deletion of expired data.

Current State

Tables with expiresAt but no automated cleanup:

  • pulse_summaries (6-hour TTL) — indexed but never cleaned
  • page_versions (30-day default, subscription-tier based) — filtered at query time only
  • sessions, verification_tokens, socket_tokens, email_unsubscribe_tokens — no cleanup
  • drive_backups, drive_backup_permissions, page_permissions — no cleanup

What does get cleaned up:

  • device_tokens — hourly cron marks as revoked (but doesn't hard-delete)
  • Redis JTIs — auto-expired by Redis TTL

Notable: A retention_policies table was created in migration 0025 but dropped in migration 0071, suggesting the feature was abandoned.

Impact

  • Database grows unbounded with expired but never-deleted records
  • No compliance with data minimization principles (GDPR Art. 5(1)(e))
  • Related: AI Usage Logs Stored Indefinitely #458 (AI Usage Logs Stored Indefinitely)

Proposed Solution

Build a retention policy engine that:

  1. Periodically hard-deletes rows past their expiresAt across all relevant tables
  2. Runs as a cron job (similar to existing cleanup-tokens)
  3. Respects subscription-tier retention policies for version history
  4. Logs cleanup operations for audit purposes

Effort: Medium

References

  • Cron infrastructure: docker/cron/crontab
  • Token cleanup example: apps/web/src/app/api/cron/cleanup-tokens/route.ts
  • Version retention: apps/web/src/services/api/rollback-service.ts (getUserRetentionDays())

Activity

  1. added a commit that references this issue on Feb 8, 2026
    b6eeec6
  2. added a commit that references this issue on Feb 9, 2026
    cc2beb9
Sign up for free to join this conversation on GitHub. Already have an account? Sign in to comment

Metadata

Metadata

Assignees

No one assigned

    Labels

    No labels
    No labels

    Projects

    No projects

      Milestone

      No milestone

      Relationships

      None yet

      Development

      No branches or pull requests

      Issue actions