Data Retention and Disposal Policy
Version 1.0 · Effective 9 October 2026 · Next review 9 October 2027
This policy states how long Dovri keeps each category of member data, why, and how that data is disposed of when the period ends. It sits under the Dovri Information Security Policy, and the periods below are the same ones published in the Dovri Privacy Policy.
This policy applies to every record containing member data, wherever it is held — production databases, backups, logs, support correspondence and records held on Dovri's behalf by a third party. The Founder and Chief Executive Officer of Dovri Technologies LLC is accountable for data retention and owns this policy. Dovri Technologies LLC is a Virginia limited liability company and currently has no employees other than the founder. This policy is reviewed at least annually and whenever the law, a partner requirement or the product materially changes.
01Principles
- Dovri collects the minimum data needed to run the service.
- Each category of data has a stated retention period, and nothing is kept indefinitely by default.
- Data is disposed of once its period ends, unless a legal hold applies.
- Where a record must be kept for a regulatory period, it is retained for that period and no longer.
02Retention schedule
The periods below apply from the trigger stated in each row. They are published in the Dovri Privacy Policy so members can see them.
| Record | Retention period | Reason |
|---|---|---|
| Identity records — name, date of birth, address, SSN last four, verification results | 5 years after the account is closed | Financial-records rules and partner requirements |
| Transaction records — contributions, payouts, fees, circle history | 5 years after the transaction | Financial-records rules and dispute resolution |
| Bank account details and Plaid access tokens | Deleted within 30 days of unlinking the account or closing the account | No longer needed once money cannot move |
| Transaction history retrieved from a linked account | Deleted within 30 days of unlinking the account or closing the account | No longer needed once money cannot move |
| Device and application logs | 13 months | Fraud investigation and reconstructing access after the fact |
| Support correspondence | 24 months after the conversation ends | Complaint handling and service history |
| Early access email addresses collected before launch | Until removal is requested, or 24 months after launch | Launch notification only |
| Backups | 35 days on a rolling schedule | Recovery from loss or corruption |
Where two periods could apply to the same record, the longer one governs.
03How data is disposed of
Dovri operates no on-premises servers and holds no member data on physical media. Disposal is logical deletion within managed cloud services.
- When a retention period ends, the record is deleted from the production database. Deletion is permanent; Dovri does not retain a shadow copy.
- Plaid access tokens are revoked with Plaid at the point of unlinking, not merely deleted locally, so the connection to the member's bank is severed as well as forgotten.
- Backups are not edited to remove individual records. A deleted record persists only in backups taken before the deletion, and ages out when those backups expire on the 35-day rolling schedule. No backup is restored into production to recover deleted member data.
- Logs expire automatically at 13 months through the platform's retention setting rather than by manual deletion.
- Where a third party holds member data on Dovri's behalf, deletion is requested from that party and the request is recorded.
- Workstations use full-disk encryption. A device is cryptographically erased or wiped before it is sold, returned or discarded.
04Member deletion requests
A member may ask Dovri to delete their information by emailing support@joindovri.com from the address on their account. Dovri responds within 30 days.
- Bank account details, access tokens and retrieved transaction history are deleted, and the Plaid connection is revoked.
- Identity and transaction records are retained for the remainder of the five-year regulatory period and are not used for any purpose other than meeting that obligation. The member is told which records are being kept and why.
- A member with an active circle is told that records tied to that circle cannot be deleted until the circle completes, because other members depend on them.
- Marketing and early access addresses are deleted on request with no retention period.
05Legal holds
Where Dovri is notified of litigation, a regulatory investigation or a law enforcement request, the records in scope are placed on hold and are exempt from scheduled disposal until the hold is lifted. A hold is recorded with its date, scope and the reason, and is reviewed when the matter closes.
A legal hold overrides the retention schedule and a member deletion request alike, for the records it covers and no others.
06Minimisation
- Dovri does not store bank usernames or passwords, and never receives them.
- Only the last four digits of a Social Security number are collected; the full number is not stored.
- Production data is not copied into development or test environments. Testing uses synthetic data.
- Before a new field is added to the product, its retention period and disposal route are decided and added to the schedule above.
07Responsibility and review
The policy owner confirms at least annually that the periods above still match the law, partner contracts and the product, and that scheduled disposal is actually happening rather than merely documented. The review is recorded with its date and any changes made.
A change to any period in the schedule is reflected in the Dovri Privacy Policy in the same release, so the published periods and the internal policy never disagree.
This policy sits under the Dovri Information Security Policy. Data handling and retention are covered in the Privacy Policy.