Data Retention and Disposal Policy

Version 1.0 · Effective 9 October 2026 · Next review 9 October 2027

This policy states how long Dovri keeps each category of member data, why, and how that data is disposed of when the period ends. It sits under the Dovri Information Security Policy, and the periods below are the same ones published in the Dovri Privacy Policy.

Scope and ownership

This policy applies to every record containing member data, wherever it is held — production databases, backups, logs, support correspondence and records held on Dovri's behalf by a third party. The Founder and Chief Executive Officer of Dovri Technologies LLC is accountable for data retention and owns this policy. Dovri Technologies LLC is a Virginia limited liability company and currently has no employees other than the founder. This policy is reviewed at least annually and whenever the law, a partner requirement or the product materially changes.

01Principles

02Retention schedule

The periods below apply from the trigger stated in each row. They are published in the Dovri Privacy Policy so members can see them.

RecordRetention periodReason
Identity records — name, date of birth, address, SSN last four, verification results5 years after the account is closedFinancial-records rules and partner requirements
Transaction records — contributions, payouts, fees, circle history5 years after the transactionFinancial-records rules and dispute resolution
Bank account details and Plaid access tokensDeleted within 30 days of unlinking the account or closing the accountNo longer needed once money cannot move
Transaction history retrieved from a linked accountDeleted within 30 days of unlinking the account or closing the accountNo longer needed once money cannot move
Device and application logs13 monthsFraud investigation and reconstructing access after the fact
Support correspondence24 months after the conversation endsComplaint handling and service history
Early access email addresses collected before launchUntil removal is requested, or 24 months after launchLaunch notification only
Backups35 days on a rolling scheduleRecovery from loss or corruption

Where two periods could apply to the same record, the longer one governs.

03How data is disposed of

Dovri operates no on-premises servers and holds no member data on physical media. Disposal is logical deletion within managed cloud services.

04Member deletion requests

A member may ask Dovri to delete their information by emailing support@joindovri.com from the address on their account. Dovri responds within 30 days.

05Legal holds

Where Dovri is notified of litigation, a regulatory investigation or a law enforcement request, the records in scope are placed on hold and are exempt from scheduled disposal until the hold is lifted. A hold is recorded with its date, scope and the reason, and is reviewed when the matter closes.

A legal hold overrides the retention schedule and a member deletion request alike, for the records it covers and no others.

06Minimisation

07Responsibility and review

The policy owner confirms at least annually that the periods above still match the law, partner contracts and the product, and that scheduled disposal is actually happening rather than merely documented. The review is recorded with its date and any changes made.

A change to any period in the schedule is reflected in the Dovri Privacy Policy in the same release, so the published periods and the internal policy never disagree.

Security contact
security@joindovri.com

This policy sits under the Dovri Information Security Policy. Data handling and retention are covered in the Privacy Policy.

Back to dovri