1. What gets deleted automatically
- Uploaded source documents after report generation.
- Temporary OCR/extraction artefacts after report generation or abandoned-session expiry.
- Expired upload sessions, OTP sessions and short-lived access tokens through cleanup jobs.
2. What remains after report generation
- Non-content My Reports metadata (for example Report ID, product, language, payment/invoice references and report-content expiry status). Generated legal-report HTML/JSON/PDF is temporary and is deleted after the configured delivery window.
- Payment order, gateway reference, invoice/GST/tax records and reconciliation status.
- Audit/security logs needed to protect the service and investigate misuse.
- Notification delivery metadata such as channel, masked recipient, delivery status and timestamps.
3. Generated report content
Generated legal-report HTML/JSON/PDF is temporary delivery material and is automatically deleted after the configured delivery window. A user may also request earlier deletion through the configured support/grievance route where available. Non-content transaction, tax, consent and security metadata may remain where required.
4. Records that may not be deleted immediately
GST invoices, payment records, refund/chargeback records, fraud/security logs, legal-hold records and accounting data may be retained for statutory, tax, audit, dispute-resolution or security reasons even after a report-content deletion request.
5. Deletion confirmation
After completing a verified deletion request, the LegalTrust operator should provide a confirmation that identifies what was deleted and what was retained for legal/tax/security reasons.