Privacy summary
Data Retention Summary
This summary describes retention implemented in the current FixIt FREE V1. Where code has no fixed duration, the category is retained according to operational policy.
Photo Diagnostics
Image bytes: processed in memory and sent to Google Gemini; not persisted by the FixIt API in its database or file storage. Temporary client-side processed files are replaced or cleared by the app lifecycle. Provider-side handling follows Google’s terms.
Results and history: stored until the repair entry, guest installation data, or account is deleted. No automatic duration is currently defined.
Usage/quota events: deliberately remain after an individual or bulk repair-history deletion so quotas cannot be reset by deleting history. They are removed by eligible guest-data or account-wide deletion.
Live Repair
FixIt does not enable LiveKit recording. Stored transcript/message content and detailed operational payload are minimized no later than 30 days after a completed session. The history row, status, timestamps, and summary can remain until history, guest installation data, or account deletion.
Account, profile, and safety records
Account mappings, verified email when supplied, linked installations, property/profile/device data, and repair history remain while the account or guest installation is active, until eligible deletion. Safety events linked to deleted repair sessions are deleted with those sessions.
Security and operational records
Rate-limit counters and concurrency leases expire with their configured short windows. Coarse network-derived HMAC fingerprints are non-reversible without the server secret and are retained with those security windows.
Request/security logs are retained according to operational and hosting-provider policy. Operational logs hosted in Railway are available to FixIt operators for 30 days under the current Railway Pro plan. FixIt does not currently export or archive these logs to another logging provider. Railway controls any underlying provider-side retention outside the operator-visible period.
Deletion tombstones and providers
Account-deletion tombstones are retained for up to 24 months after account deletion for security, deletion-integrity, and abuse-prevention purposes. Tombstones contain only a non-reversible HMAC-derived identifier, provider namespace, and deletion timestamp, and are not used to restore deleted account data.
Account deletion removes live application data, but it cannot selectively rewrite immutable historical backups. Deleted data may remain encrypted in an existing backup until that backup expires under its schedule or approved manual-backup retention. Backups are not used to restore deleted accounts except during legitimate disaster recovery, after which deletion protections must be reapplied and verified.
FixIt cannot promise immediate deletion of records independently retained by Clerk, Google/Gemini, LiveKit, Railway, Apple, Google sign-in, or Stripe under their own policies.