> ## Documentation Index
> Fetch the complete documentation index at: https://docs.mnemom.ai/llms.txt
> Use this file to discover all available pages before exploring further.

# Aletheia Customer Voice — Retention Policy

> Retention settings, on-request deletion, and audit trail for Aletheia Customer Voice data

This page documents retention and deletion for data collected by Aletheia Customer Voice (in-product feedback). Retention is a per-org setting, not a plan-tier default — see below for exactly what it does and does not do today.

<Note>
  This document describes the technical retention implementation. It does not constitute legal advice. Consult qualified legal counsel for your specific obligations under GDPR or other applicable data-protection regulations.
</Note>

## Retention setting

Every org has a `retention_days` value for its Customer Voice submissions: an integer from 1 to 3,650, or `null`. **The default is `null` — retain indefinitely** — until an org owner or admin sets a value.

<Warning>
  Setting `retention_days` records the org's retention policy, but **nothing currently reads it to automatically delete aged submissions.** There is no scheduled job that enforces this setting yet. The API reports this honestly: the settings response includes `"enforcement_active": false`. If you need a submission gone, delete it explicitly — see **On-request deletion** below.
</Warning>

## Configuring retention

The org-scoped settings endpoint authenticates with a bearer token and is available to the owner/admin (write) or owner/admin/auditor (read) roles.

Check the current retention setting for an org:

```http theme={null}
GET /v1/orgs/{org_id}/customer-voice/settings
Authorization: Bearer $TOKEN
```

```json theme={null}
{
  "org_id": "...",
  "retention_days": null,
  "updated_by": null,
  "updated_at": null,
  "enforcement_active": false
}
```

Set a retention period:

```http theme={null}
PATCH /v1/orgs/{org_id}/customer-voice/settings
Authorization: Bearer $TOKEN
Content-Type: application/json

{"retention_days": 90}
```

Restore indefinite retention:

```http theme={null}
PATCH /v1/orgs/{org_id}/customer-voice/settings
Authorization: Bearer $TOKEN
Content-Type: application/json

{"retention_days": null}
```

## On-request deletion

Because automatic expiry is not yet enforced, deletion today is always explicit — issued by an org owner or admin. Both endpoints erase the matching rows synchronously (the erasure is complete by the time the response returns) and return `200 OK`.

Delete all Customer Voice submissions for an org:

```http theme={null}
DELETE /v1/orgs/{org_id}/customer-voice
Authorization: Bearer $TOKEN
```

```json theme={null}
{ "deleted": 42, "org_id": "..." }
```

Delete a single submission:

```http theme={null}
DELETE /v1/orgs/{org_id}/customer-voice/{submission_id}
Authorization: Bearer $TOKEN
```

```json theme={null}
{ "deleted": 1, "submission_id": "..." }
```

A submission ID that doesn't exist, or belongs to another org, returns `404` either way — the response never discloses which.

<Warning>
  Deletion is irreversible. There is no tombstone or recovery window once a submission is erased.
</Warning>

## Audit trail

Every export, deletion, and settings change is recorded internally in Mnemom's governance audit log against the acting user and the org. This is a separate log from the general request-level `GET /v1/orgs/{org_id}/audit-log` endpoint (which covers HTTP-request metadata, not this feedback-specific governance trail) — there is currently no dedicated customer-facing endpoint to query these particular records directly.

## Related

* [Customer Voice Privacy & Data Use](/guides/customer-voice-privacy) — What is collected, consent, and data subject rights
* [GDPR Right to Erasure](/guides/gdpr-data-subject-rights) — Right to erasure and full deletion cascade architecture
* [EU AI Act Compliance](/guides/eu-compliance) — Article 50 audit-trail obligations


This documentation is built and hosted on [Mintlify](https://mintlify.com), a developer documentation platform.