Seek within. Our Philosophy
Innate — operated by Lotus Audaz, Lda
Effective date: 28 April 2026
Last updated: 28 April 2026
Contact: hello@innate.love
This Data Retention Policy sets out how long Lotus Audaz, Lda ("we", "us") retains personal data collected through the Innate mobile application, and the processes by which data is securely deleted or anonymised when it is no longer needed.
This policy supports our compliance with:
We apply the following principles to all data we hold:
| Data Item | Retention Period | Basis |
|---|---|---|
| Name (first, last) | Duration of account + 30 days after deletion | Contract |
| Email address | Duration of account + 30 days after deletion | Contract |
| Hashed password | Duration of account + 30 days after deletion | Contract |
| Profile avatar image | Duration of account + 30 days after deletion | Contract |
| Account preferences | Duration of account + 30 days after deletion | Contract |
Special Category Data
| Data Item | Retention Period | Basis |
|---|---|---|
| Video recording files (S3) | Duration of account + 30 days after deletion | Consent |
| Audio transcripts | Duration of account + 30 days after deletion | Consent |
| Rekognition facial analysis output | Duration of account + 30 days after deletion | Consent |
| AI-classified emotions (Bedrock) | Duration of account + 30 days after deletion | Consent |
| Self-selected emotions and intensities | Duration of account + 30 days after deletion | Consent |
| Life tags and contextual labels | Duration of account + 30 days after deletion | Consent |
| Data Item | Retention Period | Basis |
|---|---|---|
| Challenge enrollments and responses | Duration of account + 30 days after deletion | Contract |
| Community replies | Duration of account + 30 days after deletion | Contract |
| Shared community content | Duration of account + 30 days after deletion | Contract |
| Data Item | Retention Period | Basis |
|---|---|---|
| Session access tokens | 15 minutes (auto-expiry) | Contract |
| Refresh tokens | 7 days (auto-expiry) | Contract |
| Google OAuth tokens | Session duration only | Consent |
| Push notification device tokens | Duration of account | Consent |
| Data Item | Retention Period | Basis |
|---|---|---|
| Server logs (AWS CloudWatch) | 1 year | Legitimate interests |
| Error and crash reports (Sentry) | 90 days | Legitimate interests |
| Application performance metrics | 1 year | Legitimate interests |
| AWS SQS dead letter queue messages | 14 days | Legitimate interests |
| ECR container images | Last 50 images only (rolling) | Legitimate interests |
Anonymised or aggregated data that cannot reasonably be used to identify any individual (e.g. aggregate emotion trend statistics, anonymised usage patterns) may be retained indefinitely for product improvement and research purposes. This data is not subject to the retention periods above because it no longer constitutes personal data.
When a user deletes their account — either from within the App or by submitting a request to hello@innate.love:
Users in the EU/EEA and the United Kingdom may also exercise the Right to Erasure under GDPR / UK GDPR Article 17 by contacting hello@innate.love.
Users may request a copy of all personal data we hold about them. Upon receiving a verified request:
To request your data, contact hello@innate.love with the subject line "Data Export Request".
We require all third-party processors to adhere to retention periods consistent with this policy:
| Processor | Data Retained | Their Retention Policy |
|---|---|---|
| AWS | All hosted data | Deleted on our instruction; CloudWatch logs: 1 year as configured by us |
| Sentry | Crash/error reports | 90 days (configured by us) |
| OAuth tokens | Session-based; governed by Google's Privacy Policy | |
| Expo | Push tokens | Retained until unregistered or account deleted |
AWS RDS automatic backups are retained for 7 days by default. After an account deletion request is processed, that user's data will be excluded from active systems immediately; residual presence in encrypted backups will be eliminated within the 7-day backup rotation window.
Backups are encrypted at rest using AWS managed encryption keys and are accessible only by authorised Lotus Audaz personnel.
Video recordings, facial analysis data, audio transcripts, and emotional health data are classified as special category data under GDPR and UK GDPR. In addition to the retention periods above, we apply the following additional safeguards:
This Data Retention Policy will be reviewed at least annually or whenever there is a material change to our data processing activities, applicable law, or technology stack.
For questions about this policy or to make a data deletion or export request:
Data Controller
Lotus Audaz, Lda
Rua Cândido dos Reis 112
8600-681 Lagos, Portugal