Data Retention & Processing Policy

Last updated: 25 September 2026 · Version 1.0

Principle: Unknown Verdict is built on the doctrine of data minimisation. The retrieval engine processes query text in memory and does not persist it beyond the PII-redacted audit entry. There is no user account system. There is no session tracking. There is no query history.

1. What data is processed

DataWhere it livesHow long
Query text (original)Process memory onlyMilliseconds — discarded after response
Query text (PII-redacted)Hash-chained audit ledger (JSONL file)Until manually purged
Request IDAudit ledger + response bodySame as above
Retrieval strategy, chunk countAudit ledgerSame as above
Retrieved chunk textNot stored—
Response payloadNot stored—
Client IP addressNot logged by application—
Cookies, session IDsNone—
Analytics, telemetryNone—

2. PII redaction

Before any query text is written to the audit ledger, it passes through a redaction module that detects and removes the following Indian personal identifiers:

Redacted fields are replaced with the token [REDACTED:TYPE]. The original value is not retained anywhere.

3. Audit ledger

Every retrieval produces one entry in the audit ledger. Each entry contains:

The ledger is hash-chained: each entry's prev_hash is the SHA-256 of the previous entry's canonical JSON. Any modification to any historical entry breaks the chain and is detectable by the /admin/audit/verify endpoint.

4. Why we retain the redacted ledger

The ledger is retained for two purposes:

5. What we do not retain

6. Deletion requests

If you wish to have your redacted query entries removed from the audit ledger, email upmanyu@advocacyalawfrim.in with the request ID (visible in the response payload of the query in question). We will remove the entry and re-chain the ledger to preserve integrity. Response time: within 30 days.

Note: because the ledger entries do not contain PII, a deletion request will typically not reveal any personal information. The request is honoured as a matter of policy, not as a technical necessity.

7. On-premise deployments

Unknown Verdict is designed to be runnable on client-controlled infrastructure. When deployed on-premise, the audit ledger is written to the client's own storage. The operator of Unknown Verdict (The Advocacy — A Law Firm) has no access to that ledger.

8. Contact

Data Protection contact: upmanyu@advocacyalawfrim.in
Grievance Officer: Upmanyu Kumar, Advocate — upmanyu@advocacyalawfrim.in