TOVI
← TOVI

Data retention and disposal policy

EFFECTIVE 25 AUGUST 2026 · VERSION 1.0

Policy owner: Data Protection Officer
Organization: GenesisX Group LLC, operator of Tovi
Review frequency: At least annually and upon material changes to Tovi's systems, products, data processing activities or legal obligations.

1. Purpose

This policy establishes requirements for the retention, deletion and secure disposal of personal, financial and operational information collected or processed by Tovi.

Tovi retains personal information only for as long as reasonably necessary to fulfil the purposes for which it was collected, meet legitimate business or legal requirements, resolve disputes, prevent fraud, and protect the security of its services. When information is no longer required, Tovi deletes, destroys, anonymizes or otherwise renders it inaccessible using methods appropriate to its sensitivity.

One principle shapes the schedule below. The transaction lines are the sharpest information Tovi holds and the least needed once they have been read. The obligations derived from them are the product; the lines themselves are working material, and they are the first thing to go.

2. Scope

This policy applies to information under Tovi's control, including information stored or processed through:

It applies to employees, contractors, officers, administrators and other personnel authorized to access Tovi information.

3. General retention principles

4. Retention schedule

Transaction lines received through a financial account connection

Individual transactions read from a connected account, each with its date, amount, description and category:

Retention period: 400 days from the date of the transaction, after which they are deleted automatically. This is the RETENTION_DAYS setting on the purge job; it is set slightly beyond a year so that a full year of history remains available to recalculate an obligation before the oldest month falls away.

Lines may be deleted earlier on a valid deletion request, or when a member disconnects and retention is no longer reasonably necessary.

Discovered obligations and member decisions

The obligations Tovi derives — category, payee, typical amount, months observed, totals, confidence and status — together with the member's approval, withdrawal or dismissal of each and the time of that decision:

Retention period: for as long as the member has a Tovi profile. These are the member's own record of the service, and are what the product exists to hold. They are deleted on a valid deletion request, subject to any records Tovi must keep to demonstrate what was furnished and on whose authority.

Tovi Reliability snapshots

A score, its factors and the sentences explaining it, recorded each time the score is calculated:

Retention period: for as long as the member has a Tovi profile. A history is kept rather than a single current value because showing a member how their score has moved requires an earlier point to compare against.

Financial account connection credentials

Provider access tokens, connection identifiers and similar technical credentials:

Retention period: only for as long as an authorized connection exists. When a member disconnects, the connection is revoked at the provider and the stored credential is deleted in the same operation. Tovi does not keep a credential against the possibility that the member returns.

Account display information

Institution name, account name and type, the last four digits of an account number and the balance last seen:

Retention period: with the connection record. Marked revoked when the member disconnects, and deleted with the profile.

Session records

The hash of a session token, its creation and expiry, and the time it was last used:

Retention period: 180 days from creation (SESSION_DAYS), and swept once expired. The token itself is never stored; only its hash.

Abuse-prevention information

One-way hashes of IP addresses used for rate limiting on the connection endpoint, with an hourly counter:

Retention period: 2 days. The original address is not retained by Tovi for this purpose.

Application and security logs

Application, error and security logs are retained only for as long as reasonably necessary for security monitoring, troubleshooting, fraud prevention and system administration. Where Tovi controls the retention configuration, logs containing personal information should generally be retained no longer than 12 months, unless a shorter or longer period is reasonably necessary for an active investigation or legal obligation. Consumer financial detail must not be written to logs.

Furnishing records

Records of what was furnished to a consumer reporting agency, when, and on the basis of which member approval:

Retention period: as long as required to demonstrate compliance with the Fair Credit Reporting Act and to investigate disputes, and no longer. Tovi minimizes the personal information retained for this purpose. No furnishing arrangement exists as of the effective date of this policy, so no such records exist.

Data subject requests

Records necessary to document a privacy request and Tovi's response may be retained for a reasonable period after resolution to demonstrate compliance, prevent repeated unauthorized requests and resolve disputes. Tovi minimizes the personal information retained for this purpose.

Anonymized and aggregated information

Information irreversibly anonymized or aggregated so that it can no longer reasonably be associated with an identifiable individual may be retained indefinitely for statistical, analytical, product development or research purposes.

5. Disconnection and connection data

If a member disconnects a financial account, Tovi stops requesting new data through that connection immediately: the item is removed at the provider, the credential is deleted, and the connection is marked revoked, in that order, so that the promise holds even if the operation fails part-way.

Information previously obtained through the connection is reviewed and deleted where it is no longer reasonably necessary for the service, subject to legal, regulatory, security, fraud-prevention and dispute-related requirements. Obligations and reliability history are not deleted on disconnection: they are the member's record of the service, and the application says so on the confirmation before a member disconnects.

6. Deletion requests

Members may request deletion of their personal information by contacting max@genesisglobal.group. On receiving a valid request, Tovi will:

  1. Verify the identity of the requester where reasonably necessary.
  2. Identify the personal information associated with the individual.
  3. Determine whether any of it must be retained for a lawful or legitimate reason.
  4. Delete or anonymize what is no longer required.
  5. Revoke any live financial account connection and delete its credential.
  6. Take reasonable steps to address copies held by processors acting on Tovi's behalf.
  7. Document completion of the request.

Information that must be retained for legal, regulatory, fraud-prevention, security, contractual or dispute-related purposes is isolated or restricted where appropriate and deleted when the reason for retention ends.

7. Secure disposal

Personal and financial information is disposed of using methods designed to prevent unauthorized recovery or reconstruction. Depending on the system this may include permanent deletion of database records; revocation and deletion of access credentials and tokens; cryptographic deletion where supported; secure deletion through cloud provider functionality; removal from authorized personnel devices; physical destruction of retired storage media; and irreversible anonymization where statistical retention is appropriate.

8. Backups

Tovi relies on its cloud providers for infrastructure, storage, redundancy and backup. Deletion from active production systems may not immediately remove information from encrypted backups where individual records cannot reasonably be removed without affecting the integrity of the backup. Where that occurs, backup information remains protected by applicable controls, is retained only according to the provider's normal backup lifecycle, is not intentionally restored to active processing except for legitimate disaster recovery, and — if restored — has applicable deletion requests and retention rules reapplied.

9. Third-party service providers

Tovi uses Plaid, Supabase and Cloudflare to process or store information. Tovi seeks providers that maintain appropriate security, retention and disposal practices for the sensitivity of the information processed. Where Tovi instructs a processor to delete information, the processor may retain limited copies in backups, security logs or other systems according to its contractual terms, documented retention cycles or legal obligations. Plaid separately retains information it processes in accordance with its own privacy policy.

10. Legal holds and retention exceptions

Ordinary retention periods may be suspended where information is reasonably necessary for compliance with law or regulation; a court order or governmental request; pending or reasonably anticipated litigation; investigation of suspected fraud; investigation of a security incident; enforcement of contractual rights; or the establishment, exercise or defence of legal claims.

Information retained under an exception must not be kept indefinitely merely because an exception once existed. When the reason ends, the information returns to its ordinary schedule.

11. Responsibility

The Data Protection Officer oversees this policy. Personnel with access to personal or financial information must follow the retention and disposal requirements and must not keep unauthorized personal copies of member information. Technical personnel are responsible for configuring retention and deletion mechanisms in the systems under their control — which, concretely, means keeping the purge job scheduled and its settings aligned with section 4.

12. Periodic review

Tovi reviews the categories of personal information it holds, the purposes for retaining them, the applicable periods, service provider practices, technical deletion procedures and legal requirements at least annually and when material changes occur. Retention periods no longer justified by a legitimate purpose are shortened or removed.

13. Policy compliance

Material exceptions must be documented and approved by the Data Protection Officer or company leadership. Failure to comply may result in suspension or removal of access to Tovi systems.

14. Policy review and approval

This policy will be reviewed at least annually and updated as necessary.

See also our privacy notice and our information security policy.