Public production record
Evidence retention and minimization
Version: 1.0
Effective date: 30 August 2026
Owner: Kua SpA
Canonical URL: https://syntheticbeef.lab.kua.cl/legal/evidence-retention
Purpose
Kua SpA keeps the smallest production record reasonably capable of showing what was generated, under which conditions, how publication decisions were made, and what changed after publication. Retention is an accountability control, not permission to collect an operator's unrelated files or credentials.
Records retained for a generation run
The private episode dossier retains:
- the frozen episode specification, questions, prompts and declared editorial controls;
- the production-date source register and the source copies actually used for factual, contractual, safety and disclosure decisions;
- the code commit, dependency lock, relevant tool versions, provider interfaces, requested and resolved model identifiers, and self-hosted model revision;
- exact model requests, raw responses, request identifiers where providers return them, retry history, deterministic transformations and hash-chained event records;
- the generated transcript, whole-run acceptance or rejection record, automated checks and the reason for any complete-run rejection;
- the accepted final master or an exact preservation copy, together with hashes of the published transcript, audio, video and public audit manifest;
- the disclosures and platform settings used at publication; and
- material correction, complaint, right-to-comment, pause, takedown and republication records concerning the episode.
Interrupted and rejected generation runs retain the text-level run dossier needed to prove that no answer was carried into an accepted run. Post-production is not performed for a rejected run.
Records excluded by default
The archive does not retain:
- passwords, API keys, session tokens, authentication databases or exported browser profiles;
- virtual environments, package caches, model-weight caches or general operating-system snapshots;
- unrelated home-directory, company, customer, employee or personal files;
- disposable preview audio, duplicate text-to-speech caches, waveform caches, temporary renders or other reproducible intermediates when their settings and relevant hashes are already recorded;
- routine debug output unrelated to a material failure or editorial decision; or
- additional bulk copies of a legacy archive merely because a new storage provider exists.
If a normally excluded record becomes material to a dispute or explains a production failure, Kua SpA may preserve that specifically identified record and document why.
Storage and access
New episode dossiers are stored privately with restricted credentials, encryption at rest and compliance-mode retention where the selected provider supports it. Public manifests publish verification facts without exposing raw prompts that create a safety, privacy or contractual concern, personal data, or credentials.
The pre-publication legacy archive made on 28 August 2026 remains in its existing verified Cloudflare R2 preservation copy. Its prefix-retention rule is administrator-removable and is not represented as compliance-mode WORM. It is not duplicated into the new Backblaze archive because most of its size is cached audio and a second bulk copy would not materially improve the episode-one decision record. This decision does not authorize deletion of the existing copy.
Retention period and holds
Episode evidence is normally retained for at least seven years from capture. A known or reasonably anticipated dispute, investigation, preservation request or legal hold suspends ordinary deletion for relevant records. At the end of a retention period, Kua SpA reviews necessity, privacy and any active hold before deletion; expiry is not an instruction to delete automatically.
Access is limited to people who need the record for production accountability, security, complaints, disputes or legal compliance. Access and restoration tests should be recorded without copying credential values into the dossier.