# Privacy & Data Custody Policy

Data custody, deliverable retention, tenant isolation boundaries, and security practices at Bestie.

Bestie provides verification for knowledge-work deliverables. This policy describes how deliverables, analysis graphs, and account data are handled throughout the Check lifecycle.

## Deliverable Custody & Retention

Deliverables uploaded or staged for a Check run are stored in tenant-scoped storage and processed by the verification pipeline. Analysis records, extraction graphs, findings, and sealed cryptographic receipts are retained under standard tenant custody to support auditability and rerun verification.

## Tenant Isolation & Access Boundaries

All customer data is partitioned by tenant ID. Cryptographic receipts bind tenant identity to the run artifact. Access to internal check APIs requires verified API credentials, and internal operators follow least-privilege administrative protocols.

## Public Telemetry & Server Logs

Public documentation and marketing pages record operational request telemetry (HTTP method, route, response status, latency, user agent, and Accept header family) to monitor service availability and performance.

## Data Subject Inquiries & Support

To inquire about tenant records, request account data deletion, or report security considerations, contact our operations team at [support@hirebestie.com](mailto:support@hirebestie.com).
