Clarify unverified case cleanup

This commit is contained in:
SimpleTest 2026-08-13 05:29:46 +03:00
parent 17c93fa2f4
commit 7130be3b69

View File

@ -54,8 +54,15 @@ workspace through PubSub and do not generate one operator email per message.
Exact repeats of the same unverified public support submission are represented
by one pending row. Its temporary fingerprint is a SHA-256 digest of normalized
form fields; it is cleared on verification and does not replace the original
record or its audit history. Existing unverified rows are quarantined rather
than deleted because no retention policy has been approved.
record or its audit history. A pending support request or an emailed removal
notice that is still unverified after
`PUBLIC_CONTACT_VERIFICATION_MAX_AGE_SECONDS` is deleted by the maintenance
worker together with its creation audit entry. This verification-lifecycle
cleanup does not delete confirmed cases. A permitted no-contact report of
sexual material involving a minor has no mailbox to verify, enters the urgent
staff queue immediately, and is therefore outside this unverified-contact
cleanup. Retention or erasure of verified and no-contact case records remains
disabled until an applicable policy is approved.
Email-link verification establishes access to the mailbox, not government
identity, authority to act for another person, or the truth of the claim.