diff --git a/docs/support-and-content-removal.md b/docs/support-and-content-removal.md index 54f21b5..ec90d61 100644 --- a/docs/support-and-content-removal.md +++ b/docs/support-and-content-removal.md @@ -54,8 +54,15 @@ workspace through PubSub and do not generate one operator email per message. Exact repeats of the same unverified public support submission are represented by one pending row. Its temporary fingerprint is a SHA-256 digest of normalized form fields; it is cleared on verification and does not replace the original -record or its audit history. Existing unverified rows are quarantined rather -than deleted because no retention policy has been approved. +record or its audit history. A pending support request or an emailed removal +notice that is still unverified after +`PUBLIC_CONTACT_VERIFICATION_MAX_AGE_SECONDS` is deleted by the maintenance +worker together with its creation audit entry. This verification-lifecycle +cleanup does not delete confirmed cases. A permitted no-contact report of +sexual material involving a minor has no mailbox to verify, enters the urgent +staff queue immediately, and is therefore outside this unverified-contact +cleanup. Retention or erasure of verified and no-contact case records remains +disabled until an applicable policy is approved. Email-link verification establishes access to the mailbox, not government identity, authority to act for another person, or the truth of the claim.