24-Hour Zero-Retention Data Policy
Effective Date: August 15, 2026 · ICAO Document 9303 Part 3 Privacy Standard
1. Tiered Zero-Retention Architecture (Cloudflare R2)
ApprovaVisa operates under an unconditional zero-retention architecture powered by private Cloudflare R2 object storage with automated hardware-level lifecycle rules:
- Standard Plan (24-Hour Purge): All images, biometric coordinates, and print sheets submitted to our engine are automatically and permanently purged from Cloudflare R2 storage within 24 hours of generation.
- Premium Plan (7-Day Vault): For users who order the Expert Certified package, files are retained in an encrypted private vault for 7 days to enable specialist verification, consular PDF certificate generation, and cross-device re-downloads before being irreversibly deleted.
2. Zero Account & Cryptographic Session Security
We do not require users to create accounts, store passwords, or link personal identities. Transactions and file downloads are authenticated exclusively through cryptographically signed, tamper-proof HMAC-SHA256 session tokens. Download sessions automatically expire matching your plan's retention period (24 hours for Standard, 7 days for Premium), after which all access is permanently sealed.
3. Encryption & Transmission Security
All data transmission between your browser and our validation engine is encrypted using industry-standard TLS 1.3 with 256-bit SSL encryption. We never sell, license, share, or use your facial photography for AI model training or third-party behavioral profiling.
4. Payment Processing
All financial transactions are handled securely by Razorpay. ApprovaVisa does not collect, process, or store credit card numbers, CVVs, or banking credentials.