We keep the findings, not the evidence — and those are different things
What survives an audit is the measurement: the finding rows (rule_id, verdict, severity, layer, module, category, framework, device_variant, environment, wcag_reference, run_timestamp, audit_id), the score and the coverage arithmetic. That record is what lets a second audit tell you which of your findings you actually fixed, and it is what the benchmark clause in the Terms aggregates. It contains none of the following: screenshots, video frames, element text, accessibility labels, credentials, build bytes, and any pointer that could retrieve a destroyed artifact. It is linked to your audit and your Device Token, so it is pseudonymous rather than anonymous; only the benchmark projection is de-identified, and you can have your audit excluded from that or erased entirely by asking.