← CrateCore · All legal documents · Русская версия

CrateCore — Data Retention & Deletion Policy Version date: July 17, 2026 Operator: the individual developer of the CrateCore service Contact: [email protected] 1. Purpose This policy describes how long CrateCore keeps different types of data and what happens on export and account deletion. 2. Retention periods Data type: account (authentication) Examples: user identifier, anonymous session flag, e-mail when an account is linked, profile name. Period: while the account exists. Deletion: on account deletion. Data type: settings Examples: genres/eras, drop topics, content language, notification time, timezone, quiet sound. Period: while the account exists. Deletion: cascades on account deletion. Data type: collection Examples: release, grading, price, purchase date, notes. Period: while the account exists. Deletion: cascades on account deletion; individual records removed from the collection are marked deleted in the sync log until it is purged. Data type: wishlist Period: while the account exists. Deletion: cascades on account deletion. Data type: article states Examples: read, saved, liked. Period: while the account exists. Deletion: cascades on account deletion. Data type: audio chain profile and stylus tracker Period: while the account exists. Deletion: cascades on account deletion. Data type: push tokens Period: while the token is valid or while the account exists. Deletion: on sign-out, on account deletion, on disabling notifications, or on server cleanup of an invalid token. Data type: import CSV (file) Period: until the import completes; a safety sweep runs no later than 24 hours. Deletion: automatic after the import and on account deletion. Data type: import log (job and rows) Period: 90 days. Deletion: nightly cleanup; cascades on account deletion. Data type: request and security log Examples: request type, result, response time, rate-limit/attestation events. Period: 30 days. Deletion: nightly cleanup. Data type: sync log (mutations) Period: 90 days. Deletion: nightly cleanup; cascades on account deletion. Data type: notification queue Examples: which story was scheduled for which day. Period: 30 days. Deletion: nightly cleanup; cascades on account deletion. Data type: rate-limit counters and negative barcode cache Period: 2 days / 7 days respectively. Deletion: hourly cleanup. These records contain no user content. Data type: Firebase Analytics Examples: usage events without personal content, pseudonymous identifiers. Period: up to 2 months (user/event-level data; default setting); aggregate reports longer. Deletion: turning analytics off in the app stops collection; deletion requests via [email protected]. Data type: Firebase Crashlytics Examples: stack trace, device model, OS and app version. Period: 90 days. Deletion: per Firebase settings; collection can be turned off in the app. Data type: database backups Period: up to 30 days (when enabled; to be enabled before the production launch). Deletion: automatic rotation; a deleted account's data disappears from backups after their retention expires. Data type: editorial stories and their sources Examples: stories, facts, sources, image attribution. Period: as long as needed for the service, quality checks, audit, and publication; they contain no user data. Deletion: unpublish / takedown. 3. Data export Export is available in the app: Account → Privacy & Data → Export (up to 5 times per hour). The export returns machine-readable JSON with the account's data: settings, collection, wishlist, article states, audio chain profile, stylus tracker, push tokens, sync log, import jobs. The export does not include: - server security logs; - internal rate-limit records; - data whose disclosure would harm security or other people's rights; - third-party processors' data not directly accessible through the app (it can be requested via [email protected]). Your own photos of records are stored only on the device and are not part of the server export. 4. Account deletion Deletion is started in the app (Account → Privacy & Data → Delete account) or by a request to [email protected]. The system deletes: - the authentication account (including e-mail and profile name); - settings, collection, wishlist, article states, audio chain profile, stylus tracker; - push tokens; - import files; - entitlement records. 5. Exceptions Some data may be kept longer where necessary to: - comply with the law; - prevent fraud and abuse; - investigate a security incident; - protect the rights of CrateCore or third parties; - let backup retention expire. 6. Contact Questions about retention and deletion: [email protected].