← CrateCore · All legal documents · Русская версия
CrateCore — Data Retention & Deletion Policy
Version date: July 17, 2026
Operator: the individual developer of the CrateCore service
Contact: [email protected]
1. Purpose
This policy describes how long CrateCore keeps different types of data and what happens on export and account deletion.
2. Retention periods
Data type: account (authentication)
Examples: user identifier, anonymous session flag, e-mail when an account is linked, profile name.
Period: while the account exists.
Deletion: on account deletion.
Data type: settings
Examples: genres/eras, drop topics, content language, notification time, timezone, quiet sound.
Period: while the account exists.
Deletion: cascades on account deletion.
Data type: collection
Examples: release, grading, price, purchase date, notes.
Period: while the account exists.
Deletion: cascades on account deletion; individual records removed from the collection are marked deleted in the sync log until it is purged.
Data type: wishlist
Period: while the account exists.
Deletion: cascades on account deletion.
Data type: article states
Examples: read, saved, liked.
Period: while the account exists.
Deletion: cascades on account deletion.
Data type: audio chain profile and stylus tracker
Period: while the account exists.
Deletion: cascades on account deletion.
Data type: push tokens
Period: while the token is valid or while the account exists.
Deletion: on sign-out, on account deletion, on disabling notifications, or on server cleanup of an invalid token.
Data type: import CSV (file)
Period: until the import completes; a safety sweep runs no later than 24 hours.
Deletion: automatic after the import and on account deletion.
Data type: import log (job and rows)
Period: 90 days.
Deletion: nightly cleanup; cascades on account deletion.
Data type: request and security log
Examples: request type, result, response time, rate-limit/attestation events.
Period: 30 days.
Deletion: nightly cleanup.
Data type: sync log (mutations)
Period: 90 days.
Deletion: nightly cleanup; cascades on account deletion.
Data type: notification queue
Examples: which story was scheduled for which day.
Period: 30 days.
Deletion: nightly cleanup; cascades on account deletion.
Data type: rate-limit counters and negative barcode cache
Period: 2 days / 7 days respectively.
Deletion: hourly cleanup. These records contain no user content.
Data type: Firebase Analytics
Examples: usage events without personal content, pseudonymous identifiers.
Period: up to 2 months (user/event-level data; default setting); aggregate reports longer.
Deletion: turning analytics off in the app stops collection; deletion requests via [email protected].
Data type: Firebase Crashlytics
Examples: stack trace, device model, OS and app version.
Period: 90 days.
Deletion: per Firebase settings; collection can be turned off in the app.
Data type: database backups
Period: up to 30 days (when enabled; to be enabled before the production launch).
Deletion: automatic rotation; a deleted account's data disappears from backups after their retention expires.
Data type: editorial stories and their sources
Examples: stories, facts, sources, image attribution.
Period: as long as needed for the service, quality checks, audit, and publication; they contain no user data.
Deletion: unpublish / takedown.
3. Data export
Export is available in the app: Account → Privacy & Data → Export (up to 5 times per hour). The export returns machine-readable JSON with the account's data: settings, collection, wishlist, article states, audio chain profile, stylus tracker, push tokens, sync log, import jobs.
The export does not include:
- server security logs;
- internal rate-limit records;
- data whose disclosure would harm security or other people's rights;
- third-party processors' data not directly accessible through the app (it can be requested via [email protected]).
Your own photos of records are stored only on the device and are not part of the server export.
4. Account deletion
Deletion is started in the app (Account → Privacy & Data → Delete account) or by a request to [email protected]. The system deletes:
- the authentication account (including e-mail and profile name);
- settings, collection, wishlist, article states, audio chain profile, stylus tracker;
- push tokens;
- import files;
- entitlement records.
5. Exceptions
Some data may be kept longer where necessary to:
- comply with the law;
- prevent fraud and abuse;
- investigate a security incident;
- protect the rights of CrateCore or third parties;
- let backup retention expire.
6. Contact
Questions about retention and deletion: [email protected].