Data Retention Schedule

How long we keep different types of data and why.

Updated May 5, 2026 Version 1.0

This Data Retention Schedule provides detailed information about how long we retain different types of data and the legal basis for each retention period.

Related policies: Privacy Policy ยท Account Deletion Policy

1. Overview

We retain different types of data for different periods based on legal requirements, operational needs, and security considerations. This schedule provides transparency about our data retention practices.

2. Data Retention Schedule

Data Type Retention Period Legal Basis
Account data (username, role, settings) Until account deletion or termination Contract performance, legitimate interest
Email address Until account deletion (hash retained indefinitely for security) Contract performance, legitimate interest (security)
Password hash Until account deletion or password change Legitimate interest (security)
AI conversation logs 90 days, then auto-purged Legitimate interest (safety, moderation)
Login history 90 days, then auto-deleted Legitimate interest (security)
Strike records 30 days after last strike (retained up to 7 years for terminated accounts) Legitimate interest (security, ban prevention)
Payment sessions (completed) 7 years (for tax and accounting records), then deleted Legal obligation (tax, accounting)
Payment sessions (failed/expired) 7 days Legitimate interest (fraud prevention)
Payment nonces Auto-deleted after expiry (15 minutes) Legitimate interest (security)
Webhook events (processed) 90 days Legitimate interest (troubleshooting)
Page views and analytics 36 months, then aggregated and anonymized Legitimate interest (service improvement)
Device fingerprints Duration of punishment + 90 days Legitimate interest (ban evasion prevention)
Yaps chat messages 24 months after last activity, then anonymized Legitimate interest (community record)
Smail messages Until account deletion, or 12 months after last activity Contract performance
Rate limit records Automatically cleaned Legitimate interest (security)
Session data Until browser session ends Legitimate interest (security)
Guest account IP hashes 30 days (for rate limiting) Legitimate interest (security)
Minor consent records 3 years after minor reaches age 18 Legal obligation (parental consent record-keeping)
Profile pictures Until account deletion (declined images retained in admin records) Contract performance, legitimate interest (moderation)
Feedback submissions 24 months, then anonymized Legitimate interest (service improvement)
Report submissions 90 days after resolution Legitimate interest (safety, moderation)

4. Exceptions

4.1 Extended Retention for Security

We may extend retention periods for security reasons, such as ongoing investigations or suspected fraud.

4.2 Legal Holds

If we receive a legal hold (e.g., subpoena, court order), we will retain relevant data until the hold is lifted, regardless of the standard retention period.

4.3 Early Deletion

You may request early deletion of certain data by contacting us. We will evaluate your request and comply where legally possible.

5. Contact

For questions about our data retention practices or to request data deletion, contact us:

Email: support@thespencerwebsite.com

Subject line: "Data Retention Inquiry"