Data Retention & Deletion Schedule
Keep what is needed. Delete what is not.
Effective August 25, 2026 · Version 2026-08-25
This schedule explains the normal retention periods for Publish Your Profile. “Deletion” means removal from active application use; restricted safety, audit, billing, provider, legal-hold, and backup copies can follow a different schedule described below.
1. Current retention schedule
Account, profiles, media, links, and consent
Kept while the account or item is active. Deactivation hides account access or publication but is not deletion. Permanent account or individual-profile deletion removes eligible active records and queues managed media for deletion.
Sessions and one-time authentication challenges
Sessions normally expire within 30 days. Completed, failed, or expired signup, provisioning, password-recovery, and account-contact-change challenge records are removed within 30 days; secret values expire much sooner and are cleared when the challenge expires.
Age checks and incomplete provider signup
The date of birth is used only during the eligibility request and is not retained. A successful check or administrator adult attestation retains only the applicable adult-eligibility result, confirmation time, and limited setup-method evidence in the account. A non-identifying email-signup receipt containing a one-way hash of a random nonce, status, and timestamps is removed normally within one day. Google or enterprise sign-in creates a restricted pending account before the age check; a fresh ineligible record is deleted immediately, while an abandoned record expires after 24 hours and is removed on restart or during scheduled maintenance. A non-identifying denial cookie expires after 24 hours.
Connections, messages, and call records
Connections and encrypted messages remain while the associated profiles/accounts exist; disconnecting does not itself erase the earlier conversation. Closed call-session and encrypted WebRTC signaling records are normally removed after 30 days.
Profile and Web Profile analytics
First-party visit, share, contact-save, and link-click records are kept for up to 24 months for reporting, then deleted or reduced to a non-identifying aggregate. Deleting the associated profile removes its active analytics sooner.
Support requests
Support correspondence is normally kept for up to 24 months after the last correspondence so follow-up issues can be understood. A security, billing, safety, or legal matter may follow the longer relevant period below. This schedule also applies to the support mailbox operated outside the application.
Safety reports and moderation records
Open cases remain through review and appeal. Closed cases, encrypted report details, decisions, and related safety evidence are normally kept for up to 24 months after closure, then deleted or de-identified unless continued retention is needed to prevent abuse or meet a legal obligation.
Security and audit records
Application audit events are normally kept for up to 24 months. Short-lived operational logs are normally kept for 30 days. A record tied to an active investigation, repeated abuse, dispute, or legal hold may remain longer with restricted access.
Billing, tax, revenue, and account-lifecycle records
Detailed online billing history remains available while the account is active. Minimized transaction, tax, revenue, chargeback, refund, and account-deactivation/deletion records may be kept for up to seven years where needed for accounting, fraud, dispute, and legal obligations. Administrative credits and offline arrangements may be included in operator revenue summaries without appearing as a user-paid online order.
Backups and provider copies
Application database and managed-media backups must use an approved rolling lifecycle of no more than 30 days. Deleted data may remain inaccessible in a backup until that backup expires; backups are not used as an indefinite archive. A restored backup must be reconciled with completed deletion records before normal use. Payment, email, storage, and identity providers apply their own legally permitted retention.
2. Deactivation is reversible
Deactivating an account prevents normal account use and public availability but retains account data so the owner can request reactivation. Retention periods continue during deactivation. A user who wants data removed must choose permanent deletion instead.
3. Permanent account deletion
The signed-in deletion flow confirms the account identity, removes eligible database records, invalidates sessions, and atomically queues managed media deletion and closure of pending Stripe checkouts or active subscriptions. Provider cleanup is retried if it cannot finish immediately. A failed database transaction leaves the account intact instead of performing a partial application-data deletion.
4. Exceptions and minimization
Fraud prevention, payment disputes, safety investigations, court orders, legal claims, tax obligations, and preservation requirements can extend a period. Access is restricted and the record is deleted or de-identified when the exception ends. Public copies saved by visitors and information sent to a linked third-party website cannot be recalled by this service.
5. Ask about or request deletion
Use the signed-in account controls for export, individual-profile deletion, deactivation, or permanent account deletion. Questions and verified requests may be sent to support@publishyourprofile.com. Read the Privacy Policy for other privacy choices.
