Data retention
How long information stays.
Draft prepared October 4, 2026. This schedule distinguishes what the current code does from proposed launch targets. Proposed periods are not active commitments until reviewed, approved, and implemented.
Review draft. Confirm applicable legal/accounting periods, provider log and backup settings, account-deletion procedure, and the proposed windows below before publication.
| Information | Current implementation | Proposed schedule | Still needed |
|---|---|---|---|
| Browser-saved profile and progress | Saved in local browser storage; no automatic expiry in the app. | Keep until the player signs out where applicable or clears browser site data. | Explain that clearing site data may remove unsynced local progress. |
| Account, profile, entitlements, matches, ratings, results, cosmetics, and linked support/report records | Stored while the account is active. Most rows reference the account with cascading deletion, but there is no self-service deletion control. | Retain while the account is active. After a verified deletion request, remove account-linked production rows within 30 days, except records that must be retained by law. | Build and test an account-deletion runbook that also handles Stripe records, provider logs, and backups; approve the 30-day target. |
| Player reports and support tickets | Private account-linked rows; no age-based cleanup job exists. Account deletion currently cascades them. | For accounts that remain open, delete or anonymize closed tickets/reports 24 months after resolution. Preserve open cases only while needed to resolve or investigate them. | Approve the window and define exceptions for active disputes or safety investigations. |
| Matchmaking request limits | Small per-account/per-operation counters; deleted with the account, with no scheduled expiry while the account remains active. | Delete counters after 30 days without use. | Add a scheduled cleanup and verify it cannot affect active rate limits. |
| Stripe subscription and accounting records | The app stores customer/subscription identifiers and entitlement state. Stripe separately processes checkout and maintains its own billing records. Deleting a Hidden Chamber account does not currently delete the Stripe customer. | Keep only the minimum records required to provide the subscription and meet applicable financial, tax, fraud, and dispute obligations; delete or detach the rest when an account is closed. | Confirm jurisdiction-specific retention with counsel/accounting and implement a Stripe account-closure procedure. |
| Stripe webhook idempotency records | Stores event ID/type, received/processed timestamps, and a minimal related object ID. No scheduled purge exists; these records are not linked to account deletion. | Proposed 90-day maximum, subject to confirming duplicate-event and reconciliation needs. | Add and test a cleanup policy before adopting this window. |
| Hosting, service, and security logs; backups | Retention is configured by the hosting/service providers and is not defined in this repository. | Use the shortest provider-supported period that meets security and recovery needs. | Record the selected Supabase and Vercel plans/settings and their actual log/backup retention periods. |
To ask for access to or deletion of account information, email support@hiddenchamber.app. The current app does not provide a self-service deletion control, and this draft does not promise completion before the proposed procedure is approved and operational.