Policy version 1.8

Data Retention Schedule

How long each kind of information is kept, and what happens when that time is up.


Deletion runs automatically on this schedule. It is not something we do only when asked.

WHEN REGISTRATION IS NEVER COMPLETED

Incomplete verification codes and registration grants expire within minutes and are removed no later than 30 days. These are temporary authentication records, not completed accounts. Completed accounts, including accounts created by staff or migrated from the previous service, are not classified as unverified solely because no email-verification timestamp exists.

WHILE YOU PRACTICE

Live presence in a room        current state in the database, removed within
                              5 minutes after the last heartbeat
Connection heartbeats          latest time only; no event-by-event history

YOUR PRACTICE

Detailed player events         not stored as a second-by-second history
Practice counts and summaries  kept indefinitely, including what you practiced,
                               how many times, durations, dates and timestamps;
                               no deletion or detachment because of inactivity
Temporary playback diagnostics removed after 7 days for closed sessions;
                               active or resumable sessions are preserved
Private reflections            until you delete them, or you delete your account

WHAT YOU SEND

Your correspondence/questions  30 days, unless you delete them sooner
Room chat and emoji messages   permanently deleted after 24 hours
Sri Swamiji's messages/media   permanently deleted after 30 days, including
                               recordings, translations and read receipts
Call history                   permanently deleted 14 days after the call ends;
                               active calls are preserved
Moderation records             180 days; unresolved reports remain until handled

OPERATIONS

Notification and event records 30 days
Delivery and AI usage logs     30 days
Archived background-job data   7 days after archival (terminal jobs archive after
                               one hour); pending/active work follows its lifecycle
Expired OAuth/sign-in grants   removed after expiry
Retired push endpoints         30 days after retirement
Historical security records    180 days
Active session credentials     until sign-out, revocation or session expiry
Network address hashes         30 days, then cleared from the record entirely
Record of your consent choices for as long as you have an account, and a short
                               period afterwards so we can show what was agreed

Accounts, profile information, configuration, content metadata and practice history have no age-based expiry. Your offering ledger and practice summaries remain associated with your account until explicit account deletion. Routine cleanup never changes practice counts, media references, dates or timestamps.

Cleanup runs every minute in bounded batches; a backlog or service outage can delay physical deletion. Expired chat is excluded from room reads immediately. Server logs have separate finite retention: 30 days in CloudWatch, and bounded rotation for local container logs. Backups expire under the host backup policy; restores must run retention cleanup before serving traffic.

WHEN YOU DELETE YOUR ACCOUNT

Removed: your reflections, questions, comments, attendance, sittings and profile — everything we hold that is about you.

Your offerings are not removed, and they are no longer yours: the count of practice you offered stays part of the sangha's shared total, linked to no name and to no account. It cannot be traced back to you, and it is not taken away from the sangha either.

Kept: a minimal note that a deletion was requested and carried out, no longer linked to your name or email; and security records for the period above, with your identity removed from them. We do not keep anything you wrote.