Retention & Deletion Policy
Pre-launch draft · not effective. The effective version must be reconciled with implemented databases, backups, payment records, processors, and every supported jurisdiction. It is the canonical retention source referenced by the Privacy Notice and Terms.
1. Principles
We keep personal data and project data only for as long as necessary to operate the service, honour a member’s choices, secure the service, resolve a dispute, and meet legal obligations. Deletion from Mahanu cannot erase material another authorised project member already copied or published elsewhere.
The final schedule below must be implemented as a tested deletion job, including backups and processors. A legal hold, security investigation, fraud prevention, or a documented legal obligation may require a narrowly scoped extension; we record the reason and release the hold when it no longer applies.
2. Proposed operational schedule
| Record | Proposed maximum | Deletion action |
|---|---|---|
| One-time-password code and verification attempts | expiry plus 24 hours | automatically purge |
| Revoked, expired, or logged-out session token hashes | 30 days | automatically purge |
| Rate-limit and routine security logs | 30 days, unless incident-related | automatically purge or aggregate |
| Active account, membership, and project-permission records | while the account/project remains active | delete or anonymise after the account/project process below |
| Project content and assets | until an authorised owner deletes them or the project/account is closed | remove from active storage; expire from backups on their documented cycle |
| Conduct-bot evaluation of conduct surfaces | not retained | the bot evaluates content in place and stores no copy of unflagged content |
| In-project conduct-bot flags | [conduct-flag retention period] after resolution | expire within the project; removed with the project |
| Serious-category escalation material held by Mahanu | the assessment window plus any legally required reporting/preservation period | purge the flagged material; the minimised decision record follows the enforcement-records row below |
| Account-deletion request | 30-day recovery window | close access, then delete/anonymise eligible account records within 30 further days |
| Reports, appeals, consent/vouch, conduct-bot escalation, and enforcement records | 3 years after closure | delete or anonymise unless a longer legal/safety hold applies |
| Billing and tax records | the legally required period for the transaction | isolate and delete when that period ends |
| Encrypted backup copies | [backup retention period] | cryptographically or operationally expire on the same documented cycle |
The backup-retention period must be filled in only after restore drills demonstrate that it is accurate. The account-deletion flow must explain which shared-project material remains with other members and which legal/billing records cannot be immediately erased.
3. Requests and verification
Use [email protected] or [deletion request URL] to request account deletion or exercise another applicable privacy right. We verify identity and authority proportionately; a guardian makes a request for a supervised account. We confirm completion or explain any retained category and the reason.
Project owners may remove a member’s access, but cannot erase the member’s independent account or copies the member lawfully received. Removing a member from an encrypted project rotates future access; it cannot unshare history already copied by that person.
Mahanu