← Mahanu

Retention & Deletion Policy

Pre-launch draft · not effective. The effective version must be reconciled with implemented databases, backups, payment records, processors, and every supported jurisdiction. It is the canonical retention source referenced by the Privacy Notice and Terms.

1. Principles

We keep personal data and project data only for as long as necessary to operate the service, honour a member’s choices, secure the service, resolve a dispute, and meet legal obligations. Deletion from Mahanu cannot erase material another authorised project member already copied or published elsewhere.

The final schedule below must be implemented as a tested deletion job, including backups and processors. A legal hold, security investigation, fraud prevention, or a documented legal obligation may require a narrowly scoped extension; we record the reason and release the hold when it no longer applies.

2. Proposed operational schedule

Record Proposed maximum Deletion action
One-time-password code and verification attempts expiry plus 24 hours automatically purge
Revoked, expired, or logged-out session token hashes 30 days automatically purge
Rate-limit and routine security logs 30 days, unless incident-related automatically purge or aggregate
Active account, membership, and project-permission records while the account/project remains active delete or anonymise after the account/project process below
Project content and assets until an authorised owner deletes them or the project/account is closed remove from active storage; expire from backups on their documented cycle
Conduct-bot evaluation of conduct surfaces not retained the bot evaluates content in place and stores no copy of unflagged content
In-project conduct-bot flags [conduct-flag retention period] after resolution expire within the project; removed with the project
Serious-category escalation material held by Mahanu the assessment window plus any legally required reporting/preservation period purge the flagged material; the minimised decision record follows the enforcement-records row below
Account-deletion request 30-day recovery window close access, then delete/anonymise eligible account records within 30 further days
Reports, appeals, consent/vouch, conduct-bot escalation, and enforcement records 3 years after closure delete or anonymise unless a longer legal/safety hold applies
Billing and tax records the legally required period for the transaction isolate and delete when that period ends
Encrypted backup copies [backup retention period] cryptographically or operationally expire on the same documented cycle

The backup-retention period must be filled in only after restore drills demonstrate that it is accurate. The account-deletion flow must explain which shared-project material remains with other members and which legal/billing records cannot be immediately erased.

3. Requests and verification

Use [email protected] or [deletion request URL] to request account deletion or exercise another applicable privacy right. We verify identity and authority proportionately; a guardian makes a request for a supervised account. We confirm completion or explain any retained category and the reason.

Project owners may remove a member’s access, but cannot erase the member’s independent account or copies the member lawfully received. Removing a member from an encrypted project rotates future access; it cannot unshare history already copied by that person.