Back to Portal

Data Retention Schedule

Effective Date: August 11, 2026

In accordance with our commitment to data minimization, BespokeDB enforces strict data retention policies. We do not keep data longer than is absolutely necessary for security, auditing, and the core functionality of the API.

Data Category Data Points Collected Retention Period Action at End of Period
Account Registration Email Address, Google Auth Provider UID Duration of Account Permanently deleted within 14 days of account closure or ban.
API Keys Client ID, Client Secret, API Status Duration of Account Keys are permanently revoked and deleted upon account closure.
Security & Audit Logs IP Address, JWT Token Issuance, Rate Limit Violations, Auth Failures 90 Days Logs are hard-deleted from our databases via automated purge scripts.
Web Dashboard Activity Admin Logins/Logouts, IP Address, Browser User-Agent 30 Days Logs are hard-deleted from our databases.

Exceptions

In the event of an active security investigation, active cyberattack, or formal legal subpoena, the deletion of specific Security and Audit logs may be paused until the investigation has concluded.

Data Deletion Requests (Right to be Forgotten)

Upon user-initiated account deletion, your core account profile and API key are immediately destroyed. However, immutable security logs and web logs containing your email/IP address are strictly bound to their 30-day and 90-day cycles to maintain audit integrity and prevent abuse.