In accordance with our commitment to data minimization, BespokeDB enforces strict data retention policies. We do not keep data longer than is absolutely necessary for security, auditing, and the core functionality of the API.
| Data Category | Data Points Collected | Retention Period | Action at End of Period |
|---|---|---|---|
| Account Registration | Email Address, Google Auth Provider UID | Duration of Account | Permanently deleted within 14 days of account closure or ban. |
| API Keys | Client ID, Client Secret, API Status | Duration of Account | Keys are permanently revoked and deleted upon account closure. |
| Security & Audit Logs | IP Address, JWT Token Issuance, Rate Limit Violations, Auth Failures | 90 Days | Logs are hard-deleted from our databases via automated purge scripts. |
| Web Dashboard Activity | Admin Logins/Logouts, IP Address, Browser User-Agent | 30 Days | Logs are hard-deleted from our databases. |
In the event of an active security investigation, active cyberattack, or formal legal subpoena, the deletion of specific Security and Audit logs may be paused until the investigation has concluded.
Upon user-initiated account deletion, your core account profile and API key are immediately destroyed. However, immutable security logs and web logs containing your email/IP address are strictly bound to their 30-day and 90-day cycles to maintain audit integrity and prevent abuse.