Policies / Data Retention
Data Retention
Draft for legal review · updated 23 September 2026 · not yet effective
This schedule distinguishes retention enforced in code from intended cleanup that has not yet been implemented or verified. It must not be read as a claim that every record is removed after a fixed number of days. See Privacy Policy.
| Data | Present behavior or limitation |
|---|---|
| Account and profile, including phone or email sign-in details | Kept while the account is active. The in-app deletion screen records a request; it does not erase the account. Creator requests require staff review before fulfillment. |
| One-time sign-in challenges | Codes are stored as hashes and expire; routine maintenance removes expired challenges. |
| SMS delivery jobs | The readable message body is scrubbed after sending or terminal failure. Phone number and delivery metadata remain in job rows; the proposed 30-day purge is not yet implemented. |
| Sessions | Tokens are stored as hashes; revoked and expired sessions are cleaned up. Regular viewer and creator sessions may remain valid until revocation; staff sessions follow separate expiry. |
| Watch progress, likes, dislikes, saves and channel blocks | Kept until the viewer changes or clears the item, subject to the available controls. Account-wide erasure is not yet complete. Following is not a current feature. |
| Recommendation and playback events | Kept for analytics and recommendations. A proposed 13-month anonymisation or deletion rule has not yet been implemented. |
| Ad delivery and interaction records | Used for campaign totals, caps and diagnostics. Some short-lived session records are cleaned up; a general 13-month purge is not yet implemented. |
| Reports, moderation records and staff audit logs | Kept for review, safety and accountability. Proposed fixed periods have not yet been enforced. |
| Uploads, renditions, artwork and live recordings | Kept while the content is available or needed for processing, with removal subject to review and storage cleanup. Replay creation is not guaranteed for every live event. |
| Database backups and provider logs | Retention must be verified against the live host, backup jobs, Bunny and email/SMS provider terms before a fixed period is promised. |
| Local downloads, cache, searches and drafts | These can remain on a device after sign-out. Use available delete controls or uninstall the app to remove local app data. |
Account and content removal
You can request account deletion in the app or at info@24frames.co. An open in-app request may be cancelled during its seven-day change-of-mind period. Creator-account requests require staff review of the account and uploaded content, but review is not deletion. The erasure process, session revocation, media cleanup, backup treatment and lawful retention exceptions still need implementation and verification. See Delete Your Account.
Published-title removal is a separate moderated request. Staff may need to retain limited records for a documented legal, safety or dispute purpose. We will not present a requested or reviewed deletion as completed erasure. A final, enforceable schedule and data-request response target require legal and operational sign-off before this draft is published.