Introduction
Under GDPR Article 5(1)(e), personal data must not be kept longer than necessary for the purpose it was collected. This policy documents exactly how long we retain each category of data and how it is deleted.
Core Principles
Retention Schedule
Account Credentials
Description: Email address, phone number used for authentication
Profile Information
Description: Display name, avatar, timezone, currency preference
Warranties
Description: Product name, brand, purchase/expiry dates, price, serial number
Vault Documents
Description: Document titles, tags, OCR text, metadata
Attachment Files
Description: Uploaded warranty receipts, document images and PDFs in cloud storage
Reminders
Description: Reminder titles, due dates, notification settings
Push Notification Token
Description: Device push token for delivering warranty and reminder alerts
Consent Records
Description: Record of what you consented to, when, and under which policy version
Audit Logs
Description: Log of login events, data changes, exports, and consent changes
Crash Reports (Sentry)
Description: Anonymous error reports with scrubbed PII (only if analytics consent granted)
AI Extraction Logs
Description: Metadata about AI scan events (document type, engine used — no image content)
Locations
Description: Named physical locations/addresses for storing items (e.g., "Home Kitchen")
Account Deletion Process
- Request Submitted: You request deletion in Settings → Privacy Center → Delete Account.
- Immediate Actions: All active sessions revoked; account marked as deletion pending; confirmation email sent.
- 30-Day Grace Period: You can cancel the deletion within 30 days by returning to the Privacy Center.
- Data Erasure: After 30 days, all storage files deleted, personal data anonymized, auth account removed.
- Completion: Confirmation email sent; only consent records retained for legal compliance (no PII).
Questions about data retention? Contact our privacy team at privacy@checkmywarranty.app.
