LEGAL DOCUMENT
CrateCore — Data Retention & Deletion Policy
Version date: August 7, 2026 (previous: August 6, July 30, and July 17, 2026)
Operator: the individual developer of the CrateCore service
Contact: legal@cratecore.app
1. Purpose
This policy describes how long CrateCore keeps different types of data and what happens on export and account deletion.
The table below describes the maximum set of data of a registered account. As of August 6, 2026 the data of an anonymous session never leaves the device: before registration feed personalization is unavailable (the feed is the general one), and app settings and read marks are kept only on the device and never sent to our servers. Accordingly, an anonymous session has no settings, marks, collection, wishlist, import files, or push tokens on our servers — there is nothing there to keep or to delete. Records left on our servers by anonymous sessions under the previous rules (including those created before July 30, 2026) were deleted on August 6, 2026 together with those earlier sessions. The only thing a technical anonymous session leaves on the server is its own identifier — see the note in section 2.
2. Retention periods
Data type: account (authentication)
Examples: user identifier, e-mail when you register, profile name.
Period: while the account exists.
Deletion: on account deletion.
Note: if a technical anonymous session is opened to fetch the stories, all that remains of it on the server is the session identifier itself — a random number with none of your data (plus a service record of its opening in the authentication log). Period: as long as the app on this device needs the session. Deletion: the "Delete this session's data" button ends the session and deletes its identifier from the server; if you simply remove the app from the device, the unused number stays with us — with none of your data attached to it.
Data type: data before registration (anonymous session)
Examples: the app's own settings (theme, interface language), marks for read and hidden stories, the local story cache.
Where: on the device only — never sent to our servers.
Period: while the app's data exists on the device.
Deletion: with the "Delete this session's data" button in the app, by clearing the app's data, or by removing the app. No server copy exists; recovery is not possible.
Data type: settings (registered account only)
Examples: genres/eras, drop topics, content language, notification time, timezone, quiet sound.
Period: while the account exists.
Deletion: cascades on account deletion.
Data type: collection (registered account only)
Examples: release, grading, price, purchase date, notes.
Period: while the account exists.
Deletion: cascades on account deletion; individual records removed from the collection are marked deleted in the sync log until it is purged.
Data type: wishlist (registered account only)
Period: while the account exists.
Deletion: cascades on account deletion.
Data type: article states (registered account only)
Examples: read, saved, hidden from the feed, liked.
Period: while the account exists.
Deletion: cascades on account deletion.
Note: before registration, read and hidden marks stay on the device and never reach the server, while "saved" and "liked" are unavailable.
Data type: audio chain profile
Period: while the account exists.
Deletion: cascades on account deletion.
Data type: stylus tracker (the list of styluses, hours of use, photos)
Where: on the device only — never sent to our servers.
Period: while the app's data exists on the device.
Deletion: on sign-out, when another person signs in on the device, on account deletion, or when the app's data is cleared. No server copy exists; recovery after deletion is not possible.
Data type: push tokens (notifications can only be enabled in a registered account)
Period: while the token is valid or while the account exists.
Deletion: on sign-out, on account deletion, on disabling notifications, or on server cleanup of an invalid token.
Data type: import CSV (file; registered account only)
Period: until the import completes; a safety sweep runs no later than 24 hours.
Deletion: automatic after the import and on account deletion.
Data type: import log (job and rows; registered account only)
Period: 90 days.
Deletion: nightly cleanup; cascades on account deletion.
Data type: request and security log
Examples: request type, result, response time, rate-limit/attestation events.
Period: 30 days.
Deletion: nightly cleanup.
Data type: sync log (mutations)
Period: 90 days.
Deletion: nightly cleanup; cascades on account deletion.
Data type: notification queue
Examples: which story was scheduled for which day.
Period: 30 days.
Deletion: nightly cleanup; cascades on account deletion.
Data type: rate-limit counters and negative barcode cache
Period: 2 days / 7 days respectively.
Deletion: hourly cleanup. These records contain no user content.
Data type: Firebase Analytics
Examples: usage events without personal content, pseudonymous identifiers.
Period: up to 2 months (user/event-level data; default setting); aggregate reports longer.
Deletion: turning analytics off in the app stops collection; deletion requests via legal@cratecore.app.
Data type: Firebase Crashlytics
Examples: stack trace, device model, OS and app version.
Period: 90 days.
Deletion: per Firebase settings; collection can be turned off in the app.
Data type: analytics of the cratecore.app website (the website, not the app)
Examples: Google Analytics 4 — page views and the _ga / _ga_… cookies (only if the visitor pressed "Accept" in the consent banner); Cloudflare Web Analytics — anonymous page views without cookies.
Period: Google Analytics — cookies up to 2 years in the visitor's browser, user- and event-level data per the property's setting and no longer than 14 months (the GA4 limit), aggregated reports longer; Cloudflare Web Analytics — per Cloudflare's periods, with no visitor identifiers in it.
Deletion: withdraw consent and delete the cookies as described in the Cookie Policy (https://cratecore.app/cookies/en/); this data concerns no account and is not part of the account export.
Data type: database backups
Period: up to 30 days (when enabled; to be enabled before the production launch).
Deletion: automatic rotation; a deleted account's data disappears from backups after their retention expires.
Data type: editorial stories and their sources
Examples: stories, facts, sources, image attribution.
Period: as long as needed for the service, quality checks, audit, and publication; they contain no user data.
Deletion: unpublish / takedown.
3. Data export
Export is available in the app: Account → Privacy & Data → Export (up to 5 times per hour). The export returns machine-readable JSON with the account's data: settings, collection, wishlist, article states, audio chain profile, push tokens, sync log, import jobs. It returns server data, so it works after free registration: before registration there is no server data — everything there is sits on your device.
The stylus tracker is not part of the export: its data is stored only on the device and is never sent to our servers.
The export does not include:
- server security logs;
- internal rate-limit records;
- data whose disclosure would harm security or other people's rights;
- third-party processors' data not directly accessible through the app (it can be requested via legal@cratecore.app).
Your own photos of records are stored only on the device and are not part of the server export.
4. Account deletion
Deletion is started in the app (Account → Privacy & Data → "Delete my data and account") or by a request to legal@cratecore.app. The system deletes whatever exists for you:
- the authentication account (including e-mail and profile name);
- settings, collection, wishlist, article states, audio chain profile;
- the app's local data on the device, including the stylus tracker and your own photos (they have no server copies);
- push tokens;
- import files;
- entitlement records.
Before registration the same button in the app is called "Delete this session's data": it wipes the app's local data on this device (settings, read marks, the story cache) and ends the technical session if one was opened — together with its identifier on the server. An anonymous session holds none of your data on our servers — there is nothing left to delete there, and such deletion is not requested by e-mail.
5. Exceptions
Some data may be kept longer where necessary to:
- comply with the law;
- prevent fraud and abuse;
- investigate a security incident;
- protect the rights of CrateCore or third parties;
- let backup retention expire.
6. Contact
Questions about retention and deletion: legal@cratecore.app.
