DRAFT — pending attorney review. An attorney has not reviewed this document yet, and it may change before its final version.
Retention and Deletion Policy
Version 0.4.0. In effect since October 3, 2026.
| Version | 0.4.0 |
| Effective date | October 3, 2026 |
| Controller | Osvaldo Rodriguez (an individual) |
| Contact | tripsettled.app@gmail.com |
The short version
- We keep your data only as long as it's needed. Temporary data (sign-in links, security counters) is deleted within hours.
- When you delete your account, we erase your personal data right away, as soon as you confirm.
- What you contributed to shared trips stays without your personal data, as “Former member”, so nothing changes for the group.
- Backups last up to 7 days and technical logs 30 days; after that they disappear on their own.
1. How long we keep each type of data
| Data | How long | What happens next |
|---|---|---|
| Account: email, name, language, password hash, status | While you have an account | Deleted when you confirm your account deletion |
| Google link (your Google account identifier) | While you have an account | Deleted with the account |
| Document acceptance and age confirmation | While you have an account | Deleted with the account |
| Consents and their history | While you have an account | Deleted with the account |
| Incomplete sign-ups (email not verified or terms not accepted) | 7 days from account creation | The whole account is deleted. If you were on the access list, your email stays there so you can try again. |
| Account of someone who says they are under 18 when accepting the terms | Not kept | Deleted immediately |
| Active sessions | Until you sign out or they expire: 30 days without activity, and 90 days at most | They become ended sessions |
| Ended sessions (signed out, expired or revoked) | 30 days after they end, so you can review recent access and so we can investigate security issues | Deleted |
| Sign-in links: magic-link sign-in or email verification | Valid for 15 minutes and usable once | Deleted no later than 24 hours after use or expiry |
| Temporary Google sign-in data | Valid for 10 minutes | Deleted no later than 24 hours after use or expiry |
| Abuse protection counters (computed with a secret key from the IP, the account or the email) | 15-minute or one-day windows | Deleted 24 hours after their window starts |
| Access list for the test phase: emails of people invited to sign up and an optional internal note | Until the person deletes their account or we remove them from the list | The whole entry is deleted. The person can ask us to remove it at any time. |
| Audit log | 12 months. Records of rights requests (export, deletion, profile correction, consent changes, appeals): 24 months | Deleted. If you deleted your account earlier, in the meantime they only keep your internal identifier, without your name or email |
| App technical logs | 30 days | Deleted automatically |
| Performance and error telemetry, without your name, email or IP | 30 days | Deleted automatically |
| Database and file backups | Up to 7 days | Deleted automatically |
| Emails you send us at tripsettled.app@gmail.com and our replies | 12 months after they're resolved; 24 months for rights requests, so we can show how we handled them | We delete them from the mailbox, and they stay in Gmail's trash for up to 30 days. Deleting your account doesn't delete them; if you want them deleted sooner, ask us, except those we must keep as the record of a request. |
| Your data export file | Generated when you ask for it and downloaded right then | We don't keep a copy |
Daily cleanup. An automatic cleanup runs once a day and deletes each item once its period is over. So an item can stay up to one day longer than the period in the table.
Emails at Microsoft. According to Microsoft, Azure Communication Services processes email content at the time of sending and doesn't store it. Microsoft does temporarily keep addresses that bounce permanently, to prevent spam and abuse.
Trip data. When the trip, expense and file features arrive, we will publish their retention periods here. The general rule is already decided: when a trip ends, uploaded files follow this policy; when you delete your account, section 3 applies.
2. How to delete your account
- In My account, choose to delete your account. We show you what will be deleted and what will stay without your personal data.
- To confirm, type your email. For security, if you signed in more than 10 minutes ago, we will ask you to sign in again before deleting.
- When you confirm, in a single step:
- we delete your account, your Google link, your sessions (you're signed out on all your devices), your pending sign-in links, your acceptances and your consents;
- we remove your email from the access list, if it was there;
- we record in the audit log that the account with your internal identifier was deleted.
- Once the deletion is complete, we send you one last email to let you know. After sending it, we don't keep your address.
Deleting your account is never blocked: you can do it even if you have terms pending acceptance. If you want a copy of your data, download it first from My account.
3. What you contributed to shared trips
Once trips exist, when you delete your account:
- your personal data (name, email, preferences, reasons for being unavailable, health restrictions) is deleted;
- what you contributed to shared trips, such as plan items, expenses and payments, stays without your personal data and is shown as “Former member”, so the group's plan and balances don't change;
- your beds, seats and participations are removed, and the trip shows again whatever that leaves uncovered;
- if you owned a trip, we will ask you to transfer it; if you don't, it goes to the longest-standing co-organizer or, if there is none, to the longest-standing member with an account.
4. What remains for a while after deletion
- Backups: up to 7 days. We don't use them to recover individual accounts. If we ever had to restore the service from a backup, we would re-apply the deletions made after that backup's date.
- Technical logs: 30 days.
- Audit log: only your internal identifier, without your name or email, for the period in section 1.
- Telemetry: 30 days, without data that directly identifies you.
5. Exceptions
If a law, an authority or a legal proceeding requires us to keep some data, we will keep only that data, blocked from any other use, for as long as required, and we will tell you unless the law prevents it.
6. Data about people without an account and minors
- An adult without an account's data is kept while they remain on the trip. It is deleted if an organizer removes them or if the person asks us. If they claim their profile when they create an account, it moves to their account.
- A dependent minor's data is kept while they remain on the trip. It is deleted if their responsible adult removes them, or if their parent or guardian asks us.
7. Changes to this policy
We will publish each change with its version and date. If a change lengthens how long we keep your data, we will let you know before it applies.
Change history
| Version | Date | Change |
|---|---|---|
| 0.4.0 | 2026-10-03 | Before taking effect: the controller, the contact email, and how long we keep the emails you send us. |
| 0.3.0 | 2026-10-03 | The automatic cleanup runs once a day (an item can stay up to one extra day); abuse counters per account and with one-day windows. |
| 0.2.0 | 2026-10-03 | Before taking effect: deletion is confirmed by typing your email (no longer an emailed link); immediate deletion when someone says they are under 18; access list details; technical logs and telemetry down to 30 days; clarifies that we don't keep email delivery logs. |
| 0.1.0 | 2026-10-03 | First draft: periods for account data, sessions, sign-in links, security, audit, logs, telemetry and backups. |