Preview build. Highlighted items still need values in config.json. Do not publish.

CurioCoreFlowbase and SportsFlow legal

Data Retention Policy and Schedule

Flowbase and SportsFlow · Version 1.0 · Effective {EFFECTIVE_DATE} · Owner: {PRIVACY_OFFICER} · Review: annually

1. Purpose and Scope

This policy sets how long CurioCore keeps personal information in Flowbase and SportsFlow, what starts each period, and how information is disposed of. It covers production systems, backups, logs and service providers acting for us. It applies data minimization and storage limitation under the laws described in our Privacy Policy.

2. Definitions

3. Principles

3.1 We keep personal information only as long as needed for the purpose it was collected for, or as the law requires.

3.2 Unless the schedule says otherwise, personal information is deleted within 90 days after Account Closure.

3.3 Users can delete individual items, such as a message, a result they submitted, a FlowCoach conversation or a device connection, at any time. Deleted items leave production within 30 days.

3.4 Where a longer period is required by law or for legal claims, it applies only to the minimum data needed.

4. Schedule

Ref Record Retention Trigger Disposition Reason
A‑01 Account and profile Life of account + 90 days Account Closure Deletion Service delivery
A‑02 Guardian approval record 3 years Minor's Account Closure Deletion Proof of consent
T‑01 Training logs and personal erg results Life of account + 90 days Account Closure Deletion Service delivery
T‑02 Ranking and league entries Life of account + 90 days Account Closure Deletion or de-identification Ranking integrity
T‑03 Race results published by organizers or clubs Indefinite, as the historical record Publication Retained. Display name adjustable; removed on valid legal request Public sporting record
T‑04 Race schedules 2 years Event date Deletion Service delivery
W‑01 Wellbeing raw answers, adult Life of account + 90 days Account Closure Deletion Service delivery
W‑02 Wellbeing raw answers, under 18 Until age 18, or 30 days after Account Closure, whichever first 18th birthday or Account Closure Deletion Minimization for minors
W‑03 Scores, trends, readiness, load tolerance Life of account + 90 days Account Closure Deletion Service delivery
W‑04 Wearable data Life of connection or account + 90 days Disconnection or Account Closure Deletion Service delivery
W‑05 Sharing settings and pod membership Life of account + 90 days Account Closure Deletion Service delivery
W‑06 De-identified questionnaire data While needed for reliability work De-identification Deletion when no longer needed Questionnaire validation
C‑01 Messages and attachments Life of sender's account + 90 days Sender's Account Closure Deletion Service delivery
C‑02 FlowCoach conversations Life of account + 90 days, or until deleted Account Closure Deletion Service delivery
C‑03 AI provider request data Not kept by us. Provider: as limited by contract Request Provider deletion Contract
C‑04 Reels and uploaded media Life of account + 90 days, or until deleted Account Closure Deletion Service delivery
C‑05 Course progress and certificates Life of account + 90 days Account Closure Deletion; public page removed at closure Service delivery
K‑01 Boat reservations and event sign-ups 2 years Reservation or event date Deletion Club operations
K‑02 Boat damage and safety reports 3 years Report date Deletion Club safety, claims
P‑01 Subscription and purchase records 7 years Transaction Deletion Tax and accounting law
P‑02 Donation and fundraising records 7 years Transaction Deletion Tax, charitable solicitation law
S‑01 Safeguarding records (threshold events) Club policy. Default: until athlete is 25 or 7 years, whichever is later Event Deletion by club; our copy deleted 90 days after export to club Duty of care
S‑02 Abuse and misconduct reports Until the subject is 25 or 7 years, whichever is later Report Deletion Safeguarding, legal claims
S‑03 Content moderation decisions and appeals 2 years Decision Deletion Legal compliance
L‑01 Privacy request records 24 months Request closure Deletion Regulatory record-keeping
L‑02 Security and access logs 12 months Log creation Deletion Security investigations
L‑03 Product analytics 24 months Event Deletion Service improvement
B‑01 Backups 35 days rolling Backup creation Overwrite Disaster recovery

5. Disposition

5.1 Method. Automated jobs remove records from databases and storage. Hosting providers dispose of media under NIST SP 800-88 or equivalent.

5.2 Service providers. Providers delete our data on instruction or at contract end. When a user deletes consumer health data, we instruct providers to delete it too.

5.3 Backups. Deleted data expires from backups within 35 days. If a backup is restored, deletion jobs run again before the system returns to service.

5.4 Inactive accounts. Accounts with no sign-in for 24 months and no active subscription are closed after two email notices at least 30 days apart.

5.5 Verification. Deletion jobs are logged without personal data and reviewed quarterly.

When we reasonably expect litigation, an investigation or a regulatory inquiry, the privacy officer may suspend deletion of relevant records. Holds are documented, limited to what is relevant, and lifted when no longer needed.

7. Roles

Role Responsibility
Privacy officer Owns this policy; approves exceptions and legal holds
Engineering Builds and monitors deletion jobs; confirms each release matches this schedule
Clubs Keep and dispose of safeguarding, reservation and damage records they export, under their own policies

8. Review

Reviewed at least annually and whenever a new data type, feature or legal requirement is introduced.