Last updated 2026-06-24 · v1.2
Data Retention Policy
1. Purpose
This policy explains how long Lueurly keeps different categories of Lueurly data. It reflects the verified retention schedule in effect on 2026-06-16.
2. Retention Schedule
| Data | Retention |
|---|---|
| Fading Light (burn-after-read) content, including `content_text`, photos, and voice files | Cleared from active server storage no later than 1 hour after the applicable read and expiry condition is satisfied; for multi-recipient messages, content may remain until all relevant recipients satisfy the system's purge condition |
| Contact hashes | Deleted after 90 days without update |
| Keepsake (pact) signing audit location (`gps_lat`, `gps_lng`), only when the Premium audit-location option is enabled | Cleared after 90 days |
| Login attempts | 30 days |
| Audit logs, including IP, user agent, and device fingerprint | 180 days |
| Web access logs, including IP | 14 days |
| Application logs | 30 days |
| Database backups | 30-day rolling backups |
| Account data and remaining content | Kept while the account exists; deleted or anonymized within a reasonable period after account deletion, subject to the limited exceptions described in this policy |
3. Fading Light (Burn-After-Read)
Burn-after-read content is cleared from active server storage no later than 1 hour after the applicable recipient reads it and the configured countdown expires. For multi-recipient messages, content may remain until all relevant recipients have burned, expired, deleted, or otherwise satisfied the system's purge condition. The clearing process removes stored content and media files from active server storage, but message rows, delivery records, technical metadata, logs, and other non-content records may remain under this policy.
Burn-after-read is best-effort. It cannot prevent screenshots, screen recordings, photos of the screen, external recording, copying before deletion, notification previews, recipient-device backups, recipient misconduct, account compromise, or device-level bypasses. Cleared content is not retained long-term and backups roll over within 30 days. Lueurly does not promise immediate, irreversible, forensic, or recipient-device deletion. Data subject to a valid legal hold, court order, safety investigation, abuse report, payment dispute, or legal claim may be preserved to the extent permitted or required by law.
4. Backups and Logs
Database backups are retained on a 30-day rolling basis. Application logs are retained for 30 days. Web access logs are retained for 14 days.
Logs may include IP addresses, user agents, device identifiers, timestamps, and operational events needed for security, abuse prevention, debugging, and legal compliance.
5. Account Deletion
When you delete your account, Lueurly deletes or anonymizes account data and remaining content associated with the account within a reasonable period, subject to the short retention periods above and any legal, subscription, safety, dispute-resolution, abuse-prevention, or audit obligations that require limited retention. Data that must be preserved for a valid legal hold, court order, safety investigation, payment dispute, or legal claim may be retained for as long as reasonably necessary for that purpose.
6. Contact
For retention questions or deletion requests, contact:
The official version and controlling language of this document are governed by Section 27 of the Lueurly Common Terms of Use.