Cancel Cultr — Data Retention & Disposal Policy
1. Purpose & Principles
This policy defines how long Cancel Cultr retains data and how it is disposed of. Cancel Cultr follows data minimization: we collect only what the service requires, retain it only as long as needed, and delete it promptly when it is no longer needed or when the user requests deletion. We do not sell personal information or use it for secondary purposes.
2. Retention Schedule
| Data | Retention | Disposal trigger |
|---|---|---|
| Plaid access token & bank transaction data (limited to streaming-matched charges) | Only while the user holds an active Autopilot (paid) entitlement. | Revoked via Plaid item/remove and purged within 30 days of the entitlement lapsing, the user disconnecting the bank, or account deletion — whichever occurs first. |
| Account & personal information (email, optional phone, tracked shows, subscriptions, notification history) | While the account is active. | Deleted on account deletion or user request, and after 12 months of account inactivity. |
| Device push token & time zone | Until the token becomes invalid or the account is deleted. | Auto-pruned when a delivery reports the token is unregistered; otherwise deleted with the account. |
| Application / operational logs | Short-term, per the hosting provider's log window. | Expire automatically on the provider's rolling schedule. |
3. Data Minimization (bank data)
Cancel Cultr does not store the user's full transaction feed. During synchronization, only transactions that match a known streaming provider are persisted; all other transactions are discarded and never stored. Bank login credentials are never received or stored (Plaid does not expose them to us). No money-movement products are used.
4. Disposal Methods
- Production database: records are permanently deleted (hard delete). Deletion of a user cascades through all related tables via foreign-key constraints, removing subscriptions, tracked shows, notification history, linked accounts, and stored transactions.
- Bank access revocation: the Plaid item is revoked via the Plaid item/remove endpoint, terminating our access to the institution.
- Backups: production runs on Supabase Pro with point-in-time recovery and daily backups. Deleted data is removed from production immediately and expires from encrypted backups within the backup-retention window (approximately 7 days).
5. Disposal Triggers
- User-initiated deletion: in-app account deletion permanently removes the account and all associated data and revokes any Plaid connection.
- Deletion by request: users may request deletion by email; requests are honored promptly.
- Entitlement lapse / bank disconnection: when a paid Autopilot entitlement ends or a user disconnects their bank, the Plaid connection is revoked and stored bank data is purged within 30 days.
- Inactivity: accounts inactive for 12 months are deleted.
6. Encryption & Protection During Retention
All retained data is encrypted in transit (TLS) and at rest (managed AES-256). Plaid access tokens are stored server-side only and are unreachable by client applications (row-level security is enabled on every table with zero client access policies).
7. Scope Statement
Cancel Cultr is a single-operator, early-stage business. This policy documents retention and disposal practices that are genuinely implemented (user-initiated deletion with cascading hard-delete and Plaid revocation are live) together with defined procedures the operator commits to performing (entitlement-lapse purges and inactivity deletion), which are executed on a periodic basis and are being automated as the business scales.