Account deletion
Account deletion for Eclipser, published by Huzk Ltd.
Authoritative plain-text version — that document is the binding one; this page renders the same text for reading.
Controller and product support: Huzk Ltd
Effective date: 2026-08-28
How to request deletion
Open Account → Access or delete account data in the installed extension, choose
Delete, and complete the one-time code sent to the account e-mail address. A verified
request immediately restricts the account and revokes active devices while the evidenced
deletion workflow runs. If the in-product route is inaccessible, use the verified support
channel: <https://eclipser.app/support>. Never send card numbers, security codes, passwords, licence
JWTs, or one-time codes to support.
What the workflow deletes
The local workflow erases the subject's live Eclipser customer, licence, device,
promotion, authentication, Checkout, and related account rows when no scoped legal hold
blocks that step. Appearance settings and site profiles remain in local browser storage
and Chrome Sync, if enabled; clear them separately in the extension or browser. Stripe
and Link hold their own Managed Payments records and accept provider privacy requests
through the [Stripe Privacy Portal](https://privacy.stripe.com/privacy/home).
Eclipser never claims that local erasure deleted provider records.
Completion is withheld until the live-store erasure, applicable Cloudflare backup-ageing
receipt, and required Stripe/Link provider notice are each evidenced. An active legal hold
shows its category, review time, and case-specific end time in the request status.
Retention schedule in this source build
next daily maintenance pass.
15 minutes and is removed by daily maintenance.
30 days in the production contract; completion waits for the applicable ageing proof.
authorization by daily cleanup and the matching R2 prefix lifecycle rule.
Open, failed, or incomplete recovery incidents have no blind calendar expiry; they are
retained until safely sealed, then their 180-day clock starts.
erased-identity anti-resurrection records can be kept for up to 400 days under the
current production contract. Billing-review history is kept for 180 days.
Completed D1 deletion request, step, and event history is retained for exactly 400 days
after completion solely to evidence fulfillment, prevent stale-provider resurrection and
fraud, and resolve disputes. Daily cleanup deletes the whole completed request graph once
its 400-day boundary has passed and no active identity tombstone or time-bounded retention
hold remains. Open requests and active holds are never eligible for terminal-history
cleanup. Huzk Ltd has approved the exceptional rule that an open recovery incident is
kept only until it can be safely sealed; the sealed snapshot is then deleted after 180 days.
Privacy policy: <https://eclipser.app/privacy>
Support: <https://eclipser.app/support>