Eclipser

Account deletion

Account deletion for Eclipser, published by Huzk Ltd.

Authoritative plain-text version — that document is the binding one; this page renders the same text for reading.

Controller and product support: Huzk Ltd

Effective date: 2026-08-28

How to request deletion

Open Account → Access or delete account data in the installed extension, choose

Delete, and complete the one-time code sent to the account e-mail address. A verified

request immediately restricts the account and revokes active devices while the evidenced

deletion workflow runs. If the in-product route is inaccessible, use the verified support

channel: <https://eclipser.app/support>. Never send card numbers, security codes, passwords, licence

JWTs, or one-time codes to support.

What the workflow deletes

The local workflow erases the subject's live Eclipser customer, licence, device,

promotion, authentication, Checkout, and related account rows when no scoped legal hold

blocks that step. Appearance settings and site profiles remain in local browser storage

and Chrome Sync, if enabled; clear them separately in the extension or browser. Stripe

and Link hold their own Managed Payments records and accept provider privacy requests

through the [Stripe Privacy Portal](https://privacy.stripe.com/privacy/home).

Eclipser never claims that local erasure deleted provider records.

Completion is withheld until the live-store erasure, applicable Cloudflare backup-ageing

receipt, and required Stripe/Link provider notice are each evidenced. An active legal hold

shows its category, review time, and case-specific end time in the request status.

Retention schedule in this source build

  • The verification code is usable for 10 minutes; an expired code row is removed by the
  • next daily maintenance pass.

  • A short-lived chunked export bearer, when used before deletion, expires after
  • 15 minutes and is removed by daily maintenance.

  • Cloudflare D1 Time Travel can retain a pre-erasure database state for no more than
  • 30 days in the production contract; completion waits for the applicable ageing proof.

  • The independently verified deletion-journal checkpoint is deleted 180 days after
  • authorization by daily cleanup and the matching R2 prefix lifecycle rule.

  • Admin audit and safely sealed recovery-snapshot evidence are deleted after 180 days.
  • Open, failed, or incomplete recovery incidents have no blind calendar expiry; they are

    retained until safely sealed, then their 180-day clock starts.

  • Minimized Checkout recovery contracts are kept for 30 days. Webhook-integrity and
  • erased-identity anti-resurrection records can be kept for up to 400 days under the

    current production contract. Billing-review history is kept for 180 days.

  • Stripe/Link and other processors apply their own legal and operational schedules.
  • Completed D1 deletion request, step, and event history is retained for exactly 400 days

    after completion solely to evidence fulfillment, prevent stale-provider resurrection and

    fraud, and resolve disputes. Daily cleanup deletes the whole completed request graph once

    its 400-day boundary has passed and no active identity tombstone or time-bounded retention

    hold remains. Open requests and active holds are never eligible for terminal-history

    cleanup. Huzk Ltd has approved the exceptional rule that an open recovery incident is

    kept only until it can be safely sealed; the sealed snapshot is then deleted after 180 days.

    Privacy policy: <https://eclipser.app/privacy>

    Support: <https://eclipser.app/support>

    Adjusts how dark this page is.