# Eclipser Account Deletion and Retention Schedule **Controller and product support:** Huzk Ltd **Effective date:** 2026-08-10 > **Draft:** This copy is not ready for Chrome Web Store submission until the brand, support details, and permanent privacy URL are complete. ## How to request deletion Open **Account → Access or delete account data** in the installed extension, choose **Delete**, and complete the one-time code sent to the account e-mail address. A verified request immediately restricts the account and revokes active devices while the evidenced deletion workflow runs. If the in-product route is inaccessible, use the verified support channel: . Never send card numbers, security codes, passwords, licence JWTs, or one-time codes to support. ## What the workflow deletes The local workflow erases the subject's live Eclipser customer, licence, device, promotion, authentication, Checkout, and related account rows when no scoped legal hold blocks that step. Appearance settings and site profiles remain in local browser storage and Chrome Sync, if enabled; clear them separately in the extension or browser. Stripe and Link hold their own Managed Payments records and accept provider privacy requests through the [Stripe Privacy Portal](https://privacy.stripe.com/privacy/home). Eclipser never claims that local erasure deleted provider records. Completion is withheld until the live-store erasure, applicable Cloudflare backup-ageing receipt, and required Stripe/Link provider notice are each evidenced. An active legal hold shows its category, review time, and case-specific end time in the request status. ## Retention schedule in this source build - The verification code is usable for 10 minutes; an expired code row is removed by the next daily maintenance pass. - A short-lived chunked export bearer, when used before deletion, expires after 15 minutes and is removed by daily maintenance. - Cloudflare D1 Time Travel can retain a pre-erasure database state for no more than 30 days in the production contract; completion waits for the applicable ageing proof. - The independently verified deletion-journal checkpoint is deleted 180 days after authorization by daily cleanup and the matching R2 prefix lifecycle rule. - Admin audit and safely sealed recovery-snapshot evidence are deleted after 180 days. Open, failed, or incomplete recovery incidents have no blind calendar expiry; they are retained until safely sealed, then their 180-day clock starts. - Minimized Checkout recovery contracts are kept for 30 days. Webhook-integrity and erased-identity anti-resurrection records can be kept for up to 400 days under the current production contract. Billing-review history is kept for 180 days. - Stripe/Link and other processors apply their own legal and operational schedules. The D1 deletion request, step, and event history does not yet have an owner-approved fixed destruction period in this draft. Therefore `retentionSchedulePublished` must stay false, and this page must not be presented as submission-ready, until Huzk Ltd records the legal decision, implements its cleanup, and verifies the permanent public page byte for byte against this tracked source. Privacy policy: Support: