⚠️ DRAFT — This schedule requires review by a UK-qualified data protection solicitor or your appointed DPO before launch. Bracketed [PLACEHOLDERS] must be filled in before the Platform goes live.

Data Retention Schedule

Last updated: April 2026 · Version: 1.0 (DRAFT) · Jurisdiction: United Kingdom & European Union

This Data Retention Schedule is the reference document that sits underneath our Privacy Policy. It sets out, for each category of personal data we process, how long we retain it, the lawful basis, and the trigger for deletion.

It exists to satisfy:

  • UK GDPR Article 5(1)(e) — personal data must be kept for no longer than is necessary for the purposes for which it is processed ("storage limitation");
  • UK GDPR Article 30 — the obligation to maintain a record of processing activities (ROPA);
  • ICO guidance on retention schedules published at ico.org.uk;
  • Online Safety Act 2023 record-keeping requirements for age-assurance and illegal-content handling;
  • HMRC and Companies Act 2006 record-keeping for financial transactions.

Where statute imposes a minimum retention period that is longer than our operational need, we retain for the statutory minimum. Where statute imposes a maximum that is shorter than our operational need, we retain only for the statutory maximum.


1. How this schedule works

For every category listed below we record:

  • What it is — the data category.
  • Where it lives — the system(s) that hold it.
  • Retention period — how long we keep it.
  • Trigger for deletion — what event starts the clock.
  • Legal basis — Article 6 (and Article 9 where applicable) grounds.
  • Deletion method — how we actually erase it.

"Retention" means live, queryable storage. We also run backups on a rolling 35-day cycle. When a record is deleted from live storage, it is removed from backups no later than 35 days later — we do not restore a deleted record from a backup except in an emergency authorised by an authenticated data subject or a court order.


2. Account and profile data

| Category | Where | Retention | Trigger | Lawful basis | |---|---|---|---|---| | Email, hashed password, username, account settings | Supabase (PostgreSQL, EU region) | Life of account + 30 days after deletion request (grace period for reactivation and fraud review) | User requests deletion, OR account inactive for 24 months | Art. 6(1)(b) contract | | Display name, bio, pronouns, orientation self-labels | Supabase | Same as above | Same | Art. 6(1)(b) contract + Art. 9(2)(a) explicit consent for special-category inferences | | Relationship status / configuration | Supabase | Same as above | Same | Art. 6(1)(b) + Art. 9(2)(a) | | Location (city/region only — no persisted GPS) | Supabase | Same as above | Same | Art. 6(1)(b) | | Blocked-user lists and hotlist | Supabase | Same as above | Same | Art. 6(1)(f) legitimate interests (member safety) |

Deletion method: hard-delete from PostgreSQL; cascading deletion triggers remove dependent records. Verified by automated post-deletion audit query running 24h after deletion.


3. Media (photos and videos)

| Category | Where | Retention | Trigger | Lawful basis | |---|---|---|---|---| | Profile photos (original + derivatives) | Cloudflare R2 — bucket profile-photos | Life of account + 30 days | User deletes image / user deletes account | Art. 6(1)(b) + Art. 9(2)(a) where image is intimate | | Quick Post photos | Cloudflare R2 — bucket profile-photos | Permanent while account is active (note: Quick Post status/looking-for/event-shortcut expire by type — see Privacy Policy §7; photo posts persist) | Same as above | Same | | Profile videos (original) | Cloudflare R2 — bucket profile-videos (default) | Life of account + 30 days | Same | Same | | Messaging media (chat attachments, ephemeral views) | Cloudflare R2 — messaging bucket | 24 hours for ephemeral media; duration of conversation + 2 years for standard media | Auto-expiry / user deletes / account deletion | Art. 6(1)(b) | | Blurhash thumbnails + image-processing derivatives | Cloudflare R2 | Same as parent media | Same | Same |

Deletion method: R2 DELETE operations with bucket-level lifecycle confirmation. Files on replica regions are purged within 24 hours. Backblaze B2 video replicas (if enabled) are purged on the same cadence.


4. Messaging

| Category | Where | Retention | Trigger | Lawful basis | |---|---|---|---|---| | Direct message content | Supabase (encrypted at rest) | 2 years from sending, OR until account deletion, whichever is sooner | Rolling window OR account deletion | Art. 6(1)(b) | | Message metadata (timestamps, read receipts) | Supabase | Same | Same | Same | | Reported messages (flagged for review) | Supabase + moderation DB | 3 years from report to retain evidence against repeat offenders | Report closure + 3 years | Art. 6(1)(c) legal obligation + Art. 6(1)(f) | | Video-call session records (LiveKit) | LiveKit session logs | 30 days (no recording of call content — only session metadata) | 30-day rolling | Art. 6(1)(f) |


5. Age-verification records

These are retained under a distinct regime because the Online Safety Act imposes record-keeping duties for age-assurance processes.

| Category | Where | Retention | Trigger | Lawful basis | |---|---|---|---|---| | Fact of age verification (boolean + method + timestamp + provider reference ID) | Supabase age_verifications table | Life of account + 7 years after account closure | Account deletion | Art. 6(1)(c) legal obligation (OSA) | | DOB self-declaration (where permitted — not in UK/EU production) | Supabase | Life of account | Account deletion | Art. 6(1)(b) | | Third-party provider transaction ID (VerifyMyAge or equivalent) | Supabase | Same as fact-of-verification | Same | Art. 6(1)(c) | | Identity documents / selfies / biometric templates | Not stored by us. Held by the age-assurance provider under their own retention schedule. | N/A — we never receive the document images | N/A | N/A |

We deliberately do not receive or store ID documents, biometric face templates, or credit-card numbers from age-assurance providers. We only receive a pass/fail result and a reference ID.


6. Financial records

| Category | Where | Retention | Trigger | Lawful basis | |---|---|---|---|---| | Subscription records (tier, start date, end date, price) | Supabase + CCBill | 7 years after final transaction | Subscription end + 7 years | Art. 6(1)(c) legal obligation (Companies Act 2006, VATA 1994 s.58, HMRC guidance for record-keeping) | | Invoices and receipts | Supabase + CCBill | 7 years | Same | Same | | Refund and chargeback records | CCBill + internal finance log | 7 years after resolution | Dispute resolution + 7 years | Art. 6(1)(c) | | Payment-card data (PAN, CVV, expiry) | Not stored by us. CCBill handles PCI-scope data under PCI-DSS. | N/A | N/A | N/A | | Billing name and address | CCBill (primary), Supabase billing shadow table | 7 years after final transaction | Same as invoices | Art. 6(1)(c) |

We rely on CCBill's PCI-DSS compliant systems for card data. We retain only the fields needed for accounting and dispute resolution.


7. Moderation, safety, and illegal-content records

| Category | Where | Retention | Trigger | Lawful basis | |---|---|---|---|---| | Reports received from members (Tier 1 and Tier 2) | Supabase moderation schema | 3 years from report closure | Case closed + 3 years | Art. 6(1)(c) + Art. 6(1)(f) | | Moderation decisions (removals, suspensions, bans) and rationale | Supabase moderation schema | 3 years from decision | Decision + 3 years | Same | | Automated moderation classifier scores (NudeNet, Sightengine) | Supabase (short-term) + data warehouse (aggregated) | 90 days at record level; aggregated/anonymised indefinitely | Rolling 90d | Art. 6(1)(f) | | Appeal records | Supabase | 3 years from appeal closure | Appeal closed + 3 years | Art. 6(1)(c) + Art. 6(1)(f) | | Evidence of Category A violations (CSAM, terrorism) | Preserved per law-enforcement / NCMEC / IWF / CTIRU instructions — may exceed 3 years where a referral is open | Per direction of law enforcement | Referral open | Art. 6(1)(c) + Art. 6(1)(d) vital interests + Art. 9(2)(g) substantial public interest | | CyberTipline submission receipts (NCMEC) | Secure evidence store | Indefinite or as directed | Submission | Art. 6(1)(c) (18 U.S.C. § 2258A) | | Age-gating breach investigations (underage user suspected) | Secure evidence store | 7 years from closure | Closure + 7 years | Art. 6(1)(c) |

Where we receive a preservation order from law enforcement or a court, we preserve the specified records for the period stated in the order — this overrides ordinary retention.


8. Technical, security, and operational logs

| Category | Where | Retention | Trigger | Lawful basis | |---|---|---|---|---| | Web-server access logs (IP, user-agent, URL, status, timestamp) | Cloudflare + internal log store | 30 days | Rolling 30d | Art. 6(1)(f) security, fraud detection | | Authentication events (logins, password resets, MFA events) | Supabase Auth + internal log | 12 months | Rolling 12 months | Art. 6(1)(f) + Art. 6(1)(c) | | Application error logs (Sentry) | Sentry (EU region) | 90 days | Rolling 90d | Art. 6(1)(f) | | Push-notification delivery logs | Internal log | 30 days | Rolling 30d | Art. 6(1)(f) | | Rate-limit and abuse-detection events | Internal log | 12 months | Rolling 12 months | Art. 6(1)(f) | | Security-incident investigation files | Secure evidence store | 6 years from closure | Incident closed + 6 years | Art. 6(1)(f) + Art. 6(1)(c) (Limitation Act 1980 for potential civil claims) | | Data subject request (DSR) records | DSR register | 6 years after fulfilment | Fulfilment + 6 years | Art. 6(1)(c) + ICO guidance |


9. Communications and marketing

| Category | Where | Retention | Trigger | Lawful basis | |---|---|---|---|---| | Transactional email (account, security, billing) logs | Resend / Supabase | 12 months | Rolling 12 months | Art. 6(1)(b) | | Marketing email opt-in / newsletter | Resend | Until opt-out, then 3 years for suppression-list purposes (so we don't re-send) | Opt-out | Art. 6(1)(a) consent (then Art. 6(1)(f) for suppression) | | In-app notification history | Supabase | 90 days | Rolling 90d | Art. 6(1)(b) | | Support / contact form submissions | Supabase | 3 years from closure | Closed + 3 years | Art. 6(1)(b) + Art. 6(1)(f) | | Complaints submitted under the Complaints Procedure | Secure complaints register | 6 years from closure | Closed + 6 years | Art. 6(1)(c) (OSA record-keeping + Limitation Act 1980) |


10. Analytics

| Category | Where | Retention | Trigger | Lawful basis | |---|---|---|---|---| | PostHog event stream (pseudonymous) | PostHog (self-hosted / EU-hosted) | 12 months at event level; aggregated indefinitely | Rolling 12 months | Art. 6(1)(a) consent | | Session replays | Disabled. We do not run session replay on adult-content surfaces. | N/A | N/A | N/A | | A/B test assignment records | PostHog | Duration of experiment + 90 days | Experiment end + 90d | Art. 6(1)(a) |


11. Data we do not retain

For clarity — we do not store, and have never stored:

  • Raw face images, biometric templates, or identity-document images submitted to age-assurance providers (these live with the provider).
  • Raw payment-card numbers, CVVs, or card-expiry dates (these live with CCBill).
  • Your keystrokes, mouse movements, scroll behaviour, or session replays.
  • "Shadow" profile data scraped from social networks.
  • Device fingerprints used for cross-site tracking.

12. Deletion of backups

Backups are held on a rolling 35-day window. When a record is deleted from live storage, the deletion propagates to backups within that window. We do not restore individual deleted records from backup except where required by a court order or by the data subject themselves.

13. Legal holds

Where we receive a legal preservation notice — for example a subpoena, court order, civil-discovery preservation notice, or law-enforcement preservation order — we preserve the identified records for the required period, notwithstanding the retention periods in this schedule. Affected data subjects will be notified of the hold where we are permitted to do so.

14. Review cadence

This schedule is reviewed:

  • at least annually by the data protection lead;
  • whenever a new processor, data category, or product surface is introduced;
  • whenever a change in UK or EU law affects a retention period;
  • immediately after any material security incident.

15. Contact

[LEGAL ENTITY] — company number [COMPANY NUMBER] — registered at [REGISTERED OFFICE ADDRESS]

Data Protection queries: privacy@galerieminuit.com (placeholder) Data Protection Officer: [DPO NAME AND CONTACT — to be appointed before launch] ICO registration reference: [ICO REGISTRATION NUMBER — to be confirmed]


This document is a draft. It must be verified against your live systems, reviewed by a UK-qualified solicitor or your appointed Data Protection Officer, and fact-checked against your ROPA before it is published.