Tarosyn Legal
Data Retention Policy
Last updated May 31, 2026
This Data Retention Policy explains how long Tarosyn LLC ("Tarosyn," "we," "us," or "our") retains different categories of personal data, how data is archived or anonymised as it ages, and how deletion is carried out — whether you request it or we determine it is no longer needed. This policy should be read alongside our Privacy Policy and Account Deletion Policy.
retention periods by data category
DATA CATEGORY ACTIVE RETENTION POST-DELETION / EXPIRY
Account & Identity Life of account Deleted within 30 days of account deletion request
Tarot Readings & Journal Entries Life of account Deleted within 30 days; residual backup copies overwritten within 90 days
Direct Messages & Circle Chat Life of account Deleted within 30 days; soft-deleted messages purged after 90 days
Uploaded Photos & Media Life of account Object storage files deleted within 30 days of account deletion
Billing Records & Transactions Life of account + 7 years (tax/legal) Retained up to 7 years from transaction date for legal compliance; then purged
Push Notification Subscriptions Until revoked or account deleted Removed immediately on unsubscribe or account deletion
Server & Security Logs 90 days rolling Automatically purged after 90 days; fraud/abuse logs retained up to 2 years
Moderation & Safety Records 2 years from incident Anonymised after 2 years unless subject to legal hold
Analytics & Usage Data 13 months rolling Aggregated/anonymised after 13 months; raw events deleted
Encrypted Database Backups 90-day rolling window Overwritten automatically on rotation; no manual step required archival approach
Data that is no longer actively needed but must be retained for legal, regulatory, or safety reasons is moved to an archived state. Archived data is:
Stored in a lower-cost, access-restricted storage tier No longer surfaced in the product or accessible via the API Accessible only to authorised Tarosyn personnel for legal or compliance purposes Encrypted at rest using the same standards applied to live data
Where the legal or safety basis for archival ends before the stated retention period, we will delete or anonymise the data earlier.
deletion schedules
Deletion is triggered by one of the following events:
Account deletion request — you delete your account via Settings → Account or by emailing [email protected]. Personal data is purged within 30 days, except for categories with a mandatory retention period listed above. Retention period expiry — data whose active retention window has closed is deleted or anonymised on a rolling schedule, typically within 30 days of expiry. Content removal — content you delete (readings, journal entries, Chant posts, messages) is removed from live databases promptly; residual copies in encrypted backups are overwritten within 90 days.
Automated deletion jobs run on a nightly schedule. Some categories (e.g. billing records, safety logs) require manual review before deletion to ensure legal obligations are met.
retention exceptions
We may retain data beyond the periods stated above where required for:
Legal hold — data subject to active litigation, regulatory inquiry, or law-enforcement request is frozen until the matter is resolved. Tax and financial compliance — billing records and transaction logs may be required for up to 7 years under applicable tax law. Fraud and abuse prevention — evidence of policy violations used to enforce bans or report criminal conduct may be retained beyond the standard period. Dispute resolution — records relevant to a pending refund dispute or chargeback may be held until resolution.
When an exception applies we retain only the minimum data necessary for the specific purpose. We do not use exceptional retention as a blanket justification for keeping data indefinitely.
backups & encrypted copies
Tarosyn maintains encrypted database backups for disaster-recovery purposes. Backup retention is set to 90 days. Data deleted from live systems will persist in backups until those backups rotate out, after which the data is gone permanently. Backups are stored in an access-restricted environment and are not used for analytics or product development.
questions & requests
To request deletion, export, or correction of your data, or to ask about the retention period that applies to a specific category, contact us at [email protected]. We will verify your identity before responding.
EU/UK residents and California residents have additional rights described in our Privacy Policy §11.
Tarosyn LLC, United States.
