ShroomShroom Retention Schedule (annex to the Privacy Policy)
Effective: 04.09.2026 · Version 1.1
Principle: the collection is the product, so player-created content lives as long as the player wants it, while each data category has its own clock and justification. Deletion by the user always overrides these clocks (except legal-hold items).
| Data | Retention | Justification / notes |
|---|---|---|
| Account (email, handle, settings, consent log) | Until deletion; after 10 years of no interaction the account is deleted, preceded by reminder emails (first after 2 years of inactivity, then yearly, final notice 60 days before deletion) | Storage limitation met by the reminder-and-delete cycle; a season-based collection game reasonably persists across long gaps. Consent/objection log kept 10 years after account deletion as evidence (Art. 5(2) accountability). |
| Find photos and observation records (incl. precise coordinates) | Life of the account (same 10-year inactivity rule) | Core service content; coordinates render hunt maps, which are public by default until the profile, hunt or card is made private. Coordinates are truncated to 3 km in any dataset release. |
| Pseudonymised training/dataset copies | Indefinite for already-released datasets and trained models; excluded from new releases after deletion/objection | Terms 4.4; pseudonymised, 3 km truncation. |
| Kindwise API responses | Life of the find | Re-used to avoid repeat charges; part of the record. |
| Verification result + reference code | 12 months, then aggregate only | Enough to honour "already verified" without re-checking. |
| Verification image | Not stored. Deleted on result | Mirrors VerifEye commitment. |
| Suspected-fraud verification attempt (metadata, image where strictly necessary) | 30 days | Investigation window; then delete or escalate to a legal case file. |
| Research-programme verification images (opt-in adults) | Until consent withdrawn; maximum 3 years per contribution | Art. 9(2)(a); forward deletion on withdrawal. |
| Server and access logs, IP addresses | 12 months | Security norm. |
| Crash/diagnostic reports | 6 months | Debugging. |
| Support correspondence | 3 years after ticket close | Limitation periods for consumer claims. |
| Orders, invoices, payment records | 7 years from the end of the financial year | Estonian Accounting Act §12 (raamatupidamise seadus). |
| Marketing consent + sends | Until withdrawn; proof of consent 10 years | Accountability. |
| Deleted account data | Purged from live systems within 30 days; backups expire within 90 days | Backup rotation cycle. |
| Junior-account guardian links | Life of the junior account + consent log as above | — |
An active or dormant account is kept because the player chose to keep their collection. Abandoned accounts are not kept silently: the reminder cycle above tells the player the account exists, offers export and deletion, and announces the final deletion. The 12-month log clock and the 30-day fraud clock are not extended.
