| What | Stored | For how long |
|---|---|---|
| Account | e-mail address, time of registration, a hashed token per signed-in device | until you erase it; a device token 30 days; unconfirmed addresses 7 days |
| Profile | what you add: name, organisation, role, line, biography, place, contact, website, languages, picture | until you change or erase it |
| Journal | your entries, public or private | until you delete them or the account |
| Files | the files you upload, with title and public flag | until you delete them; deleted files leave the backups after 14 days |
| Proposals | name, title, area, summary, links, the record trail you attach | an unconfirmed proposal 7 days; a published module while it is in the catalogue |
| Applications | the text you write to become a contributor | 24 months after the decision |
| Requests and reports | name, address, organisation, kind, text | 180 days |
| Invitations | the address you invite and your message | unanswered ones 180 days |
| Services | name, kind, the address to check, results | until you remove them |
| Sign-in links | a hash of the link, its purpose and expiry | 20 minutes for sign-in, one hour for a proposal confirmation, then purged |
| Request log | IP address, path, status, duration, account number when signed in | 14 days |
| Record chain | account numbers, hashes, kinds, short texts | permanently |
| Backups | encrypted copies of the database and the site | kept without a fixed limit for the time being; the statement says so |
What stays in your browser, and only there: your projects, the board's record trail, your theme and your sign-in token.
Dormant accounts
No sign-in for 24 months brings a notice by mail; three months later without a sign-in the account is erased like a self-erasure, with the attribution set on each module.