Data Retention & Deletion Policy
STATUS: DRAFT. This document has not been reviewed by licensed counsel. It describes how Sparkshed actually behaves today and is published so that behaviour is inspectable, but it is not legal advice and it is not a finished agreement. See the counsel review packet for what is still outstanding.
Data we store
Account data: email, display name (if you create an account).
Project data: circuit designs, firmware source, simulation results (if you publish or sync to cloud).
Community data: published projects, leaderboard scores, comments (if you participate).
Telemetry: anonymous event counts (if you consent to telemetry). No individual event logs are retained.
Retention periods
Account data: retained while your account is active. Deleted within 30 days of account closure.
Published projects: retained indefinitely while your account is active. Removed when you unpublish or delete your account.
Unpublished projects (local): stored only in your browser's IndexedDB. Never sent to our servers unless you explicitly sync or publish.
Telemetry counts: retained indefinitely as aggregate statistics. No individual event logs exist.
Crash reports (local): stored only in your browser's localStorage. Never sent to our servers.
Your deletion rights
You can delete your account and all associated data by contacting us. Deletion is permanent and irreversible.
You can request a copy of all data we hold about you (data portability) by contacting privacy@sparkshed.dev. We will provide a machine-readable export within 30 days.
Under GDPR (EU/UK) and CCPA (California), you have the right to access, correct, delete, and port your personal data.
Legal holds
In rare circumstances (legal obligation, dispute resolution, enforcement of our terms), we may retain data beyond the standard retention period. You will be notified if a legal hold is placed on your data.