| Account data | Name, email, organization, authentication metadata. | Kept while the account is active. Self-service deletion immediately revokes sessions and tokens and scrubs direct identifiers from active application records. |
| Conference workspaces | Conference setup, memberships, schedules, registrations, submissions, and reviews. | Kept while the workspace is active. Owner deletion makes it private immediately and keeps it recoverable for 30 days. Permanent purge is allowed only after that window. |
| Orders, receipts & payment records | Transaction records, invoices, and receipts. Card numbers are never stored — Stripe handles card data. | Transaction records are retained only as needed for support, fraud prevention, and applicable accounting or legal obligations. Account deletion removes or replaces linked attendee identifiers where the record can be preserved without them. |
| Submissions & reviews | Papers, abstracts, review forms, scores, and decision records for a conference. | Kept with the conference workspace. Deleting an author or reviewer account scrubs direct identifiers but does not silently remove the conference's academic record. |
| Uploaded files | Manuscripts, camera-ready files, and other documents in object storage. | Retained while referenced by an active or recoverable record. Files become eligible for storage cleanup after the parent record is permanently purged and then age out of backup snapshots. |
| Application & audit logs | Security and audit logs of sensitive actions, plus operational error logs. | Kept for operational security, debugging, abuse investigation, and accountability. Provider log windows and application audit records can differ; contractual fixed windows are not offered in free public beta. |
| Analytics | Consent-backed, pseudonymous first-party product events. No third-party ad trackers. | Retained for beta product measurement and aggregate reporting. Events use hashed visitor and session identifiers rather than account email addresses. |