Account Deletion & Data Retention Policy
Effective Date: September 19, 2026
Last Updated: September 22, 2026
Platform Provider: Startum Identity Platform ("Startum", "we", "us", or "our")
1. Overview
This Account Deletion & Data Retention Policy details how user accounts, identity claims, developer configurations, active sessions, and OAuth tokens are managed, retained, and permanently deleted across the Startum Identity Platform.
2. User Account Deletion Lifecycle
Users may initiate account closure at any time directly through the Startum Account Portal under Security & Account Settings -> Delete Account.
When an account deletion request is submitted:
Phase 1: Instant Revocation (Immediate)
- Session Invalidation: All active user web sessions (
startum_session) across all browsers and devices are destroyed immediately. - Token Invalidation: All access tokens and refresh tokens issued to third-party applications authorized by the user are immediately revoked and blacklisted.
- Consent Disconnection: All OAuth authorization grants connecting the account to third-party client applications are severed.
Phase 2: Soft Deletion & Recovery Window (7 Days)
- The account profile enters a temporary 7-day deactivation state. During this period, the account cannot be used for third-party SSO.
- During this 7-day window, the account owner may authenticate directly at
https://startum.cloudto access an immediate self-service "Cancel Deletion / Restore Account" option. - Account deletion can also be cancelled by contacting
[email protected]from the verified account owner email, as a secondary fallback if self-service recovery is inaccessible.
Phase 3: Permanent Database Erasure (Day 8–30)
- On Day 8 following deletion, automated scrubbing scripts remove all personal identity data from active databases:
- Backup snapshots rotate out within 30 calendar days, achieving complete data erasure.
Primary user record (username, email address, password hash, display name, avatar URL).
Pairwise subject identifier mappings associated with the account.
* Multi-factor authentication secrets and recovery keys.
3. Data Retention Windows for Platform Operations
Startum retains specific operational logs and system metadata for strict security, auditing, and compliance windows:
| Data Category | Retention Period | Storage & Handling |
|---|---|---|
| Active Identity Profile | Duration of Account | Encrypted primary identity store (startum.db). |
| OAuth Consent Grants | Until Revoked or Account Deleted | Stores scope permissions granted per Client ID. |
| Authentication Audit Logs | 90 Days | IP address, user-agent, timestamp, login pass/fail status used for anomaly detection. |
| API Rate Limit Logs | 24 Hours | Transient memory cache used strictly for DDoS mitigation. |
| Developer Application Metadata | Duration of App Registration | App title, Client ID, Client Secret hash, redirect URIs. |
4. Pairwise Subject ID Unlinking & Third-Party Apps
- Non-Reusable Subject IDs: Because pairwise subject identifiers (
sub) are derived from the user ID, Client ID, and Startum Master Key, deleting a Startum account permanently destroys the underlying identity seed. - Third-Party App Records: Deleting your Startum account severs your identity link with third-party applications. If you subsequently register a new Startum account using the same email address, third-party apps will receive a new, completely different pairwise subject ID.
- Third-Party Data Deletion: Deleting your Startum account invalidates app tokens, but does not automatically erase data stored on third-party application servers. You must contact individual third-party app providers to request deletion of data stored directly within their systems.
5. Developer Account & Application Deletion
Developers who register applications in the Startum Developer Portal may delete registered applications at any time:
- Deleting a registered application immediately revokes its
client_idandclient_secret. - All active user tokens and authorizations issued for that application are rendered invalid instantly.
- Deleting a developer account removes all registered applications owned by that developer.
6. Questions & Data Removal Requests
For questions or assistance regarding account deletion, data retention, or statutory privacy requests:
Email: [email protected]
Account Portal: https://startum.cloud