Last updated: 22 July 2026
Version: 1.0
This Policy explains how long Nexus keeps personal data and how deletion works.
It reflects the retention behaviour actually implemented in the Service and
supports the principle of storage limitation (Article 5(1)(e) GDPR).
We keep personal data only for as long as necessary for the purposes for which
it was collected, or as required by law. When data is no longer needed, it is
deleted or anonymised.
| Data category | Retention period |
|---|---|
| Account data (identity, profile) | While the account exists |
| Messages and uploaded files | While the account exists / until deleted by the user or the conversation is removed |
| Account after a deletion request | Anonymised or deleted after a grace period, during which the user can cancel the deletion |
| Open moderation reports | Until resolved, plus 90 days |
| Resolved or dismissed moderation reports | 180 days after the decision; the content snapshot is then cleared and the record is removed shortly afterwards |
| Group/channel block appeals | Kept as moderation records subject to the same report retention rules |
| GDPR processing log (Art. 30 records of moderation/PII actions) | Up to 3 years |
| Approximate location cache (IP-to-country/city) | Cached temporarily and periodically refreshed |
| Session records | Until the session expires or is revoked by the user |
| Rate-limiting records | Kept short-term for abuse prevention |
Automated routines periodically remove or anonymise expired moderation data and
old processing-log entries.
Before deleting your account, you can export your data from within the app
(Settings → Export my data), supporting your right of access and right to data
portability.
Where backups exist, deleted or anonymised data is removed from active systems
promptly and cycles out of backups according to the backup rotation schedule.
E-mail: [CONTROLLER CONTACT EMAIL]