Retention & deletion
Data Retention & Deletion Policy
- Operator:
- Science Communications Worldwide (Science Communications Worldwide - Verein zur weltweiten Verbreitung wissenschaftlicher Kommunikation)
- Last updated:
- 20 September 2026
- Version:
- 2.4 — supersedes the revision dated 5 September 2026
In short
Principles
Retention follows the GDPR’s storage-limitation principle (Article 5(1)(e)): every category of data has either a fixed period or a criterion tied to its purpose. Three purposes justify longer retention: the integrity of the public scholarly record, the security of the platform, and legal obligations including the ability to demonstrate consent and to establish, exercise, or defend legal claims.
Retention schedule
| Category | Retention | Notes |
|---|---|---|
| Account identity (email, sign-in identities, settings) | While the account exists, then the 30-day restoration window | Erased or irreversibly de-linked at purge (Section 3) |
| Sign-in sessions | Session token 15 minutes; refresh token 7 days | Active device sessions are listed in Settings → Security and can be revoked at any time |
| Passkey and sign-in challenges | Minutes | Deleted automatically when the sign-in ceremony completes or expires |
| Profile content (biography, interests, CV documents) | Until you edit or remove it, at latest until account purge | Most fields are directly editable in your settings |
| Published listings and hosted research content | Lifetime of the scholarly record | De-linked from your identity if your account is deleted; removal on request where rights require it |
| DOI-registered metadata | The DOI identifier remains resolvable; associated personal metadata is kept only while justified | A removed item’s DOI resolves to a tombstone. Metadata can be corrected or reduced where applicable rights require it |
| Job applications you submit | Until you delete your account | Deleted in the purge; the employer’s received copy is under the employer’s responsibility |
| Consent records (accept/reject decisions) | As long as needed to demonstrate compliance | Kept as proof under Art. 7(1) GDPR |
| Usage analytics (opt-in) | Raw records: 26 months | A daily transactional job purges overdue rows and records counts and cutoffs. Aggregate content metrics and consent evidence are excluded |
| PostHog session replay (opt-in) | 30 days under the current recording-retention setting | Recordings expire automatically. A retention-setting change applies only to new recordings |
| Application, worker, API, and firewall logs | 7 days (build logs up to 30 days) | Application records use truncated, keyed network hashes; firewall records contain full IP addresses |
| Load-balancer access logs | 90 days | Perimeter request records include full IP address, requested address, timestamp, response status, and browser identification string |
| Security audit trail (sign-ins, security changes, administrative actions) | Retained long-term, append-only | De-linked from deleted accounts; kept to investigate abuse and defend claims |
| Unfinished material | Abandoned sign-ups ≈ 24 hours; unprocessed submissions 7 days; failed conference uploads 24 hours; rejected conference uploads 30 days | Cleaned up automatically, including the underlying files |
| Support requests, reports, and feedback | As long as needed to resolve the matter, plus any legally required audit period | |
| Database backups | Automated backups: 7 days; manual recovery snapshots: see Section 5 | Recovery copies are restricted and are not used for ordinary processing |
Account deletion, step by step
You can delete your account yourself under Settings → Security. Because deletion is irreversible after the window, the request requires a recent sign-in and, where enabled, your second factor. The process:
- Immediately: the account is marked for deletion, every active session on every device is signed out, and a 30-day restoration window begins during which signing back in can restore the account.
- After 30 days: an automated purge erases the account. Identity data, profile, settings, bookmarks, follows, alerts, comments, ratings, notes, sign-in identities, passkeys, and two-factor material are deleted. Uploaded profile media and personal storage are removed. Your job applications are deleted. A public speaker page linked to the account is stripped to “Deleted user” with all identifying fields cleared.
- De-linking: records that must survive for the integrity of the platform — published listings, the moderation trail, pseudonymised analytics, and the security audit ledger — lose their reference to your account rather than being destroyed, so they can no longer be attributed to you.
- Receipt: the purge leaves only a content-free deletion receipt (a one-way hash) proving the erasure took place.
If you cannot access your account, request deletion by email from the address associated with it: info@world-wide.org.
What deletion does not remove
- The scholarly record: listings and hosted work remain published in de-linked or attributed form as appropriate. A DOI remains resolvable, normally to a tombstone after withdrawal, but its personal metadata is not categorically exempt from correction, restriction, or erasure (Section 2). Ask us about removing or anonymising a specific published item — rights under the Privacy Notice apply.
- Backups: copies persist in the automated backups until those cycle out (7 days after the purge). Manual recovery snapshots can remain longer as described below.
- Legal holds: where a legal obligation or an ongoing dispute requires retention, the affected records are kept restricted until the obligation ends.
Backups
The production database is backed up automatically on a rolling 7-day cycle. Manual snapshots may be retained beyond that cycle for a migration, recovery, or documented legal hold. They remain restricted and are removed when that specific need ends. Backups exist for recovery only and are not used to resurrect deleted data; if a backup ever has to be restored, deletions performed since that backup are re-applied as part of recovery.
Targeted deletion requests
You do not need to delete an account to have specific data removed — this applies equally to people without an account who are named in hosted content (see Privacy Notice, Section 3.3). Email info@world-wide.org with the URL of the material. We normally answer within one month; for a complex request the GDPR permits up to two further months after notice. Where we must retain something (for example, for legal claims or the integrity of the citation record), we will say so and restrict it instead where the GDPR provides for that.
Contact
For legal, privacy, and policy inquiries, email info@world-wide.org.