Retention & deletion

Data Retention & Deletion Policy

Operator:
Science Communications Worldwide (Science Communications Worldwide - Verein zur weltweiten Verbreitung wissenschaftlicher Kommunikation)
Last updated:
20 September 2026
Version:
2.4 — supersedes the revision dated 5 September 2026

In short

We keep data only as long as its purpose requires. Deleting your account starts a 30-day restoration window; after it, your identity data is erased and remaining records are de-linked. Published research content and persistent DOI records are designed to outlast accounts — that is what a scholarly record is for, while applicable correction and erasure rights still apply to personal metadata. Database backups cycle out after 7 days.

Principles

Retention follows the GDPR’s storage-limitation principle (Article 5(1)(e)): every category of data has either a fixed period or a criterion tied to its purpose. Three purposes justify longer retention: the integrity of the public scholarly record, the security of the platform, and legal obligations including the ability to demonstrate consent and to establish, exercise, or defend legal claims.

Retention schedule

Retention periods by data category
CategoryRetentionNotes
Account identity (email, sign-in identities, settings)While the account exists, then the 30-day restoration windowErased or irreversibly de-linked at purge (Section 3)
Sign-in sessionsSession token 15 minutes; refresh token 7 daysActive device sessions are listed in Settings → Security and can be revoked at any time
Passkey and sign-in challengesMinutesDeleted automatically when the sign-in ceremony completes or expires
Profile content (biography, interests, CV documents)Until you edit or remove it, at latest until account purgeMost fields are directly editable in your settings
Published listings and hosted research contentLifetime of the scholarly recordDe-linked from your identity if your account is deleted; removal on request where rights require it
DOI-registered metadataThe DOI identifier remains resolvable; associated personal metadata is kept only while justifiedA removed item’s DOI resolves to a tombstone. Metadata can be corrected or reduced where applicable rights require it
Job applications you submitUntil you delete your accountDeleted in the purge; the employer’s received copy is under the employer’s responsibility
Consent records (accept/reject decisions)As long as needed to demonstrate complianceKept as proof under Art. 7(1) GDPR
Usage analytics (opt-in)Raw records: 26 monthsA daily transactional job purges overdue rows and records counts and cutoffs. Aggregate content metrics and consent evidence are excluded
PostHog session replay (opt-in)30 days under the current recording-retention settingRecordings expire automatically. A retention-setting change applies only to new recordings
Application, worker, API, and firewall logs7 days (build logs up to 30 days)Application records use truncated, keyed network hashes; firewall records contain full IP addresses
Load-balancer access logs90 daysPerimeter request records include full IP address, requested address, timestamp, response status, and browser identification string
Security audit trail (sign-ins, security changes, administrative actions)Retained long-term, append-onlyDe-linked from deleted accounts; kept to investigate abuse and defend claims
Unfinished materialAbandoned sign-ups ≈ 24 hours; unprocessed submissions 7 days; failed conference uploads 24 hours; rejected conference uploads 30 daysCleaned up automatically, including the underlying files
Support requests, reports, and feedbackAs long as needed to resolve the matter, plus any legally required audit period
Database backupsAutomated backups: 7 days; manual recovery snapshots: see Section 5Recovery copies are restricted and are not used for ordinary processing

Account deletion, step by step

You can delete your account yourself under Settings → Security. Because deletion is irreversible after the window, the request requires a recent sign-in and, where enabled, your second factor. The process:

  • Immediately: the account is marked for deletion, every active session on every device is signed out, and a 30-day restoration window begins during which signing back in can restore the account.
  • After 30 days: an automated purge erases the account. Identity data, profile, settings, bookmarks, follows, alerts, comments, ratings, notes, sign-in identities, passkeys, and two-factor material are deleted. Uploaded profile media and personal storage are removed. Your job applications are deleted. A public speaker page linked to the account is stripped to “Deleted user” with all identifying fields cleared.
  • De-linking: records that must survive for the integrity of the platform — published listings, the moderation trail, pseudonymised analytics, and the security audit ledger — lose their reference to your account rather than being destroyed, so they can no longer be attributed to you.
  • Receipt: the purge leaves only a content-free deletion receipt (a one-way hash) proving the erasure took place.

If you cannot access your account, request deletion by email from the address associated with it: info@world-wide.org.

What deletion does not remove

  • The scholarly record: listings and hosted work remain published in de-linked or attributed form as appropriate. A DOI remains resolvable, normally to a tombstone after withdrawal, but its personal metadata is not categorically exempt from correction, restriction, or erasure (Section 2). Ask us about removing or anonymising a specific published item — rights under the Privacy Notice apply.
  • Backups: copies persist in the automated backups until those cycle out (7 days after the purge). Manual recovery snapshots can remain longer as described below.
  • Legal holds: where a legal obligation or an ongoing dispute requires retention, the affected records are kept restricted until the obligation ends.

Backups

The production database is backed up automatically on a rolling 7-day cycle. Manual snapshots may be retained beyond that cycle for a migration, recovery, or documented legal hold. They remain restricted and are removed when that specific need ends. Backups exist for recovery only and are not used to resurrect deleted data; if a backup ever has to be restored, deletions performed since that backup are re-applied as part of recovery.

Targeted deletion requests

You do not need to delete an account to have specific data removed — this applies equally to people without an account who are named in hosted content (see Privacy Notice, Section 3.3). Email info@world-wide.org with the URL of the material. We normally answer within one month; for a complex request the GDPR permits up to two further months after notice. Where we must retain something (for example, for legal claims or the integrity of the citation record), we will say so and restrict it instead where the GDPR provides for that.

Contact

For legal, privacy, and policy inquiries, email info@world-wide.org.

The periods stated here reflect the platform’s current production configuration and are updated when it changes. The Privacy Notice governs the underlying processing.

We use essential cookies to run the site. Optional analytics and public-page session replay help us improve World Wide. Learn more.

Data Retention & Deletion Policy | World Wide - World Wide