DARIENCRUTE.COM DATA RETENTION POLICY
Version: 1.0
Effective Date: July 13, 2026
Last Updated: July 13, 2026
1. PURPOSE
This Data Retention Policy explains how DarienCrute.com determines how long personal information and related records are kept, when information is deleted or deidentified, how deletion requests are handled, and what limited circumstances may require information to be retained longer.
DarienCrute.com is operated by Darien Cruté. In this policy, "DarienCrute.com," the "Site," "we," "us," and "our" refer to the Site and its operator.
This policy supplements the DarienCrute.com Privacy Policy and Terms of Use. If this policy conflicts with a legal obligation, court order, or valid preservation requirement, the applicable legal requirement controls.
2. SCOPE
This policy applies to personal information and related records maintained through DarienCrute.com, including:
- User account information;
- Authentication and password-reset information;
- Birthday and age-eligibility information;
- Private profile information;
- Book ratings and written reviews;
- Soulcandle descriptions, traits, images, and related records;
- Contact-form submissions;
- Privacy, support, and account-management requests;
- Terms of Use and Privacy Policy acceptance records;
- Technical and security logs;
- Fraud, abuse, and moderation records;
- Security-incident and breach-response records;
- Backup copies; and
- Related administrative records.
This policy applies regardless of whether information is stored in a database, file system, server log, email system, backup, service-provider system, or another authorized location.
This policy does not require deletion of non-personal creative, literary, educational, technical, or business content merely because it has existed for a particular period. Books, fictional lore, calendar systems, public Site content, source code, and similar materials may be retained for as long as they remain useful or legally protected.
3. RETENTION PRINCIPLES
DarienCrute.com follows these general principles:
- Collect only information reasonably necessary for a defined purpose;
- Retain information only while that purpose continues or another legitimate reason applies;
- Use shorter retention periods for sensitive or temporary information;
- Avoid retaining raw information when a less identifying form will serve the same purpose;
- Restrict access according to operational need;
- Delete, destroy, or deidentify information when its retention period ends;
- Apply heightened care to information belonging to known users under 18;
- Suspend ordinary deletion when a valid legal or security preservation requirement applies; and
- Review retention periods as the Site, technology, and law change.
Information will not be retained indefinitely merely because storage is available.
4. RETENTION PERIOD DEFINITIONS
For purposes of this policy:
"Account closure" means the date an account is permanently deleted or otherwise closed for ordinary use.
"Active system" means a production database, active file system, administrator interface, or other system used in the regular operation of the Site.
"Deletion" means removal from active use and destruction or erasure through reasonable technical methods.
"Deidentification" means modifying information so that it cannot reasonably be linked to an identifiable user without additional information that is maintained separately and protected.
"Legal hold" means a documented suspension of ordinary deletion because information may be relevant to litigation, an investigation, a government request, a security incident, a contractual dispute, or another legal obligation.
"Service provider" means an outside provider that processes information on behalf of DarienCrute.com, such as a hosting, email, backup, security, or artificial intelligence provider.
5. USER ACCOUNTS
5.1 Active Accounts
The following information may be retained while an account remains active:
- Username;
- Email address;
- Password hash;
- Access level;
- Account status;
- Wickborne birthday;
- Account creation and update dates;
- Profile information;
- Associated reviews;
- Soulcandle result and image;
- Authentication and account-management records; and
- Current legal-policy acceptance records.
This information is retained because it is necessary to provide and administer the account and its requested features.
5.2 Inactive Accounts
An account that has not been accessed for five consecutive years may be scheduled for deletion.
Before deleting an inactive account, we will make a reasonable effort to send notice to the email address associated with the account at least 60 days before the scheduled deletion.
Logging into the account or responding to the notice may cancel the scheduled deletion.
We may delete an inactive account without the full notice period when:
- The email address is invalid or undeliverable;
- The account was created fraudulently;
- The account violates the Terms of Use;
- The account presents a security risk;
- The user is ineligible to maintain an account;
- Continued retention is unlawful; or
- Immediate action is otherwise reasonably necessary.
5.3 Account Closure or Deletion
Following a verified account-deletion request or final administrative account deletion:
- The account will be disabled promptly;
- Active account data will ordinarily be deleted within 30 days;
- Associated reviews will ordinarily be deleted with the account;
- The Soulcandle database record will be deleted;
- The associated Soulcandle image file will be deleted from active storage;
- Active password-reset credentials will be invalidated;
- Active sessions will be invalidated where technically available; and
- Information remaining in restricted backups will expire through the normal backup cycle, ordinarily within 90 days.
Limited records may be retained longer under the exceptions described in this policy.
6. PASSWORDS, AUTHENTICATION, AND SESSION INFORMATION
6.1 Passwords
DarienCrute.com does not retain plaintext account passwords.
A password hash is retained while the account remains active and is deleted from active systems as part of account deletion.
Old password hashes should not be retained after a password is successfully changed unless a temporary security need requires otherwise.
6.2 Password-Reset Tokens
Raw password-reset tokens are not stored in the account database.
A hashed reset token and related timestamps may be retained while the reset request remains active.
A password-reset link ordinarily expires 30 minutes after issuance and may be used only once.
Expired or used reset-token hashes should be deleted or invalidated within 24 hours after expiration or successful use. Limited event metadata may be retained in security logs for up to 12 months.
6.3 Sessions
Session information is retained only for the duration reasonably necessary to maintain the login session, provide requested features, or investigate a security issue.
A session may end through:
- Logout;
- Expiration;
- Password change;
- Account deactivation;
- Account deletion;
- Administrative security action; or
- Invalidated authentication credentials.
Temporary form-security tokens and rate-limit counters are retained only for their operational windows and are not intended to create permanent user histories.
7. BIRTHDAY AND AGE-ELIGIBILITY INFORMATION
The Gregorian birthday entered during signup or a profile update is used to:
- Confirm that the user is at least 16;
- Determine whether the user is under 18; and
- Convert the birthday to the Wickborne calendar.
The raw Gregorian birthday is not intended to be permanently stored in the account database after the conversion and eligibility process is completed.
The resulting Wickborne birthday may be retained while the account is active because it is a requested profile and calendar feature.
Any age-status or minor-status indicator retained for compliance purposes will be limited to what is reasonably necessary and will be deleted with the active account, except for a minimized record that may be retained when necessary to document eligibility, consent, a legal-policy acceptance, a dispute, or compliance with law.
Information belonging to a known user aged 16 or 17 will not be retained for a new or unrelated purpose merely because the information is already available.
8. REVIEWS AND RATINGS
A user's rating and written review may be retained while:
- The user's account remains active;
- The review remains published;
- The user has not requested its removal;
- The review is needed for moderation or investigation; and
- No other deletion requirement applies.
A review removed by the user or administrator will ordinarily be deleted from active systems within 30 days.
When an account is deleted, reviews associated with that account will ordinarily be deleted rather than preserved as anonymous public content.
A removed review may be retained in a restricted record for up to 12 months when reasonably necessary to:
- Investigate fraud or rating manipulation;
- Document harassment or abuse;
- Resolve a moderation appeal;
- Protect another user;
- Enforce the Terms of Use;
- Respond to a rights complaint; or
- Address a security or legal matter.
A review subject to a legal hold may be retained until the hold is released.
9. SOULCANDLE INFORMATION
9.1 Questionnaire Answers
Soulcandle questionnaire answers are processed to create the requested fictional result.
DarienCrute.com does not intentionally save the raw questionnaire answers as part of the user's account after the generation request is completed.
Temporary application memory, request data, technical logs, or service-provider systems may process the answers for the time reasonably necessary to complete, secure, or troubleshoot the request.
Retention by an artificial intelligence service provider is governed by the provider's applicable configuration, agreements, and policies.
9.2 Generated Soulcandle Records
The following may be retained while the account remains active:
- Candle name;
- Epithet;
- Colors;
- Shape;
- Wax and flame descriptions;
- Surface and motion details;
- Traits;
- Tensions;
- Motifs;
- Full and short readings;
- Image path;
- Generated image;
- Generation seed or variation value; and
- Creation and update dates.
These records are retained to display the result on the user's private profile and Soulcandle page.
9.3 Soulcandle Deletion
When a Soulcandle is deleted or its associated account is deleted:
- The active database record will ordinarily be deleted within 30 days;
- The associated image will be removed from active file storage within 30 days;
- Links to the deleted image will be invalidated where technically possible; and
- Backup copies will expire through the normal backup cycle, ordinarily within 90 days.
A user who downloads or independently shares an image creates copies outside DarienCrute.com's control. Deleting the Site's copy does not delete copies saved by the user or shared through a third-party service.
10. CONTACT-FORM SUBMISSIONS
Contact-form submissions may include a name, email address, subject, message, and submission timestamps.
Ordinary contact messages will be retained for no longer than 24 months after:
- The message is received, if no response or follow-up occurs; or
- The final substantive response or related communication, if a conversation occurs.
Messages may be deleted earlier when they are no longer useful.
Messages may be retained longer when they relate to:
- A contract or business transaction;
- A professional engagement;
- A rights complaint;
- A privacy request;
- A legal dispute;
- Harassment or threats;
- Fraud or abuse;
- A security matter; or
- Another documented legal or operational need.
Spam and obvious automated junk submissions may be deleted immediately or retained temporarily for abuse-prevention purposes.
11. SUPPORT, PRIVACY, AND ACCOUNT REQUESTS
Records of support, access, correction, review-removal, consent-withdrawal, and account-deletion requests may be retained for three years after the request is closed.
The retained record should be limited to information reasonably necessary to document:
- The nature of the request;
- Identity-verification steps;
- Actions taken;
- Dates of relevant actions;
- Communications with the requester; and
- The final outcome.
Passwords, authentication links, and unnecessary copies of identity documents must not be included in the retained request record.
When practical, completed request records should be minimized or pseudonymized.
12. POLICY ACCEPTANCE AND CONSENT RECORDS
Records showing acceptance of the Terms of Use, acknowledgment of the Privacy Policy, and any legally required consent may be retained:
- While the account remains active; and
- For seven years after account closure or the user's final interaction governed by the record.
Such records may include:
- Account or internal user identifier;
- Document name and version;
- Date and time of acceptance;
- Acceptance method;
- Limited Internet Protocol or device information;
- Whether the user represented that they were at least 16;
- Whether a 16- or 17-year-old user confirmed parent or guardian permission; and
- Any withdrawal, replacement acceptance, or related dispute.
After account deletion, acceptance records should be minimized or pseudonymized where practical while preserving their evidentiary value.
13. TECHNICAL, SECURITY, AND ABUSE-PREVENTION RECORDS
13.1 Routine Technical Logs
Routine server, access, diagnostic, login, authentication, email-delivery, rate-limit, and security logs may be retained for up to 12 months.
Shorter periods should be used when the information is no longer useful for:
- Security monitoring;
- Troubleshooting;
- Fraud prevention;
- Service reliability;
- Abuse prevention; or
- Investigation of unauthorized access.
13.2 Moderation and Abuse Records
Records concerning spam, fraudulent accounts, review manipulation, threats, harassment, repeated Terms violations, or attempted security abuse may be retained for up to three years after the matter is closed.
Records may be retained longer when the conduct is serious, repeated, subject to legal proceedings, or reasonably likely to create an ongoing safety or security risk.
13.3 Security Incidents and Breach Records
Security-incident and breach-response records may be retained for seven years after the incident is closed.
These records may include:
- Incident reports;
- Investigation notes;
- System evidence;
- Notifications;
- Risk assessments;
- Remediation records;
- Communications with service providers;
- Communications with affected users;
- Reports to government agencies; and
- Written determinations concerning whether notification was required.
Access to incident records will be restricted according to role and need.
14. EMAIL RECORDS
Transactional email content and delivery records may be retained only as long as reasonably necessary to:
- Deliver the message;
- Confirm delivery;
- Troubleshoot failures;
- Respond to a user;
- Investigate account security;
- Document a policy notice;
- Establish that a request was completed; or
- Meet a legal obligation.
Ordinary delivery metadata may be retained for up to 12 months.
Copies held by an email service provider may be subject to the provider's own retention schedule and contractual obligations.
DarienCrute.com does not use account email records to build advertising profiles.
15. BACKUPS
Backups may contain copies of information that has been deleted from active systems.
Restricted backups will be maintained for disaster recovery, system restoration, security, and business-continuity purposes.
Unless a legal hold or exceptional recovery need applies:
- Backup copies containing deleted personal information will ordinarily be overwritten or expire within 90 days;
- Deleted information in backups will not be restored to ordinary active use;
- If a backup restoration reintroduces previously deleted information, the deletion will be reapplied within a reasonable period; and
- Access to backups will be limited to authorized persons and systems.
Backups are not to be used as permanent archives of deleted user information.
16. SERVICE PROVIDERS
Service providers may retain information for periods established by:
- Their service function;
- DarienCrute.com's configuration;
- Contractual requirements;
- Security and abuse-monitoring needs;
- Backup cycles; or
- Applicable law.
DarienCrute.com will make reasonable efforts to:
- Select service providers with appropriate retention and deletion practices;
- Configure provider retention settings consistently with this policy where available;
- Limit the information transmitted to providers;
- Require deletion or return of information when services end, where appropriate;
- Review changes to provider practices; and
- Apply appropriate protections when a provider processes information belonging to a known user under 18.
A provider may retain limited information after DarienCrute.com requests deletion when independently required by law or permitted under an applicable agreement and disclosed policy.
17. LEGAL HOLDS AND EXTENDED RETENTION
Information scheduled for deletion may be retained longer when reasonably necessary to:
- Comply with a court order, subpoena, warrant, or other lawful request;
- Preserve evidence relating to threatened or pending litigation;
- Investigate fraud, abuse, unauthorized access, or a security incident;
- Protect the rights, safety, or property of users or others;
- Enforce the Terms of Use;
- Resolve a payment, contract, copyright, privacy, or other legal dispute;
- Meet tax, accounting, insurance, or business-record obligations;
- Demonstrate legal or regulatory compliance; or
- Establish, exercise, or defend a legal claim.
A legal hold must be limited to information reasonably related to the matter.
When the reason for extended retention ends, the information will return to its ordinary retention schedule and be deleted, destroyed, or deidentified within a reasonable period.
18. DELETION AND DISPOSAL METHODS
Depending on the system and record type, deletion may include:
- Deleting a database record;
- Removing an uploaded or generated file;
- Invalidating a token or session;
- Removing information from an administrator interface;
- Overwriting a backup through its normal cycle;
- Securely erasing electronic media;
- Cryptographically destroying access to encrypted information;
- Deidentifying or aggregating a record;
- Shredding a paper record; or
- Instructing a service provider to delete or return information.
Deletion methods should be reasonable in light of:
- The sensitivity of the information;
- The available technology;
- The cost and feasibility of deletion;
- The risk of reconstruction;
- The system involved; and
- Applicable legal requirements.
Information will not be represented as fully deleted while it remains knowingly available for ordinary active use.
19. DEIDENTIFIED AND AGGREGATED INFORMATION
DarienCrute.com may retain information that has been deidentified or aggregated so that it cannot reasonably be linked to an identifiable user.
Examples may include:
- Total numbers of accounts;
- Aggregate review ratings;
- General feature-usage counts;
- Error-frequency statistics;
- Non-identifying performance measurements; and
- General security trends.
Deidentified information must not be intentionally reidentified except when necessary to test whether the deidentification process remains effective or when required by law.
20. USERS AGED 16 OR 17
Information belonging to a known user aged 16 or 17 will follow the same maximum retention periods stated in this policy, but shorter retention will be used when the information is no longer strictly necessary for the requested service, security, legal compliance, or another permitted purpose.
DarienCrute.com will not extend the retention of a minor user's information for advertising, unrelated profiling, data brokerage, or another nonessential purpose.
A user's information does not lose its protected history merely because the user later turns 18. Records collected while the user was a minor remain subject to the commitments and lawful purposes that applied when they were collected, unless the user later provides a legally valid new instruction or consent.
21. RETENTION RESPONSIBILITY AND REVIEW
Darien Cruté is responsible for overseeing this policy unless responsibility is formally assigned to another authorized person.
Retention practices will be reviewed:
- At least annually;
- When a material Site feature is introduced;
- When a new category of personal information is collected;
- When a new service provider is adopted;
- After a significant security incident;
- When applicable law materially changes; or
- When existing periods no longer reflect operational needs.
The review should evaluate:
- What information is being collected;
- Where it is stored;
- Who can access it;
- Why it is retained;
- Whether the retention period remains necessary;
- Whether deletion procedures work as intended; and
- Whether the public Privacy Policy remains accurate.
22. CHANGES TO THIS POLICY
We may update this Data Retention Policy to reflect:
- Changes to Site features;
- Changes to collected information;
- Changes to service providers;
- Improved deletion capabilities;
- Security developments;
- Operational changes; or
- Changes in applicable law.
The version number, effective date, and last-updated date will identify the current policy.
Material changes that significantly extend retention or change how user information is handled may be communicated through the Site, account notices, email, or another reasonable method.
Where required, a new consent or acknowledgment will be obtained before information is retained for a materially different nonessential purpose.
23. CONTACT
Questions or requests concerning data retention or deletion may be directed to:
Darien Cruté
Website: DarienCrute.com
Email: support@dariencrute.com
Subject Line: Data Retention Request
Do not send passwords, authentication links, financial information, government identification numbers, or other highly sensitive information by email.