Last updated 3 September 2026
This schedule explains when Beacon deletes or de-identifies information. Shorter deletion can happen when you remove content, close your account or make a valid information-rights request.
Version 2026-09-03
How to read this schedule
A period is a maximum for the stated purpose, not a promise to keep information for that long. Automated cleanup runs in bounded background batches, so an expired record may take a short time to disappear from storage but cannot become newly visible during that process.
Where deletion would break a conversation, Beacon keeps an empty tombstone instead of the original content. Anonymous statistics cannot be used to identify an account and are not personal account history.
Account and profile
- What this covers
- Sign-in details, profile fields, preferences and profile media.
- How long
- While the account remains open.
- What happens next
- Account deletion removes the live account, profile, ordinary social records and content created by the member. A still-open Alert request is detached and de-identified instead of being abandoned.
- Accountable owner
- Privacy Lead
- Exceptional holds
- A valid legal obligation or claim may require a restricted record to remain; the member is told when the law permits.
Posts, replies and direct communications
- What this covers
- Post text, audience, conversation links and processed images.
- How long
- Until the author or Beacon deletes it. Processed media is removed at deletion; remaining soft-deleted text is erased within 30 days.
- What happens next
- The database keeps only a blank tombstone where conversation integrity requires the post row to exist. Account deletion removes authored rows completely.
- Accountable owner
- Community Safety Lead
- Exceptional holds
- A documented legal, safeguarding or security hold can pause deletion for the specific record. The Privacy Lead reviews the purpose and end date.
Post edit record
- What this covers
- Edit time and the member-selected reason for editing.
- How long
- While the post remains available, or until deleted-post text is erased after 30 days.
- What happens next
- Beacon replaces the wording in place and never stores the previous version. Reason-only records are removed when the deleted post is scrubbed or the post is hard-deleted.
- Accountable owner
- Community Safety Lead
- Exceptional holds
- A documented legal, safeguarding or security hold can pause deletion for the specific record. The Privacy Lead reviews the purpose and end date.
Scopes
- What this covers
- Scope media, text, layout, views, likes, promotions and delivery state.
- How long
- 48 hours from publication.
- What happens next
- The Scope and dependent records are hard-deleted. Its processed media is placed in a retryable deletion queue. An expired Scope cannot be viewed even if cleanup is briefly delayed.
- Accountable owner
- Product Operations
- Exceptional holds
- Not extended by a routine hold.
Relationships and private controls
- What this covers
- Follows, likes, reposts, bookmarks, blocks and mutes.
- How long
- Until undone, the target is removed, or either relevant account is deleted.
- What happens next
- Rows are removed with their account or content target. Completed follow-suggestion dedupe records expire after one year; unprocessed suggestions expire after 30 days.
- Accountable owner
- Product Operations
- Exceptional holds
- Not extended by a routine hold.
In-app notifications
- What this covers
- Notification type, sender, recipient, target and read time; data-light global Beacon Alert notices.
- How long
- Ordinary notifications: 90 days. Data-light global Beacon Alert notices: 365 days.
- What happens next
- Expired rows and read receipts are deleted in bounded background batches. The Alert lifecycle audit is separate from the notification inbox.
- Accountable owner
- Product Operations
- Exceptional holds
- Not extended by a routine hold.
Reports and moderation
- What this covers
- Report reason and note, target, outcome, staff action and posting restrictions.
- How long
- Open cases remain while investigated. Closed reports and completed moderation actions are kept for 730 days. An active posting restriction keeps its supporting action.
- What happens next
- Closed cases are hard-deleted after the period unless a record-specific hold applies. Content and account references may be detached sooner.
- Accountable owner
- Community Safety Lead
- Exceptional holds
- A documented legal, safeguarding or security hold can pause deletion for the specific record. The Privacy Lead reviews the purpose and end date.
Published Beacon Alerts
- What this covers
- Active missing-person details and image, restricted coordination details, status and field-name-only audit.
- How long
- Identifying information remains only while the Alert is active. The de-identified outcome and field-name-only audit remain until an administrator removes the Alert.
- What happens next
- Resolution immediately removes names, narrative, location, police details, private coordination data and the public image from live systems. Media deletion is retryable and monitored.
- Accountable owner
- Beacon Alert Lead
- Exceptional holds
- A hold must not keep unnecessary identifying information public. Any restricted preservation is decided and documented case by case.
Beacon Alert requests and evidence
- What this covers
- Candidate details, requester contact, evidence, review messages and lifecycle audit.
- How long
- Unfinished requests expire after 90 days without activity. On approval, rejection or merge, candidate/contact/evidence data is removed immediately; review-message text is erased within 90 days and the remaining case record after 730 days.
- What happens next
- Evidence files enter a monitored deletion queue. Minimal lifecycle fields can remain during the stated case period without the candidate narrative or contact details.
- Accountable owner
- Beacon Alert Lead
- Exceptional holds
- A documented legal, safeguarding or security hold can pause deletion for the specific record. The Privacy Lead reviews the purpose and end date.
Digital Field of Remembrance
- What this covers
- Tribute, remembered name, submitter/contact details and moderation outcome.
- How long
- Published tributes remain until the submitter account or an administrator removes them. Contact details are erased 30 days after review. Rejected submissions are deleted after 30 days; unanswered pending submissions after 90 days.
- What happens next
- Removing a tribute also removes its related notifications. Imported/public tribute text remains only while the tribute is published.
- Accountable owner
- Remembrance Editor
- Exceptional holds
- A documented legal, safeguarding or security hold can pause deletion for the specific record. The Privacy Lead reviews the purpose and end date.
Sessions, devices and MFA
- What this covers
- Hashed session/device identifiers, broad browser description, MFA challenges and used recovery-code hashes.
- How long
- Sessions and MFA challenges are deleted after expiry. Used recovery-code hashes remain 30 days. Administrator device-recognition rows expire after 365 days without use.
- What happens next
- Signing out or revoking a device removes its session earlier. Disabling MFA removes its credentials and remembered devices.
- Accountable owner
- Security Lead
- Exceptional holds
- Not extended by a routine hold.
First-party usage statistics
- What this covers
- One member/day/coarse-platform activity row and anonymous daily totals.
- How long
- Member-level activity: eight days. Anonymous daily totals: retained for trend reporting because they cannot be linked back to a member.
- What happens next
- Opting out or deleting the account erases recent member-level rows immediately. Beacon records only Android, iOS, web or other—not routes, content, searches, IP addresses or device identifiers.
- Accountable owner
- Product Operations
- Exceptional holds
- Not extended by a routine hold.
Email, push and background delivery
- What this covers
- Delivery jobs, retry state, suppression outcome codes and data-light provider event evidence.
- How long
- Completed/failed email jobs: 30 days. Sent/failed catch-ups: 90 days; cancelled catch-ups: 30 days. Push events: 7 days. Data-light Postmark callback records: 180 days.
- What happens next
- Expired queue rows are deleted automatically. Media-deletion jobs remain only until the file is safely removed, because discarding a failed deletion job could orphan member media.
- Accountable owner
- Product Operations
- Exceptional holds
- Not extended by a routine hold.
Support and information-rights cases
- What this covers
- The request, identity checks, correspondence, decision and completion evidence held in the approved mailbox/case record.
- How long
- Routine correspondence: 12 months after closure. A formal complaint, legal claim or statutory record may be retained for up to six years when necessary.
- What happens next
- The Privacy Lead reviews closed cases monthly and removes unnecessary correspondence. A longer period requires a documented purpose and review date.
- Accountable owner
- Privacy Lead
- Exceptional holds
- A documented legal, safeguarding or security hold can pause deletion for the specific record. The Privacy Lead reviews the purpose and end date.
Operational logs
- What this covers
- Allow-listed service events, release identity, aggregate counts, latency and error codes. Beacon excludes message bodies, emails, URLs, account/session IDs, media keys, IP addresses and stack traces.
- How long
- Live container logs use a rolling 50 MB maximum per service instance rather than indefinite storage.
- What happens next
- The oldest local log segments are rotated automatically. Any restricted incident extract must have its own documented purpose and deletion date.
- Accountable owner
- Security Lead
- Exceptional holds
- A security or legal incident may require a minimal restricted extract; the owner records a review and deletion date.
Backups and deleted accounts
- What this covers
- Database, roles and processed-media recovery copies.
- How long
- Supported backup sets carry a deletion date no later than 30 days after creation.
- What happens next
- Deletion takes effect in live systems first. Backup data is not restored into ordinary use; if a restore is required, deletions and expiries must be replayed before service returns. On-host and off-host copies are reviewed against the same deletion date.
- Accountable owner
- Infrastructure Lead
- Exceptional holds
- A hold requires a separately restricted, documented copy and cannot be used to republish deleted information.
Deletion requests and backup copies
Account deletion takes effect in Beacon's live systems first and cannot be undone. Backup copies are isolated from routine use and expire under the schedule above. If a backup must be restored after an incident, Beacon must replay account deletions, content deletions and time-based expiry before reopening the service.
For a correction, export, restriction or erasure request, email [email protected]. The Privacy Notice explains your rights, and the Right to Be Forgotten standard explains the stricter handling of missing-person information.