Last updated: July 2026 · Next review: June 2027
This policy sets out how long each category of personal data collected by Strath Steps is retained, and the process by which it is deleted. It supplements our Privacy Notice.
| Data category | Retention period | Deletion process |
|---|---|---|
| Account profile (email, display name) | Until user-initiated deletion, or automatically after 7 years of account inactivity per University of Strathclyde retention policy | User-initiated: immediate via Profile settings. Automatic: scheduled for future implementation. |
| Step and activity logs (manual entries) | Same as account profile | Deleted via CASCADE when account is deleted |
| Synced fitness device data | Same as account profile | Deleted via CASCADE when account is deleted |
| OAuth tokens (fitness device connections) | Until disconnected or account deleted | Revoked with provider and deleted immediately on disconnect |
| Team membership | Until account deletion or leaving team | Deleted via CASCADE when account is deleted |
| Badge and challenge records | Same as account profile | Deleted via CASCADE when account is deleted |
| Audit logs (security events) | Indefinite, user reference removed on account deletion | user_id set to null on deletion; event record retained for security and compliance purposes |
| Page view analytics | Indefinite, user reference removed on account deletion | user_id set to null on deletion; aggregate counts retained |
| Sentry error logs | Per Sentry's standard retention (90 days on current plan) | Automatically expired by Sentry; no manual process required |
For questions about this policy, contact the University's Information Governance Unit at dataprotection@strath.ac.uk.