University of Strathclyde Sport

Data Retention Policy

Last updated: July 2026  ·  Next review: June 2027

This policy sets out how long each category of personal data collected by Strath Steps is retained, and the process by which it is deleted. It supplements our Privacy Notice.

Retention by data category

Data categoryRetention periodDeletion process
Account profile (email, display name)Until user-initiated deletion, or automatically after 7 years of account inactivity per University of Strathclyde retention policyUser-initiated: immediate via Profile settings. Automatic: scheduled for future implementation.
Step and activity logs (manual entries)Same as account profileDeleted via CASCADE when account is deleted
Synced fitness device dataSame as account profileDeleted via CASCADE when account is deleted
OAuth tokens (fitness device connections)Until disconnected or account deletedRevoked with provider and deleted immediately on disconnect
Team membershipUntil account deletion or leaving teamDeleted via CASCADE when account is deleted
Badge and challenge recordsSame as account profileDeleted via CASCADE when account is deleted
Audit logs (security events)Indefinite, user reference removed on account deletionuser_id set to null on deletion; event record retained for security and compliance purposes
Page view analyticsIndefinite, user reference removed on account deletionuser_id set to null on deletion; aggregate counts retained
Sentry error logsPer Sentry's standard retention (90 days on current plan)Automatically expired by Sentry; no manual process required

Key points

  • Users can delete their own account at any time via Profile settings. Deletion is immediate, irreversible, and removes all personal data via database constraints and a dedicated deletion function.
  • Per University of Strathclyde data retention policy, accounts are also subject to automatic deletion after 7 years. This automated process is not yet implemented in the application and is tracked as an outstanding development item ahead of public launch.
  • Two categories of data outlive account deletion by design: audit logs and page view analytics. In both cases, the user reference is removed on deletion, meaning the record can no longer be linked back to the individual — this is retained anonymous, aggregate data for security monitoring and usage analytics, not personal data under GDPR once the identifying link is removed.
  • Sentry error data follows Sentry's own retention schedule rather than ours, since it is a third-party processor. No intentional personal data is sent to Sentry.

For questions about this policy, contact the University's Information Governance Unit at dataprotection@strath.ac.uk.