1. Retention principle
We retain information for as long as reasonably necessary to operate the service, provide requested reports and history, maintain security and abuse controls, meet accounting or legal obligations, resolve disputes, and enforce our agreements. We review retention as product capabilities change.
2. Current record categories
- Account and access records: retained while an account is active and for a limited period afterward where needed for security, fraud prevention, support, or legal obligations.
- Campaign, wallet, Sybil, and ScamGuard analysis records: retained while the associated account, project, report, or paid access remains active so users can review evidence, exports, decisions, and historical context.
- API keys, usage, and webhook delivery records: retained while the integration is active and afterward as needed for debugging, rate-limit enforcement, security review, billing, and dispute handling. API key material is stored as a hash rather than a recoverable plaintext value.
- Telegram Guardian records: retained while a group is connected and for a limited operational period after removal or disablement to investigate alerts, abuse, and delivery issues.
- Payment and subscription references: retained as necessary for payment verification, access entitlements, accounting, tax, security, and legal recordkeeping.
- Security logs and feedback: retained for as long as reasonably necessary to protect the service, investigate false positives or missed risk, and improve detection integrity.
3. Current product state
Automated self-service deletion schedules are not yet available for every record type. Until they are, records are handled through account controls and verified support requests rather than a promise of instant, universal erasure. We do not preserve an original CSV as a standalone file merely to keep it; related analysis records may remain until deletion or the retention need ends.
4. Deletion requests
To request account or data deletion, contact info@triproofprotocol.com from your account email and describe the record or project involved. We may request identity verification. Deletion may remove access to reports, credits, API configuration, group history, and related product functionality. We may retain minimal information where necessary for legal obligations, security, fraud prevention, audit trails, or to complete a request already in progress.
5. Backups and de-identification
Deleted information may persist in encrypted backups for a limited operational cycle before being overwritten. Where practical, we may de-identify or aggregate records so they can support reliability and security improvements without remaining linked to a specific account.
6. Enterprise agreements
Enterprise or B2B customers may require a separate retention schedule, data-processing agreement, or deletion workflow. A signed agreement controls if it conflicts with this public policy.