Eclipser

Authoritative plain-text version — that document is the binding one; this page renders the same text for reading.

Eclipser Account Deletion and Retention Schedule

Controller and product support: Huzk Ltd

Effective date: 2026-08-10

> Draft: This copy is not ready for Chrome Web Store submission until the brand, support details, and permanent privacy URL are complete.

How to request deletion

Open Account → Access or delete account data in the installed extension, choose

Delete, and complete the one-time code sent to the account e-mail address. A verified

request immediately restricts the account and revokes active devices while the evidenced

deletion workflow runs. If the in-product route is inaccessible, use the verified support

channel: <https://eclipser.app/support>. Never send card numbers, security codes, passwords, licence

JWTs, or one-time codes to support.

What the workflow deletes

The local workflow erases the subject's live Eclipser customer, licence, device,

promotion, authentication, Checkout, and related account rows when no scoped legal hold

blocks that step. Appearance settings and site profiles remain in local browser storage

and Chrome Sync, if enabled; clear them separately in the extension or browser. Stripe

and Link hold their own Managed Payments records and accept provider privacy requests

through the [Stripe Privacy Portal](https://privacy.stripe.com/privacy/home).

Eclipser never claims that local erasure deleted provider records.

Completion is withheld until the live-store erasure, applicable Cloudflare backup-ageing

receipt, and required Stripe/Link provider notice are each evidenced. An active legal hold

shows its category, review time, and case-specific end time in the request status.

Retention schedule in this source build

  • The verification code is usable for 10 minutes; an expired code row is removed by the
  • next daily maintenance pass.

  • A short-lived chunked export bearer, when used before deletion, expires after
  • 15 minutes and is removed by daily maintenance.

  • Cloudflare D1 Time Travel can retain a pre-erasure database state for no more than
  • 30 days in the production contract; completion waits for the applicable ageing proof.

  • The independently verified deletion-journal checkpoint is deleted 180 days after
  • authorization by daily cleanup and the matching R2 prefix lifecycle rule.

  • Admin audit and safely sealed recovery-snapshot evidence are deleted after 180 days.
  • Open, failed, or incomplete recovery incidents have no blind calendar expiry; they are

    retained until safely sealed, then their 180-day clock starts.

  • Minimized Checkout recovery contracts are kept for 30 days. Webhook-integrity and
  • erased-identity anti-resurrection records can be kept for up to 400 days under the

    current production contract. Billing-review history is kept for 180 days.

  • Stripe/Link and other processors apply their own legal and operational schedules.
  • The D1 deletion request, step, and event history does not yet have an owner-approved

    fixed destruction period in this draft. Therefore retentionSchedulePublished must stay

    false, and this page must not be presented as submission-ready, until Huzk Ltd records the

    legal decision, implements its cleanup, and verifies the permanent public page byte for

    byte against this tracked source.

    Privacy policy: <https://eclipser.app/privacy>

    Support: <https://eclipser.app/support>