infra/docs/automated-account-deletion.md

928 B

Automated account deletion

Per GDPR legislation, accounts should be automatically deleted after a period of inactivity. We discern between two different types of accounts:

  1. Without verified email: should be deleted after 30 days without being activated
  2. With verified email: should be deleted after 2 years of inactivity

Some services hold on to a session for a very long time. We'll have to query their APIs to see if the account is still in use: