Vizno · Compliance

Data Retention and Deletion Policy

Effective 2026-05-16Version 1.0Owner: Marc DeForest

Retention periods by data class, deletion mechanism, legal-hold exceptions, user rights, and annual review cadence.

1. Purpose

This policy describes how Vizno retains personal information and other regulated data, how long each category is kept, the basis for those retention periods, and the mechanisms by which data is deleted. It implements the retention commitments stated in the Vizno Privacy Policy and is intended to satisfy applicable data-protection law (including GDPR Article 5(1)(e), CCPA / CPRA, and US state privacy laws) and the recordkeeping expectations of Vizno's banking, payment, and identity-verification partners.

2. Scope

This policy applies to all personal information processed by Vizno LLC in connection with the Vizno platform (vizno.com), including data collected from players, creators, reseller-program participants, and visitors; data collected automatically; and data received from third parties acting on Vizno's behalf.

3. Retention principles

  • Vizno retains personal information only for as long as is necessary to provide the Service, comply with legal obligations, resolve disputes, and enforce agreements.
  • Retention periods are set by data class and are derived from one of: (a) operational need, (b) legal or regulatory requirement, or (c) contractual obligation to a partner.
  • Where the law mandates a longer or shorter period than operational need would suggest, the legal requirement controls.
  • Aggregated or de-identified data that cannot reasonably be linked to an individual is not subject to retention limits.

4. Retention schedule

The following retention periods apply. Where a range or condition is specified, the longer applicable period governs.

Data class Examples Retention
Account data Email, hashed password, display name, profile Life of account; deleted within 30 days of account deletion
Player save data In-game progress, choices, preferences Life of account; deleted within 30 days of account deletion
Authoring content (creators) Projects, scripts, uploaded assets, Aldus AI conversation history Life of account; deleted within 90 days of account deletion
Bank / payout PII Plaid-returned routing and account numbers, Plaid item identifiers, holder name and address Encrypted at the application layer; deleted within 30 days of the creator removing the payout method or closing the account, subject to the financial-records retention below
Identity / KYC artifacts Tax forms (W-9 / W-8BEN), identity-verification documents, age-verification artifacts Retained for the period required by applicable tax and recordkeeping law (typically 7 years from the tax year of last activity)
Financial records Payout records, transaction history, chargeback evidence Retained for 7 years from the date of the transaction (tax and merchant-recordkeeping requirements)
Operational logs Application logs, security event log, request traces 90 days for general logs; up to 1 year for security-relevant events
Backups Encrypted Postgres dumps Daily backups retained for a minimum of 14 days, then expired
Support correspondence Inbound email, in-product reports, case threads 3 years from case closure
Aggregated / de-identified Aggregate analytics, anonymized usage counts May be retained indefinitely

5. Deletion mechanism

Users may request deletion of their account at any time through the account settings page or by emailing privacy@vizno.com. Account deletion triggers the following process:

  • Identity is verified against the requesting account (typically by confirming control of the registered email address).
  • The account enters a soft-deleted state, during which sign-in is disabled and the account is invisible to other users. This grace period is 14 days and exists to allow recovery from inadvertent or unauthorized deletion requests.
  • At the end of the grace period, hard deletion runs across all data classes per the retention schedule above. Data subject to legal-hold or financial-records retention is migrated to a restricted-access archive and is excluded from active systems.
  • Backups containing the deleted data are not selectively scrubbed; they expire on the normal backup-rotation schedule (14-day retention), at which point the data is no longer recoverable from backup.
  • Where data is held by a subprocessor (for example, Plaid, Increase, Payoneer, Resend, Anthropic, Cloudflare, Hetzner), Vizno issues a deletion instruction to the subprocessor through the mechanism made available by that subprocessor. Subprocessor retention is governed by the subprocessor's own policies and any contractual data-processing terms.

6. Legal-hold and exceptions

Data otherwise eligible for deletion may be retained beyond its scheduled period when:

  • Vizno has a legal obligation to preserve it (litigation hold, regulatory inquiry, subpoena, or tax recordkeeping requirement).
  • It is required to detect, investigate, or respond to fraud, security incidents, or policy violations.
  • It is the subject of an ongoing payment dispute, chargeback, or sanctions-screening matter.

When the basis for the hold ends, the data resumes the normal retention schedule and is deleted at the next applicable expiration.

7. User rights

Subject to applicable law, users may request access to, correction of, portability of, or deletion of their personal information. Requests are submitted to privacy@vizno.com and are responded to within the timeframes required by the relevant law (typically 30 to 45 days). Vizno may extend response times where permitted and will inform the user of the extension and its basis.

8. Subprocessors

Vizno's principal subprocessors holding regulated data include: Hetzner (compute and database hosting), Cloudflare (DNS, edge, and object storage), Plaid (bank verification for creator payouts), Increase (US ACH payment processing), Payoneer (international payment processing), Resend (email delivery), and Anthropic (AI authoring assistance for creators). Each subprocessor is engaged under terms requiring it to use Vizno data only as needed to provide the contracted service.

9. Review and enforcement

  • This policy is reviewed at least annually by the founder and updated to reflect changes to the platform, the subprocessor list, or applicable law. Material changes are recorded with a revision date.
  • Deviation from the retention schedule must be authorized by the founder and documented in writing.
  • Adherence is verified through periodic audit of database age distributions, backup-rotation logs, and deletion-request handling.

10. Contact

Questions about this policy, retention practices, or to exercise a data-subject right, contact privacy@vizno.com.