RECORD RETENTION POLICY

Data Retention & Deletion Schedule

A precise breakdown of our automated location data deletion cron jobs and database purging policies.

Core Rule: We Don't Keep History

Unlike legacy trackers that archive years of your location history to build demographic consumer profiles, NudgePanda strictly logs coordinates only as long as necessary to trigger safety check-ins and Crew alerts. All historical movements are automatically and permanently expunged.

Data CategoryRetention PeriodPurge Mechanism
Geofence Crossing Logs15 DaysAutomated SQL purge query executed every 24 hours.
SOS Event Metadata15 DaysPermanently deleted 15 days following the resolution of the SOS alert.
Active Geofencing ConfigsIndefinite (Active Only)Active boundaries remain stored. Purged immediately if deleted by user.
Database System Backups15 Days MaximumEncrypted backup tapes are completely rotated and overwritten every 15 days.
User Account Data0 Days (Instant Deletion)Cascading database trigger immediately wipes all profiles, settings, and logs.

Technical Implementation Details

PostgreSQL Cron Purging

We configure database-level triggers to execute a delete query on coordinates older than 15 days:DELETE FROM location_pings WHERE created_at < NOW() - INTERVAL '15 days';

Cascading User Wipes

When you initiate account deletion from the app, PostgreSQL triggers a cascade constraint:ON DELETE CASCADE;This ensures no orphaned coordinates, keys, or log files survive on our nodes.