Controlled-beta draft · owner and legal review required before public launch
Retention and Deletion Policy
Crown Inspect keeps Crown Studio 3D information only for an identified service, security, support, contractual, or legal purpose. A documented legal, security, abuse, fraud, or dispute hold may temporarily override a normal deletion period.
| Information | Default period | Normal deletion behaviour |
|---|---|---|
| Incomplete or abandoned upload | Up to 24 hours | Automatic expiry and removal from active storage |
| Source photographs submitted to processing | Until the job succeeds, fails, or is cancelled | Removed from active processing storage at terminal cleanup |
| Free Beta results and recoverable job session | 7 days after successful completion | Automatic removal; download before expiry |
| Creator results and recoverable job session | 30 days after successful completion | Automatic removal; download before expiry |
| Pay-as-you-go results, if introduced | 14 days after successful completion | Automatic removal; download before expiry |
| Failed or cancelled job artifacts | Removed promptly; no later than 24 hours | Temporary input and output directories are removed |
| Unused queued job authorization | 24 hours | Cancelled and its reserved processing credit restored |
| Account, tenant, project, and active session records | While the account or project remains active | In-product deletion removes primary records and confirms hosted processing-file deletion first |
| Security, service, and audit logs | Up to 90 days unless legitimately required longer | Rotation and secure expiry |
| Encrypted application backups | Maximum 35 days | Encrypted backup rotation and repository pruning |
| Support correspondence | Up to 24 months after the matter closes | Deletion unless needed for an unresolved matter |
| Payment, invoice, tax, refund, and fraud records | As required for legal, tax, and accounting obligations | Deleted or de-identified when the obligation ends |
Project and account deletion
A signed-in user can delete an individual project or the whole account when no processing job is active. The service first requests deletion of matching hosted uploads, temporary files, results, and processing sessions. Only after that deletion is confirmed does it remove the project or account database record. If processing storage is unavailable or deletion cannot be confirmed, the operation fails closed and keeps the account record so the user is not falsely told that the content was deleted.
The target for a supported account-deletion request is completion in primary systems within 7 days. Copies in encrypted backups expire through normal rotation within 35 days. Files already downloaded to a user’s device are outside Crown Inspect’s control.
Deployment verification
These are the approved controlled-beta periods. Before this draft is treated as the live production policy, Crown Inspect must verify the deployed cleanup schedule, 90-day log rotation, encrypted off-site backup pruning at 35 days, and a documented restore test. A hosting provider’s whole-server recovery backup is separate from the encrypted application backup and must be included in that verification.
Requests and questions
Use the in-product deletion controls or email info@crowninspect.ca with the subject “Privacy request.” We may verify identity and will explain any lawful exception to deletion.