Back to Home

Aphelion Pvt. Ltd.

Data Retention & Deletion

Effective Date: May 24, 2026

1. Introduction

This Data Retention and Deletion Policy details how long Aphelion Pvt. Ltd. retains your personal data, content uploads, message history, and server logs. We design our platform around data minimization principles, keeping your data only for as long as necessary to provide our services, maintain security, or fulfill legal obligations.

2. Account Lifecycle and Deletion

The retention timeline for account data is structured as follows:

  • Active Accounts: All profile fields, credentials, and content are stored securely while your account remains active.
  • Self-Initiated Deletion: Deleting your account is permanent once confirmed in the app. Your authentication account, profile, posts, messages, saved items, fitness data, Poses records, and related active database rows are removed immediately, and owned media objects are queued for backend deletion from active Cloudflare R2 storage. This self-service deletion cannot be restored by logging back in.
  • Banned Accounts: If your account is deactivated/banned for violating our guidelines, we may preserve limited account and moderation records for a 30-day appeal window. Once this window closes, remaining active account data is purged unless subject to a law enforcement hold, child-safety investigation, fraud-prevention obligation, or other legal requirement.
  • Law Enforcement Holds: Data subject to a valid court summons, warrant, preservation request, or child safety investigation is retained indefinitely for as long as legally required, overriding any user deletion request.

3. User-Created Content and Media Files

Timelines for posts, comments, media, and tracks:

  • Post Deletion: If you delete an individual post (Lines, Planes, Dots, Poses, Wrex workout), it is permanently and immediately deleted from all platform feeds and databases.
  • Media Files: When a post containing media is deleted, the corresponding photos or video objects stored in Cloudflare R2 are queued for permanent backend deletion from active media storage. We do not maintain offsite recycling bins for deleted user media.
  • Comments: Comments are permanently deleted immediately upon your deletion request.
  • Bloom Mode (Rays): Deleting an educational Ray immediately removes it from tag listings, search indexes, and active sessions.
  • AI and Poses Records: Poses uploads, saved Poses photos, AI suggestion metadata, model proof records, quota records, and Poses reports are deleted or anonymized according to the same account, safety, and legal-hold rules described here.

4. Messages and Chat Histories

  • Individual Message Deletion: Deleting a sent direct message deletes its text content immediately. The conversation list will display a "Message deleted" tombstone UI placeholder, which retains none of the original text.
  • Account Deletion: When an account is permanently deleted, all message content sent by you is purged. Conversation placeholders in other users' chat lists may remain to maintain the layout integrity of their history.
  • Hidden or Locked Chats: Chat locks (biometrics) or hidden flags are client-level display flags and are stored on our servers only as preferences. They are permanently wiped when your account is deleted.
  • Guest Sessions, Threads, and Private Shelves: Temporary guest-session messages expire with the session unless preserved under the app's explicit retention rules. Living thread and private shelf records preserve only the user's chosen saved snapshots and never override view-once or view-twice media limits.

5. App Store and Google Play Data Categories

For store privacy labels and data-safety disclosures, Maleu collects or processes at least the following categories while an account is active:

  • Account data: email, user id, username, display name, profile data, authentication records, and settings.
  • User content: posts, chat messages, comments, Bloom/Wrex/Poses content, saved items, reports, reactions, and moderation records.
  • Photos, videos, audio, and files: camera captures, uploads, profile/circle/post/chat/Poses media, and voice or video audio when enabled.
  • Location: Wrex run/walk route tracking and optional one-time location sharing in chat.
  • Fitness and wellness: workouts, run/walk metrics, pace, speed, elevation, routes, diet, meals, hydration, progress, and streaks.
  • Notifications: push tokens, preferences, notification records, delivery logs, and read state.
  • AI-related data: Poses uploaded image input, generated suggestion metadata, model/provider proof rows, usage quota records, and AI report records.
  • Diagnostics and security: auth/session records, device/app version signals, abuse-prevention counters, admin audit logs, crash/error/upload logs, and security events where applicable.

6. System Logs and Backups

To ensure system integrity, audit safety, and crash diagnostic capability, we retain structural log files under the following strict retention schedules:

  • Supabase Automated Backups: Database snapshots and system transaction logs are preserved securely for 30 days.
  • Cloudflare Media & CDN Logs: Object storage transactions, security gateway events, and media transfer logs are purged after 7 days.
  • Internal Crash & Diagnostic Logs: Technical error traces, app crash stack traces, and database connection failures logged through our custom monitoring system are kept for 30 days.

7. Contact Information

For manual data export requests, access questions, or data correction requests under the DPDPA 2023, please contact our designated Grievance Officer, Dharantej Reddy Poduvu, at fuy.aphelion@gmail.com. Manual export requests are processed within 15 working days.

Privacy PolicyTerms of Service

© 2026 Aphelion Pvt. Ltd. All rights reserved.