Local data remains until you delete it in the app, clear app data, or uninstall
the app. After our secure servers accept a new album manifest, crops that are no longer
referenced are normally scheduled for deletion after a safety window of at
least 24 hours. Temporary service failures may delay physical deletion; cached
copies and copies already downloaded to a phone or watch are not remotely
revocable. There is currently no user-facing self-service deletion API. Contact
support to request deletion of the remaining album data stored on our secure
servers and provide the information necessary to verify the request.
Mainland account, order, entitlement, restoration, and activation-code binding
records are retained as needed for fulfillment, purchase restoration, dispute
handling, security audits, and applicable legal obligations, and are then
deleted or anonymized unless the law requires otherwise. Update APKs and
manifests are non-personal release artifacts and may remain for update delivery
and release traceability. Support records and security logs are retained only
as needed to handle requests, protect the service, and meet legal obligations.
Where no fixed period is stated, we do not invent one and instead apply
necessity and data-minimization principles.
We use measures such as random album tokens, access tokens, ownership checks,
delayed deletion, restricted read-only administration, service separation, and
collection minimization, but no network transmission or storage system can be
guaranteed completely secure.