d0abe27623
Introduce versioned official content workflows and privacy-safe keyboard analytics, while preventing repeat DeviceCheck sign-ins from incorrectly restricting eligible accounts.
1.1 KiB
1.1 KiB
Account data lifecycle
- Apple subjects, refresh tokens, and account nicknames are encrypted at rest.
- Apple email and avatar data are not requested or stored.
- Deleting an account removes its session, profile, referral, grant, and mutable account records in the same local transaction before Apple revocation is retried.
- Product analytics installations linked to the account and all of their events are deleted by database cascade. The service stores only the digest of a random installation UUID and never stores user content in analytics events.
- Keyboard usage contains daily Chinese, English, other-character and input-session counters only. It never contains text or keystrokes and is purged after 90 days regardless of account linkage.
- Pseudonymous immutable credit-ledger entries, StoreKit transaction audit data, and time-limited anti-abuse tombstones remain after deletion where required to prevent replay, preserve financial integrity, and stop repeated trial abuse.
- Logs must never include Apple subjects, credentials, tokens, or nicknames.