d0abe27623
Introduce versioned official content workflows and privacy-safe keyboard analytics, while preventing repeat DeviceCheck sign-ins from incorrectly restricting eligible accounts.
17 lines
1.1 KiB
Markdown
17 lines
1.1 KiB
Markdown
# Account data lifecycle
|
|
|
|
- Apple subjects, refresh tokens, and account nicknames are encrypted at rest.
|
|
- Apple email and avatar data are not requested or stored.
|
|
- Deleting an account removes its session, profile, referral, grant, and mutable
|
|
account records in the same local transaction before Apple revocation is retried.
|
|
- Product analytics installations linked to the account and all of their events
|
|
are deleted by database cascade. The service stores only the digest of a
|
|
random installation UUID and never stores user content in analytics events.
|
|
- Keyboard usage contains daily Chinese, English, other-character and
|
|
input-session counters only. It never contains text or keystrokes and is
|
|
purged after 90 days regardless of account linkage.
|
|
- Pseudonymous immutable credit-ledger entries, StoreKit transaction audit data,
|
|
and time-limited anti-abuse tombstones remain after deletion where required to
|
|
prevent replay, preserve financial integrity, and stop repeated trial abuse.
|
|
- Logs must never include Apple subjects, credentials, tokens, or nicknames.
|