Controlled-beta draft · owner and legal review required before public launch
Retention Policy
Crown Studio keeps information only for an identified operational, security, support, contractual, or legal purpose. This page states the controlled-beta defaults. A preservation hold for an incident, dispute, or legal requirement can temporarily override deletion.
| Data | Default controlled-beta period | Deletion |
|---|---|---|
| Incomplete upload | Up to the expiry shown by the service; currently one hour | Automatic expiry and removal |
| Source photographs for a submitted job | Until the job succeeds, fails, or is cancelled | Removed from active processing storage at terminal cleanup |
| Generated 3D models and orthophotos | Until the result expiry shown in the application; currently one hour | Automatic active-storage expiry; download before expiry |
| Cloud processing session and job record | Job runtime plus the displayed result period | Automatic expiry; minimal audit metadata may remain separately |
| Account, tenant, project, and security-session records | While the account is active | Account deletion removes active records subject to legal or security preservation |
| Service, security, and audit logs | Up to 30 days by default | Rotation and secure expiry; shorter where practical |
| Support correspondence | Up to 24 months after the matter closes | Secure deletion unless needed for an unresolved dispute |
| Encrypted metadata backups | Daily copies for 7 days, weekly copies for 4 weeks, monthly copies for 3 months | Repository expiry after the off-site backup destination is approved and tested |
Important implementation note
The application-enforced one-hour processing expiry is active. Log and encrypted off-site backup periods above are the approved target policy for controlled-beta operations; their automated expiry must not be enabled until restore testing and owner approval are recorded. The provider’s standard whole-server backup is a separate single daily restore point and is not a substitute for encrypted off-site backups.
Deletion requests
Use the in-product account deletion control or the Support page. Active records are deleted or de-identified after identity verification. Copies disappear from backups as those backups expire. We will explain any lawful exception.