Skip to content
Pocket Genes

Privacy and rights

Data-Retention and Deletion Policy

Explains how long Pocket Genes retains account information, temporary integration data, platform decision records, community content, operational logs, backups, and what happens when information is deleted.

Purpose and scope

This policy explains how Pocket Genes retains, deletes, de-identifies, or preserves information in account, integration, platform decision, informed-consent, report-access, community, support, log, and backup workflows.

Retention values reflect implemented behavior. Where Pocket Genes has not published a fixed automated expiration period, this policy states the current deletion trigger instead of inventing a fixed number of days.

Who this policy applies to

  • Pocket Genes users, invited users, caregivers, and representatives.
  • People whose contact information is provided by an integrator.
  • RareFriends community participants.
  • Trusted Organizations, providers, and integrators connected to a workflow.

Definitions

Active systems

Databases, authentication services, storage, and application records used to operate live Pocket Genes features.

Backup

A provider or operational copy used for disaster recovery or service restoration, not ordinary user access.

Deletion trigger

The user request, account closure, workflow closure, moderation action, expiration, revocation, or operational action that starts deletion.

Legal or safety hold

A narrow preservation reason such as security investigation, legal claim, abuse evidence, fraud prevention, or statutory obligation.

De-identified information

Information no longer reasonably linked to an identifiable person. Truly anonymous data is not treated as account data in this policy.

Retention schedule

InformationRetention beginsRetention endsDeletion triggerPossible exception
Uncompleted integration invitationReceipt from integrator or provider.Workflow completion, rejection, manual cleanup, account deletion, or a published integration-specific expiry.User declines, requests deletion, invitation is revoked, or operator closes the workflow.Security investigation, legal hold, abuse review, or provider dispute.
Account dataAccount creation or invitation acceptance.Account deletion plus active-system deletion process and backup rotation.Verified user request, authorized admin deletion, or account closure workflow.Legal, fraud-prevention, security, payment, or dispute requirement.
Platform decision recordPlatform preference, report-access activation, optional communication choice, or informed-consent upload status.When the evidentiary, provider, or legal need ends.Expiry of evidentiary requirement, deletion request where applicable, or workflow retirement.Legal claim, compliance requirement, or dispute.
Report access reference or linkLink, code, token, reference, or access state creation.Expiry, revocation, provider relationship end, account deletion, or provider workflow cleanup.User request, provider revocation, account deletion, or integration cleanup.Support investigation, security incident, legal hold, provider dispute.
Community profileProfile creation or RareFriends enrollment.Profile deletion, RareFriends exit, account deletion, or moderation removal.User request, account closure, or moderator action.Moderation record, safety evidence, legal hold.
Posts and commentsPublication.User deletion, account deletion cascade, moderation removal, or community feature retirement.User action, account closure, or moderation action.Safety investigation, legal preservation, abuse evidence.
MessagesMessage sent or received.Deletion, account closure, feature-specific retention, or moderation cleanup where messaging is enabled.User or account deletion, report, or moderation action.Abuse investigation, safety review, legal hold.
Support and booking requestsTicket, email, form, or booking submission.Closure, manual archive, deletion request, or operational cleanup.User request, support closure, or operator archive.Legal dispute, billing, abuse, or security investigation.
Security logsSecurity, authentication, system, or access event.Provider log cycle, configured log expiry, incident closure, or operational cleanup.Automated expiry where configured or manual cleanup.Active incident, abuse investigation, legal hold.
BackupsBackup creation by provider or operational process.Maximum provider backup cycle or rotation.Automatic rotation, restoration cleanup, or provider process.Disaster recovery, legal hold, active incident.
De-identified analyticsCreation from operational or usage information.When no longer useful or according to analytics configuration; may be indefinite if genuinely anonymous.Policy schedule or dataset retirement.Not applicable if no longer personal information.

Active systems versus backups

Deletion from active systems means Pocket Genes removes or de-identifies the record from the systems used for ordinary product functionality. The exact timing can depend on the account, provider workflow, queue, database, storage, and support process.

Deleted data may remain briefly in backups until provider or operational backup rotation completes. Backups are intended for restoration and continuity, not normal lookup. Restoration handling includes known deletion, restriction, or moderation states where feasible.

Platform decision records

Platform decision records may outlive temporary contact information because Pocket Genes may need evidence of the decision, screen or policy version, workflow, time, and provider or organization relationship. This is separate from retaining a complete report or unnecessary invitation information.

The record keeps the minimum information needed to understand what was accepted, declined, changed, withdrawn, or superseded.

Account deletion

Account deletion covers the Pocket Genes account, private profile, public profile, community user record and events, authored posts and comments up to operational batch limits, report codes, user progress, report owner records, and uploaded report records linked to the user.

Account deletion does not delete provider-controlled reports, provider medical records, provider portals, app-store records, external organization records, or information other users lawfully retain outside Pocket Genes. It also may not remove moderation, legal, security, backup, or de-identified operational records.

Legal and safety exceptions

  • Fraud, security, or account-compromise investigation.
  • Legal claim, subpoena, court order, regulator request, or statutory obligation.
  • Abuse, harassment, scam, exploitation, or moderation evidence.
  • Enforcement of Terms of Service, Community Terms, or Trusted Organization Standards.
  • Protection of another user privacy, safety, or rights.

Retention model

  • Retention is stated from implemented behavior, not aspirational periods.
  • Active-system information is deleted or de-identified when a valid deletion trigger applies.
  • Preserved records are limited to legal, safety, or security reasons.
  • Provider-controlled or third-party records remain outside Pocket Genes deletion control.

User, integrator, and organization responsibilities

  • Users should request deletion from Pocket Genes and separately from providers or organizations when those parties control their own records.
  • Integrators should avoid sending unnecessary data and should honor revocation or correction requests in their own systems.
  • Organizations should delete or correct independently collected user information under their own notices and obligations.

Exceptions and limitations

  • Operational batch limits may require staged deletion for unusually large content histories.
  • Backups and provider-managed logs can delay final removal from every copy.
  • Some records may be retained in de-identified, aggregated, or legal-hold form.

How to make a request or report a problem

Privacy, account, deletion, accessibility, safety, trusted-organization, and security requests can be sent to support@goldencrowvs.com. Use a subject line that identifies the issue, the affected Pocket Genes account or workflow, and whether the request is urgent.

Pocket Genes may need to verify the requester before changing or disclosing account information. Verification is handled proportionally to the request, the sensitivity of the information, and the risk of giving account access or private information to the wrong person.

Effective date, version, and review history

ItemValue
Effective dateAugust 14, 2026
Version1.1
Last reviewedAugust 2026
Material changesExpanded Trust Center format, operator identity, data-map boundaries, request paths, and responsibility sections.
Previous versionJuly 2026 Trust Center overview copy.

Related pages

Related pages