All policies

Data Retention

Last updated: July 31, 2026 · Version 1.0.0

This page describes how long Hack n Roll retains different categories of data and what happens when you request deletion.

1. Overview

We retain personal data only as long as necessary to operate the Platform, comply with legal obligations, and maintain community integrity. This policy supplements our Privacy Policy.

2. Account Data

Account information (username, email, password hash) is retained for as long as your account is active.

  • You may close your account from your account settings, or contact us to request deletion.
  • Account deletion is permanent (hard-delete). Your profile identity is removed; preserved forum content is shown as "Deleted User".
  • Challenge progress, submissions, sessions, credentials, and policy acceptance records tied to your account are permanently deleted.
  • Some associated community and moderation content may be preserved without your identity, as described below.

For assistance with account deletion, contact privacy@hacknroll.dev.

3. User-Generated Content

Forum posts, tutorials, articles, comments, and other community contributions may be retained after account deletion when needed for community continuity and platform integrity. Posts may remain visible with an anonymized author label rather than being removed entirely.

This approach preserves context for other participants (for example, answers to questions or collaborative write-ups) while removing personal identifiers from your profile. See Licensing and our Terms of Use for ownership and license details.

4. Policy Acceptance Records

When you accept the Terms of Use or Privacy Policy, we retain an audit trail that may include the policy name, accepted version, timestamp, IP address, and user-agent. These records are kept to demonstrate consent and compliance with applicable law.

Legal documents are versioned, and changes are reflected in the "Last updated" date and version shown on this page. Hack n Roll records the version of legal documents accepted by each user.

Legal documents are versioned. Material changes may require renewed acceptance before you continue using some or all Platform features. Minor editorial or non-material changes do not require renewed acceptance.

5. Authentication Tokens

Authentication credentials (including access and refresh tokens stored in HttpOnly cookies) are retained only while needed for active sessions. They become invalid after expiration or revocation, such as when you sign out. See our Cookie Policy for related details.

6. Challenge Submissions and Solves

Challenge submission records and solve timestamps are retained while your account is active to maintain leaderboard accuracy, scoring history, and access control for solution threads.

  • Incorrect submissions may be retained for rate-limiting and abuse prevention while your account exists.
  • When you delete your account, your challenge solves, submissions, and related progress are permanently deleted with your account. They are not retained in anonymized form.

7. Moderation and Audit Logs

Moderation and audit logs (for example, records of content removals or enforcement actions) may be retained after account deletion when necessary for platform integrity, security, abuse prevention, or legal compliance. Actor and reporter identity references are anonymized so the deleted user's identity is not retained solely through those records.

8. Email and Transactional Records

Transactional emails (verification, password reset, and similar notices) are processed through our email provider. Retention of delivery metadata follows the provider's retention policies and our operational requirements.

9. Backups

Database backups are created periodically for disaster recovery. Data in backups may persist for a limited time after deletion from the live system until those backups expire or are rotated as part of normal backup rotation cycles.

When you delete your account or we process a deletion request, we remove applicable personal data from active systems promptly. Residual copies in backups are removed as those backups rotate out of the normal cycle. We do not promise permanent, immediate deletion of every residual copy.

10. Technical Logs

Infrastructure and security logs (including IP addresses collected through our application logging or infrastructure providers such as Cloudflare) are retained only as long as necessary for security monitoring, abuse prevention, and troubleshooting. Provider-side logs are processed under that provider's own policies. These logs are not used for advertising or analytics and are not retained indefinitely by Hack n Roll beyond operational need.

11. Your Rights

You may request access to, correction of, or deletion of your personal data (including policy acceptance records) by contacting privacy@hacknroll.dev. We will respond within the timeframes required by applicable law. See our Privacy Policy for a full list of your rights.