Data Retention Schedule
This schedule explains how long APERTURESyndicate OÜ ("APERTURESyndicate", "AS", "we", "us") keeps each category of personal data, and what happens when a period ends. It applies across the whole platform and should be read together with our Privacy Policy and GDPR & Your Data.
We follow the storage-limitation principle of the GDPR: we keep personal data only while we have a lawful and proportionate reason to, and then we delete it or strip it of anything that points at you. The minimum age to use our services is 16.
Where a longer period is required by law — Estonian accounting and tax rules in particular — that requirement prevails.
1. The short version
| Data category | Retention | Basis |
|---|---|---|
| Account & profile data | While your account is active; after closure, ~30 days before purge | Contract |
| Session IP address & User-Agent | 30 days | Legitimate interest — security & anti-abuse |
| System logs on our servers | 30 days | Legitimate interest — security & operations |
| Technical identifiers in the administrative audit log | 30 days (the audit entry itself is kept longer) | Legitimate interest — security auditing |
| Raw product analytics events | 30 days, then aggregates only | Legitimate interest |
| Aggregate analytics (no link to a person) | Indefinite — no longer personal data | — |
| Resonance listening history | Long-term (see section 6) | Contract — royalties and your own statistics |
| Support requests & attachments | Until you delete them; closed requests stay as the record of what was agreed | Contract; legitimate interest |
| AI conversation history & memory | Until you delete it or opt out | Contract / consent |
| Billing & invoice records | 7 years | Legal obligation — Estonian Accounting Act |
| Support correspondence | ~2 years | Legitimate interest |
| Marketing-consent records | Until withdrawn, plus a short proof window | Consent / accountability |
The rest of this page explains the entries that are easy to misread.
2. Account and profile data
Your account and profile stay while your account is active. When you close it (or we close it under our Terms), we mark it deleted immediately — it disappears from the product at once — and purge it after a grace window of about 30 days. The window exists so an accidental or coerced closure can be reversed and final billing can be reconciled. Records that another line of this schedule requires us to keep, such as invoices, survive the purge.
3. Sessions, IP addresses and system logs
Every sign-in creates a session row that records the IP address and browser User-Agent, so that you can see your devices and so we can investigate account takeovers. These technical identifiers are cleared after 30 days by a daily job, in two ways:
- sessions that are already dead — signed out, revoked, or expired — are deleted outright, row and all;
- sessions still alive after 30 days keep working, but their IP address and User-Agent are erased. In your device list, such a session simply loses its label. We do not sign you out just to rotate a log field.
System logs written on our servers are kept for 30 days and then rotated away.
4. The administrative audit log
Actions taken by administrators — granting a role, changing something in the studio — are written to an append-only audit log. Two different periods apply to one entry, and the distinction matters:
- The technical identifiers attached to the administrator's session, their IP address and User-Agent, are erased after 30 days, on the same schedule as everything else in section 3.
- The entry itself — who did what, to what, and when — is kept for longer under our legitimate interest in being able to reconstruct security-relevant actions and investigate incidents. An audit log that deletes itself after a month cannot do its job.
If you exercise your right to erasure, this log is one of the places where a reference to you may survive; how that is handled is explained in GDPR & Your Data.
5. Product analytics
We record events such as "this feature was opened" against your account so we can see what is used and what is broken. These raw events are deleted after 30 days, automatically.
What remains afterwards is aggregate: daily counts per feature, with no user identifier attached. Aggregates are no longer personal data, so we keep them — they are how we compare this month to last year. In your browser, the related measurement window is about 12 months.
6. Resonance listening history — deliberately long-lived
This is the entry most likely to be misread, so we are stating it plainly: your Resonance listening history is not covered by the 30-day rule and is not deleted on that schedule.
Each qualifying play is recorded with the track, the artist, the timestamp, how long you actually listened, and a two-letter country code. It is kept long-term for two reasons that cannot work on a short window:
- Royalties. Artists are paid from stream counts. Deleting the record deletes the basis on which someone was paid, which we cannot do and which accounting rules would not accept either.
- Your own statistics. Streaks, listening minutes, top artists and yearly summaries are computed from the same history.
What this record does not contain is your IP address. Location is stored only as a country code — the coarsest form that still lets an artist see where their listeners are. You can browse and clear entries from your own history in the app, use a private session that keeps a play out of your history, and hide your statistics from other people in privacy settings. Details are in the Resonance Privacy Addendum.
7. Support requests, uploads and AI history
Support requests and any files you attach to them stay with your account. Closing a request does not delete it — a support conversation is often the record of what was agreed, so it is kept while your account exists and is removed with it. AI conversation history and memory stay until you delete them or opt out. In both cases deletion is applied in the product immediately and the data is then purged from our active systems.
8. Billing and invoices
Billing and invoice records are kept for 7 years. The Estonian Accounting Act (Raamatupidamise seadus) requires source documents underlying accounting entries to be retained for seven years from the end of the financial year. Because this is a legal obligation, these records survive account closure and an erasure request cannot shorten the period. Card details are held by our payment processor, not by us.
9. Support correspondence and marketing consent
Support email is kept for about 2 years so we can follow up and resolve related disputes, unless a legal hold applies.
Where you opted in to marketing, we keep the consent until you withdraw it, then a minimal record of the fact and timing of consent and withdrawal, so we can show we honoured it.
10. Deletion, purge and backups
Deletion happens in two steps: the data is marked deleted and vanishes from the product, then it is purged from our active systems after the applicable grace window.
Backups: what we will not promise. Off-site database backups are being set up and are not yet fully in place. Until they are, we are not going to quote a period after which deleted data has definitely aged out of every backup set, because we cannot yet stand behind such a number. What we do commit to: we do not restore deleted personal data from a backup except where strictly necessary for disaster recovery, and we re-apply pending deletions after any restore. This paragraph will be replaced with a concrete rotation window once the backup system is running.
11. Legal holds
We may keep data longer where we have a lawful reason — a legal or regulatory obligation, establishing or defending legal claims, resolving a dispute, or protecting the safety and integrity of the service. When the hold ends, the data returns to its normal period and is then deleted.
12. Deletion requests
You can ask us to delete your personal data, subject to the exceptions above. How to ask, and what happens to each system, is set out in GDPR & Your Data.
13. Contact
Questions about this schedule, or a request: [email protected]. Company details: Company Registration.
APERTURESyndicate OÜ · Registry code 17384111 · VAT EE102972654 · Priisle tee 8, Lasnamäe linnaosa, Tallinn, Harju maakond, 13914, Estonia.
This schedule is governed by the laws of Estonia, with disputes subject to the courts of Tallinn. The English version is the controlling version.
Version history — v1.1 — 2026-07-31 — Removed the "draft, do not rely on it" disclaimer now that the deletion jobs described here actually run; separated the 30-day technical-identifier rule from long-lived listening history; stopped promising a backup rotation window we cannot yet keep. · v1.0 — 2026-06-22.