Data Retention Schedule
Last updated: 28 September 2026
This schedule lists every type of data OmegleNet keeps, how long we keep it, and how it's deleted. Anything under a legal hold (for example a child-safety report to NCMEC, or a law-enforcement preservation request) is kept until the hold ends, even if the normal period has passed.
Retention table
| # | Data | Where it's stored | Retention (published) | Current code | Deletion mechanism | Change needed |
|---|---|---|---|---|---|---|
| 1 | Text chat messages (roomId, sender user ID, text, time) | MongoDB chatlogs | 30 days | 30 d (CHAT_RETENTION_DAYS) | Hourly retention worker + TTL index | Skip legalHold docs; replace TTL with partial TTL (P0-4) |
| 2 | Safety snapshots not flagged (image + score/labels) | Screenshot storage + safetyscreenshots | 90 days | 90 d (UNFLAGGED_SCREENSHOT_RETENTION_HOURS=2160) | Worker deletes file + doc | None |
| 3 | Safety snapshots flagged | Same | 1 year (legal hold) | 365 d hold (LEGAL_HOLD_DAYS) | Worker deletes file + doc | Skip held items (P0-4) |
| 4 | Suspected/confirmed CSAM and related data | Encrypted evidence store + evidenceitems | ≥1 year after the NCMEC report (longer if law enforcement asks); then deleted after review | Not implemented. Would be deleted at 90 d | Manual, audited deletion after holdUntil | Build evidence store (P0-3) |
| 5 | Reports (reporter ID, reported ID, room, reason) | reports | 365 days | 365 d (BAN_RETENTION_DAYS) | Worker + TTL | Skip held |
| 6 | Bans (user ID, device ID, IP hash, reason, source, expiry) | bans | 365 days from creation, never while active; permanent bans kept while in force | 365 d, never while active | Worker (+ TTL on createdAt, which ignores active bans — remove or make partial) | Fix TTL so it can't delete an active or permanent ban |
| 7 | Appeals and moderation decisions (statement of reasons) | bans.appeal, notices | 365 days after decision | Not implemented | Worker | Build (P0-8/P0-9) |
| 8 | Notices from non-users (illegal content / NCII reports) | notices | 365 days after closure | Not implemented | Worker | Build (P0-9) |
| 9 | Anonymous device record (device ID, IP hash, age-check result) | anonusers | 12 months after last visit, unless there's an active ban or legal hold | Kept indefinitely | Worker on lastSeenAt | Add (P1-3) |
| 10 | Retention run logs (counts only, no personal data) | retentionruns | 2 years | Indefinite | Worker | Add TTL |
| 11 | Admin/moderator audit log | admin_audit | 2 years (evidence-related entries: life of hold + 1 year) | Not implemented | Worker | Build (P1-1) |
| 12 | Privacy (DSR) request log | dsr_requests | 3 years (proof of compliance) | Not implemented | Worker | Build (P0-10) |
| 13 | Law-enforcement requests | notices (category law_enforcement) | 1 year after the request is closed (data it asks us to preserve is kept under a legal hold) | 1 y after decision (BAN_RETENTION_DAYS) | Retention worker | None |
| 14 | Server / nginx / Cloudflare / coturn relay logs (coturn: client IP + opaque TURN username, no account ID) | Log sink, Cloudflare | ≤30 days; IPs truncated or hashed where possible; no tokens in URLs | Not configured | Log platform settings | Configure (P1-10) |
| 15 | Database backups | Backup storage | ≤35 days rolling | Not configured | Backup rotation | Configure; evidence backups inherit hold |
| 16 | Interests and matchmaking queue | Server memory only | While you're connected | Memory only | Process memory | — |
| 17 | Video and audio streams | Not stored (P2P or TURN relay) | Never stored | Not stored | — | Keep a regression test: no media recording |
| 18 | Age-assurance raw data (selfie / ID image / DOB) | Age-assurance provider only | Deleted by the provider right after the check. We keep only the result + method + date (see row 9) | Not implemented | Provider DPA | Contract term |
| 19 | Browser items (omegle.deviceId, omegle.token, omegle.prefs, omegle.rulesAccepted, …) | Your device | Until you clear them or use "Delete my data" (token expires after 30 d) | As stated | User / "Delete my data" | Add client "Delete my data" (P0-10) |
Deletion on request
When you use Delete my data (or email hello@omeglenet.com), we delete rows 1, 2 and 9, and reports you filed (row 5), within 30 days (usually immediately). We keep bans and reports about you (rows 5–6) until their normal expiry, and anything under legal hold (row 4). Backups roll off within 35 days.
Governance
- Owner: Quantumplug Technologies LLP (hello@omeglenet.com). Reviewed every 12 months or when a new data type is added.
- Every retention run is logged (
retentionruns). Alert if a run fails or deletes 0 rows for 3 days in a row. - Changing any retention environment variable (
CHAT_RETENTION_DAYS,SCREENSHOT_RETENTION_DAYS,BAN_RETENTION_DAYS) requires updating this schedule and the Privacy Policy first.