OmegleNet

Data Retention Schedule

Last updated: 28 September 2026

This schedule lists every type of data OmegleNet keeps, how long we keep it, and how it's deleted. Anything under a legal hold (for example a child-safety report to NCMEC, or a law-enforcement preservation request) is kept until the hold ends, even if the normal period has passed.

Retention table

#DataWhere it's storedRetention (published)Current codeDeletion mechanismChange needed
1Text chat messages (roomId, sender user ID, text, time)MongoDB chatlogs30 days30 d (CHAT_RETENTION_DAYS)Hourly retention worker + TTL indexSkip legalHold docs; replace TTL with partial TTL (P0-4)
2Safety snapshots not flagged (image + score/labels)Screenshot storage + safetyscreenshots90 days90 d (UNFLAGGED_SCREENSHOT_RETENTION_HOURS=2160)Worker deletes file + docNone
3Safety snapshots flaggedSame1 year (legal hold)365 d hold (LEGAL_HOLD_DAYS)Worker deletes file + docSkip held items (P0-4)
4Suspected/confirmed CSAM and related dataEncrypted evidence store + evidenceitems≥1 year after the NCMEC report (longer if law enforcement asks); then deleted after reviewNot implemented. Would be deleted at 90 dManual, audited deletion after holdUntilBuild evidence store (P0-3)
5Reports (reporter ID, reported ID, room, reason)reports365 days365 d (BAN_RETENTION_DAYS)Worker + TTLSkip held
6Bans (user ID, device ID, IP hash, reason, source, expiry)bans365 days from creation, never while active; permanent bans kept while in force365 d, never while activeWorker (+ TTL on createdAt, which ignores active bans — remove or make partial)Fix TTL so it can't delete an active or permanent ban
7Appeals and moderation decisions (statement of reasons)bans.appeal, notices365 days after decisionNot implementedWorkerBuild (P0-8/P0-9)
8Notices from non-users (illegal content / NCII reports)notices365 days after closureNot implementedWorkerBuild (P0-9)
9Anonymous device record (device ID, IP hash, age-check result)anonusers12 months after last visit, unless there's an active ban or legal holdKept indefinitelyWorker on lastSeenAtAdd (P1-3)
10Retention run logs (counts only, no personal data)retentionruns2 yearsIndefiniteWorkerAdd TTL
11Admin/moderator audit logadmin_audit2 years (evidence-related entries: life of hold + 1 year)Not implementedWorkerBuild (P1-1)
12Privacy (DSR) request logdsr_requests3 years (proof of compliance)Not implementedWorkerBuild (P0-10)
13Law-enforcement requestsnotices (category law_enforcement)1 year after the request is closed (data it asks us to preserve is kept under a legal hold)1 y after decision (BAN_RETENTION_DAYS)Retention workerNone
14Server / nginx / Cloudflare / coturn relay logs (coturn: client IP + opaque TURN username, no account ID)Log sink, Cloudflare≤30 days; IPs truncated or hashed where possible; no tokens in URLsNot configuredLog platform settingsConfigure (P1-10)
15Database backupsBackup storage≤35 days rollingNot configuredBackup rotationConfigure; evidence backups inherit hold
16Interests and matchmaking queueServer memory onlyWhile you're connectedMemory onlyProcess memory—
17Video and audio streamsNot stored (P2P or TURN relay)Never storedNot stored—Keep a regression test: no media recording
18Age-assurance raw data (selfie / ID image / DOB)Age-assurance provider onlyDeleted by the provider right after the check. We keep only the result + method + date (see row 9)Not implementedProvider DPAContract term
19Browser items (omegle.deviceId, omegle.token, omegle.prefs, omegle.rulesAccepted, …)Your deviceUntil you clear them or use "Delete my data" (token expires after 30 d)As statedUser / "Delete my data"Add client "Delete my data" (P0-10)

Deletion on request

When you use Delete my data (or email hello@omeglenet.com), we delete rows 1, 2 and 9, and reports you filed (row 5), within 30 days (usually immediately). We keep bans and reports about you (rows 5–6) until their normal expiry, and anything under legal hold (row 4). Backups roll off within 35 days.

Governance

  • Owner: Quantumplug Technologies LLP (hello@omeglenet.com). Reviewed every 12 months or when a new data type is added.
  • Every retention run is logged (retentionruns). Alert if a run fails or deletes 0 rows for 3 days in a row.
  • Changing any retention environment variable (CHAT_RETENTION_DAYS, SCREENSHOT_RETENTION_DAYS, BAN_RETENTION_DAYS) requires updating this schedule and the Privacy Policy first.