Lifecycle
Data deletion and retention
Effective September 21, 2026
Deletion of a game, player profile, session, or account has different effects. This page explains the current service behavior and the manual steps used for privacy requests. We do not claim that deleting a game alone deletes every frame of its source recording.
Current retention
| Data | Current period or deletion trigger |
|---|---|
| Account and workspace records | Kept while the account or workspace is active. Individual account erasure is handled by the operator on request; there is no self-service account deletion button yet. |
| Original recordings, live stream segments, uploaded files, and playback copies | No automatic expiry for completed media at present. A session or source deletion may not remove other copies or a still-referenced source. Workspace deletion removes tracked object-storage media; legacy filesystem recordings require operator review and removal. |
| Game records, event logs, scores, OCR, and associated evidence | Kept while the relevant game/session/workspace exists or while evidence is retained for reviewed training. Deleting a game does not necessarily delete its source session, shared recording, or independently reviewed training evidence. |
| Player profiles, face images, and embeddings | Kept while the profile is used. Profile or face-sample deletion removes the database reference; unreferenced object media is then eligible for cleanup. A face may still appear in an original recording or another retained image. |
| Unreferenced object media and previews | A maintenance collector runs daily with a 24-hour grace period for newly unattached objects. Other preview and evidence cleanup jobs remove eligible orphaned files. Referenced material is not removed solely because of age. |
| Incomplete object-storage uploads | Provider lifecycle rules abort incomplete multipart uploads after seven days. |
| Database backups | Daily backups are scheduled for 30-day retention. Individual records cannot be removed from an existing backup; expired backups are deleted by the backup maintenance job. |
| Security and deletion audit records | Kept as needed to investigate abuse, prove a deletion was handled, or meet legal obligations. There is not yet a fixed automatic expiry for all such records. |
Request deletion or exercise a GDPR right
- Email privacy@flipper.stream. Include the account email or username and links or identifiers for the recordings, games, or player profiles. Do not send identity documents unless we specifically ask for them through an appropriate channel.
- We verify that you are the account holder or the person shown, and determine whether the request concerns your account, a workspace you administer, a shared game, a face profile, or third-party footage. We may ask for enough additional detail to locate the data.
- We assess the request and any legal grounds to retain data. Where GDPR applies, we normally respond within one month of receiving the request; if complexity or the number of requests requires more time, we notify you within that month and may extend by up to two additional months. We explain any refusal or partial deletion and available complaint rights.
- When erasure is required, we remove or de-identify applicable active records, player matches, face samples, derived evidence, and tracked media; revoke relevant account access; and remove library visibility. Shared footage or games require a separate assessment of other players' and uploaders' rights. We check legacy recordings and copies that are not covered by automated object cleanup.
- We confirm the scope and completion status. Deleted data can remain in already-created database backups until their scheduled expiry (normally within 30 days). If a backup must be restored before then, we reapply outstanding deletions before reopening access.
Some data may need to remain for legal claims, compliance, security, or the rights of others. We will explain the specific exception rather than treating every request as an automatic all-or-nothing deletion. Copies already downloaded by another authorized user or held by Twitch, YouTube, or another independent service are outside our direct control.
What existing delete controls do
Deleting a game removes that game entry, but not necessarily its session or source video. Deleting a session removes its analysis records and associated archive references; a source can still be retained and used elsewhere. Deleting a player or face sample removes that profile or sample, not every appearance in footage. Administrator workspace deletion is a durable, retryable process: member access is disabled immediately, tracked object-storage media is deleted before workspace database records, and the operator monitors failures. It currently requires an export and cannot start with active work, pending uploads, or unmigrated filesystem media. Contact us for an individual account erasure or a broader request; the UI controls alone may not satisfy it.
See also our privacy policy and terms of service.
