Storage should have a purpose—and an end.
This policy explains browser storage, cloud services, operational retention, cancellation archives, backups, and secure disposal.
Where information is stored
- Supabase: account authentication, PostgreSQL records, Event data, files, storage, server functions, and audit/notification operations.
- GitHub Pages: public static application files; user Event records are not intentionally written into the public repository.
- Resend: email addressing, content, and delivery events needed for transactional or consented Business marketing email.
- Connected providers: optional social-publishing credentials and Business-selected hosted payment links/status.
- User device: authentication session, drafts, cache/version state, preferences, and recovery data stored through browser storage.
The current provider list appears in Subprocessors.
Browser storage and cookies
Galaxy Cue relies on local storage and provider-managed browser session storage so passwordless authentication, form drafts, navigation, offline recovery, and selected preferences work. Clearing site data may sign the user out or remove an unsynced local draft.
Required storage is used for service functionality and security—not advertising. For Italy, this required storage must be listed with purpose and duration. Galaxy Cue must not add an advertising cookie, cross-site pixel, replay tool, optional analytics tag, or similar identifier until it has a documented purpose, vendor review, retention setting, prior consent where required, an Italian notice, and an equally accessible reject/withdraw control. Continued browsing or scrolling is not consent.
Retention schedule
| Record | Operational rule | Reason |
|---|---|---|
| Account and profile | While active; then through verified deletion and dependency review | Identity, connections, support, security |
| Draft request | Until submitted or deleted by its authorized creator | Client-controlled preparation |
| Cancelled incomplete Event/request | 30-day archive before operational purge | Recovery, dispute prevention, synchronized cleanup |
| Expired, paused, or cancelled Business subscription | 30-day reactivation window; no automatic hard purge at the end of the window | Account recovery followed by dependency, retention, legal-hold, and deletion review |
| Completed Event | Archived until authorized permanent deletion | Documents, history, repeat planning, disputes |
| Quotes, contracts, signatures, receipts | With the Event and longer when law, contract, tax, or dispute requires | Proof of agreement and transaction |
| Accounting snapshot | Minimum period required by applicable accounting/tax rules and Business policy | Books and records; may outlive deleted operational Event |
| Consent and unsubscribe record | While needed to prove and honor the choice | Consent accountability and suppression |
| Security/audit record | Risk-based period limited to investigation, prevention, and legal need | Security and fraud prevention |
| Provider credentials | Until disconnected, revoked, expired, or no longer required | Integration operation |
| Local drafts | Until synchronized, replaced, user-cleared, or browser eviction | Recovery and continuity |
Where a law or signed agreement requires a specific period, that requirement controls. Galaxy Cue documents and reviews the operational periods used for accounting, audit, security logs, and backups rather than promising a date the product cannot enforce.
Archives are not silent deletion
Cancelled incomplete Events remain in the authorized archive for 30 days and are removed from active Business and Client lists. Completed Events remain read-only in Archive until an authorized Danger Zone action. Deleting an operational Event must clean up dependent client-facing forms and views while preserving only the limited financial or legal record that is independently required.
A Business subscription’s 30-day reactivation window is separate from the Event archive rule. Subscription expiration suspends Business OS access; it does not silently delete active Events or evidence of Contracts, signatures, retainers, receipts, accounting, consent, security incidents, or disputes. Those records are reviewed under this schedule and the DPA before deletion or return.
Backups and replicas
Deleted information may remain temporarily in encrypted backup or provider-recovery systems until ordinary rotation. It is not restored to production except for legitimate disaster recovery, and a restored system must reapply valid deletion and suppression records where practicable.
Exports and secure disposal
A user-downloaded PDF is stored outside Galaxy Cue and no longer follows the platform’s access controls, archive timer, or deletion workflow. Platform deletion does not erase copies already downloaded to a user’s device, cloud drive, backup, printer, or email. The person or Business creating an export is responsible for lawful retention, secure storage, restricted sharing, and secure deletion. An export does not change the authoritative platform record or extend Galaxy Cue’s own retention period.
When retention ends, Galaxy Cue should delete, anonymize, aggregate, or make information inaccessible using the service provider’s supported controls. Paper or exported records are the responsibility of the person or Business that created them. Secrets must be revoked—not merely hidden from the interface.
Review and change control
Retention rules must be reviewed at least annually and whenever a new provider, data category, jurisdiction, payment flow, native app, analytics tool, or legal obligation is added. Product code, database jobs, policies, and documentation must remain synchronized.
