How long TEBHOS keeps your information
How long TEBHOS retains different types of information and why we keep it.
We keep as little as we can, for as short a time as we can, and you can delete most things yourself. Our Privacy Policy is the main reference for what we collect and how long we keep it; its retention section covers the topic in full. This article summarises the points people ask about most.
What we keep while your account is active
While your account exists, we hold the things needed to run it: your username, email address, password hash, date of birth, and the content you have created (messages, uploads, servers, profile details). You can delete most of this yourself at any time, and you can close the account entirely.
A few things are commonly assumed to be kept that we do not actually keep:
- Card numbers. Payments go through Polar as our merchant of record. We never see or store the full card number.
- Message content for analytics or AI. Aggregate metrics count events, not content. Nothing you share is used to train AI models.
- Advertising and tracking data. No ad trackers, no third-party analytics SDKs, no browser fingerprinting, no tracking pixels.
- Your plaintext password. Your password is stored as an Argon2 hash; nobody, including us, can read it.
What you can remove yourself
- Individual messages and attachments. Delete them in the app; deleting a message also deletes its attachments.
- Your whole account. User Settings → Account & Security. See how to delete or disable your account. After a 14-day grace period (during which signing in cancels the deletion), the account is removed.
- A specific piece of data. Email [email protected] from your registered address.
What happens when you delete something
- A message or account record is removed from active systems quickly. It may persist in encrypted backups for up to 30 days, then it is permanently removed.
- An attachment is removed from active storage and is permanently gone. Attachments are not included in our long-term backups — we cannot bring them back.
- Your account gets a 14-day grace period (cancellable by signing in), then identifying data is removed. Backup purge follows the 30-day cycle above.
Content you sent in servers or direct messages may remain visible to the other people who received it after your account is gone, but it is no longer linked to you. If you want it gone first, delete it before closing the account.
What we keep longer, and why
A few kinds of data outlive your account, but only for specific, narrow reasons:
- Security and usage logs. Kept for a limited period and deleted on a rolling cycle; specific logs may be kept longer only for an active security investigation, a legal obligation, or an ongoing dispute.
- Purchase and transaction records. Kept for the period tax law requires. Full card numbers are not stored.
- Backups. Encrypted, kept on a rolling cycle of up to about 30 days, then overwritten.
- Legal records. Anything else we are specifically required by law to keep, for the period the law requires.
Aggregated or anonymised information that can no longer identify you may be kept indefinitely to understand service trends.
Inactive accounts
Inactive accounts are not deleted automatically today. If this changes, only accounts unused for at least 2 years would be in scope, with advance notice to the registered email address before deletion proceeds. See how to delete or disable your account for the criteria.
Your rights
You can request a copy of your data, delete your messages, and close your account. Anything you cannot do through the app can be requested at [email protected] from your registered email — see exporting your account data.
The KVKK also gives you rights of access, rectification, erasure, and objection to processing. All of them are described in the Privacy Policy, along with how to exercise them and how to lodge a complaint with the Turkish Data Protection Authority.