Different KGE data categories serve different purposes and therefore do not all have the same retention period. This policy describes the principles KGE applies when setting those periods.
Effective:
1. Active account data
Core account and product data may be retained while an account is active and for a reasonable period afterward to support reactivation, security, disputes and legal obligations.
2. Closed accounts
Ordinary closure disables the KGE identity and can trigger deletion or de-identification of eligible product data. Some records may remain where necessary for legal, financial, fraud-prevention, safety, audit or dispute reasons.
3. Financial and virtual-economy records
Purchase, refund, chargeback, entitlement and Moxbits ledger records may be retained longer because they support accounting, tax, fraud and audit requirements.
4. Security and diagnostic logs
Security, authentication and diagnostic logs are retained for periods appropriate to incident investigation, abuse detection, reliability and legal requirements, then deleted or de-identified when no longer needed.
5. Support and safety cases
Support tickets and high-risk safety records may be retained to resolve the case, document actions, prevent repeated abuse and meet legal obligations.
6. AI memory and conversation data
AI conversation content and persistent memory should be retained according to product purpose and user controls. Structured memory may outlive an individual chat where the user has enabled persistence, but should remain subject to correction, deletion and legal-retention rules.
7. Backups
Deleted information may remain temporarily in backups until normal backup rotation removes it. KGE should not restore deleted data to active use except for legitimate recovery or legal reasons.
8. Guardian consent records
Guardian-consent requests may retain the request identifier, product, age band, guardian contact address, consent method, disclosure and policy version, decision, confirmation timestamps, revocation state and audit history for as long as reasonably necessary to demonstrate consent, administer the account, protect safety and meet legal obligations. Raw one-time tokens, approval sessions and signup status keys are not retained in readable form and expire. KGE should avoid duplicating a child's full date of birth in the consent store when KGE Identity already holds the authoritative value.
9. Review and minimization
KGE should periodically review retention settings and reduce or de-identify data that no longer serves a legitimate purpose.
Important: Product-specific disclosures, app-store rules and rights that cannot legally be waived may supplement or override general language in this policy.