Written from what the code does rather than from a template — every entry below was read out of the file that implements it, and the file is named. It is deliberately specific in the places a policy is usually vague, because the vague places are the ones that matter.
Three sections, because there are three different answers to “who has this”. Read the one that applies to you; the boundaries between them are real.
Section {section.number}
{section.controller}
{section.lede}
{row.body}
How long {row.retention.summary} {row.retention.detail && ( {row.retention.detail} )}
Section 4
This applies to section 1 only — the beta list.
We hold one piece of information about you and it is the address you typed into the beta form. Ask for it to be removed and it will be erased rather than marked: what stays behind is a date and the fact that a removal happened, so we can confirm we did it without keeping the thing you asked us to let go of.
Say which address to remove. There is no form to fill in and no account to prove — knowing the address is all that is needed, because it is all that is stored.
{brand.contactEmail}The same request works in the community Discord, which is generally the faster of the two.
Join the DiscordOne consequence of erasing rather than flagging, stated because it is the honest reading and not a caveat we would rather you missed: afterwards the list cannot tell your address from one it has never seen. Asking twice gets the same answer as asking about a stranger, and signing up again later is an ordinary new signup.
Section 5
If what the software collects changes, this page changes with it in the same release — the entries above are generated from a single inventory in the source, so a change to what is stored and a change to what this page says are the same edit. The date at the top is the last time that happened. This site sends no email at all, so there is no notification to send you when it does; the page itself is the record.