Palena
/Data Policy

Data Policy

This page is Palena's operational data inventory and retention guide. It helps users understand where their data comes from and gives the team a baseline for support-assisted privacy requests.

Data inventory

Account and profile

Email address, authentication identifiers, name, handle, avatar, location, sport preferences, account settings, and administrator status where applicable.

Stories, activity, and community content

Race reports, imported activity details, photos and other media, comments, messages, follows, saved items, club or challenge activity, and the metadata needed to publish or organise them.

Connected services

Provider account identifiers, OAuth tokens, and activity data from services you choose to connect, such as Strava, Garmin, RideWithGPS, TrainingPeaks, or Komoot.

Support and launch communications

Contact messages, early-access signups, feedback reports, email addresses, and any screenshots or files you deliberately attach.

Technical and usage information

Authentication cookies, device and browser information, IP-derived request information, feature usage, diagnostics, rate-limit records, and analytics events when the relevant services are enabled.

Retention categories

Palena should keep personal data only for the purpose that required it. Exact provider log, analytics, support, and backup periods depend on deployment settings and must be approved and recorded by the product and legal owners before launch.

Account and profile records

Kept while the account is active. After a verified deletion request, active account records should be removed through the support-assisted deletion process.

Published content and media

Kept while published or needed to provide the service. Content is removed when the user deletes it through an available control or when a verified removal request is completed.

Connected-service credentials and imports

Connection credentials are kept until the connection is disconnected or the account is deleted. Content already imported or published is handled separately as account content.

Support, feedback, and safety records

Kept while the request or investigation is active and afterward only while needed for follow-up, security, abuse prevention, or an applicable record-keeping obligation.

Operational logs, analytics, and backups

Kept according to the configured hosting, analytics, security, and backup schedules. Deleted data may remain in restricted backups until those backups expire or are overwritten.

Request handling

  1. The requester emails the configured privacy address with the subject Privacy request, account email or handle, request type, and scope.
  2. Support records the request, checks that it reached the correct operator, and verifies account control without requesting passwords, access tokens, or unnecessary identity documents.
  3. Support searches the relevant account, content, media, connected-service, support, analytics, and backup systems based on the request scope.
  4. Support provides the export or correction, completes the supported deletion steps, disconnects integrations where requested, and explains any data that cannot yet be removed.
  5. The outcome and any follow-up are confirmed through the same monitored request channel.

Operational limits

Account erasure is currently a support-assisted operation rather than a complete automated product feature. Removing an account does not automatically retrieve copies other people made of public content, and restricted backups may retain deleted records until their normal expiry.