Account and profile data
Account identity, locale, and app-side profile fields are kept while the account is active and are anonymized when the member deletes the account.
- Profile-facing fields are cleared during account deletion.
- Access ends immediately when deletion is confirmed.
Billing and invoice records
Billing records stay available for reconciliation, invoicing, and Portuguese tax obligations.
- Invoice and tax records are retained for the legally approved period.
- These records can remain even after the member deletes the app account.
Checkout allocation and audit trail
Checkout reservations and related entity events are kept for payment reconciliation, fraud review, and provider-allocation history.
- Open reservations expire automatically when the checkout window closes.
- Resolved allocation history remains with the billing audit trail.
Watch progress and member preferences
Watch-progress checkpoints and similar member-experience data stay available while the account is active and are not kept indefinitely.
- Current baseline: remove or anonymize these records after 180 days of inactivity.
- Deleting the account also removes app-side access to this data.
Cookie and browser-side preferences
Locale and cookie-consent preferences are stored in the browser so the public site can remember user choices.
- duo-cookie-consent and duo-locale are stored for up to 180 days.
- Browser clearing or changing preferences removes these values earlier.