Account data
- Accounts use email, username, password hash, email verification status, and profile preferences.
- Login attempts may record IP address, user agent, approximate location label, and failure reason for abuse prevention.
- API tokens may be created for mobile access and can be revoked from your profile.
- You can delete your account from profile settings after confirming your password. Account-owned data is removed together so a partial deletion cannot leave an active profile behind.
- Failed-login evidence may remain until the configured security cleanup date, but the deleted email is replaced with a non-login deletion reference.
- Active username, email, and IP bans remain enforceable after deletion. All other retained account audit events remove username, email, IP address, user agent, and profile links.