Legal · Version 2026-08-05-v620
Data Retention Policy
Generated works use plan-based retention. Free and trial works are retained for a shorter period; paid plans and credit-pack unlocks may extend retention. Users may request deletion of generated works and account-associated data through the support flow.
These policies govern use of Magic QR Studio SaaS, including accounts, uploads, generated works, checkout, credits, plans, private downloads, support and content safety.
1. Principles
We retain personal data only for the period reasonably necessary for the stated service, security, accounting, dispute and legal purposes. The periods below are operational defaults, not promises to retain data for the full period, and may be shortened by deletion or extended by a legal hold, fraud investigation, backup rotation or mandatory law.
2. Works, uploads and generated files
- Free works: normally up to 7 days.
- Plus works: normally up to 30 days.
- Pro works: normally up to 60 days.
- Max works: normally up to 90 days.
- Orphan uploads, previews, temporary and intermediate processing files: normally removed earlier, commonly within 24 hours when no longer linked to a work.
3. Account, authentication and communications
- Active account profile and current authentication data: for the life of the account, then deleted or de-identified subject to exceptions.
- Expired sessions and verification/reset records: deleted after expiry and short operational grace periods.
- Login history, security events, support, feedback and operational correspondence: normally up to 90 days where operational, or longer while a ticket, complaint, refund or legal issue remains open.
4. Operational and safety records
- Rate-limit records: normally up to 2 days.
- Worker heartbeat records: normally up to 14 days.
- Preprocessing cache: normally up to 30 days.
- CPU and usage telemetry: normally up to 45 days.
- Scan, content-safety, checkout-intent, webhook-attempt and email-delivery logs: normally up to 90 days.
5. Billing, consent and legal evidence
Billing lifecycle records are normally retained for at least 365 days and longer where tax, accounting, merchant-of-record, chargeback, limitation, fraud, contract or regulatory duties require. Unpaid or abandoned checkout-consent evidence is normally deleted after about 365 days; paid purchase-consent evidence and minimum identifiers may remain longer, including after account deletion, in restricted or de-identified form where needed for contract, accounting, fraud, dispute or legal purposes. Raw payment-event and dead-letter payload content is normally redacted after about 90 days when operationally safe.
6. Backups, deletion and providers
Deletion from active systems may not immediately remove encrypted backups. Backups expire through normal rotation and are used only for disaster recovery; deletion instructions are reapplied after restoration. We ask relevant processors to delete data where required and reasonably possible, but independent controllers such as the merchant of record retain their own legally required records. Provider-side copies and diagnostic records follow the applicable provider agreement and retention controls.
7. Requests and exceptions
Request deletion or retention information through the Data Requests page or [email protected]. We may preserve a minimal request record and data necessary to complete a transaction, secure the service, comply with law, investigate abuse or establish, exercise or defend legal claims.
Support: [email protected]
For privacy, copyright, data, billing or security requests, contact [email protected]. We may ask for job ID, code ID, order ID or account email to verify and investigate the request.