Token & Session Lifetimes
| Item | Lifetime |
|---|---|
| Access token | 1 hour |
| Refresh token | 90 days (renewable on use) |
| Pairing code | 10 minutes |
| Password reset token | 1 hour |
| Email verification token | 24 hours |
| Desktop session token | 90 days |
Data Retention Periods
| Data Category | Retention Period |
|---|---|
| Account email & password hash | Until account deleted |
| Internal user ID | Until account deleted |
| Workspace configurations | Until deleted by user or account deletion |
| Paired device identifiers | Until device unpaired or account deletion |
| Command history | 30 days |
| Security logs (logins, failed attempts, device changes) | 90 days |
| Desktop connection logs | 30 days |
| Analytics data | Up to 14 months |
| Crash reports | 90 days |
| Support correspondence | 90 days after account deletion |
| Transaction & purchase records | 7 years (legal requirement) |
| Aggregated anonymised analytics | Indefinite (no PII) |
Deleted-account & backup retention
- Account data marked for deletion — permanently removed from live systems within 30 days of verified request
- Backup copies — purged within 30 days of deletion from live systems
- Local device data — not affected by account deletion; users must clear manually
Temporary Data
- Pairing codes — single-use; expire after 10 minutes and are discarded immediately after use or expiry
- Remote command relay data — commands in transit are discarded within 60 seconds of delivery or failure
- Password reset tokens — expire after 1 hour
- Email verification tokens — expire after 24 hours
Token Storage & Revocation
- Refresh tokens are hashed before storage — the server cannot retrieve the original token value
- Pairing requests are single-use — a used or expired pairing code cannot be reused
- Revoked desktop tokens are rejected on all subsequent connection attempts — the desktop agent will show a disconnected state
- Secrets and credentials are not written to application or server logs
Access Controls
Access to production data is restricted as follows:
- Only authorised personnel have access to production systems
- Access is granted on a need-to-know basis
- Authentication requires strong passwords and multi-factor authentication where supported
- All access to production systems is logged and audited
- Third-party service providers process data under data processing agreements
Desktop Token Revocation
Desktop agent tokens can be revoked in the following ways:
- In-app: Settings → Connected Devices → select desktop → Revoke AccessDesktop Agent: Open the Agent → Revoke Access or Sign OutAccount deletion: All tokens are revoked automaticallyPassword change: All sessions and tokens are invalidated
Breach Response Procedure
In the event of a data breach or security incident involving personal information, we will:
- 1Investigate the incident and contain the breach immediately
- 2Assess the scope and impact of the breach
- 3Notify affected users within 72 hours where required by applicable law
- 4Provide affected users with details of what data was involved and steps they should take
- 5Report the incident to the Nigeria Data Protection Commission (NDPC) as required
- 6Implement measures to prevent recurrence
- 7Document the incident and response for compliance purposes
If you suspect a security issue with your account or our services, please contact us immediately at support@creatorstudioslabs.stream.
Contact
For security-related enquiries or to report a vulnerability:
We practice coordinated disclosure and appreciate responsible reports of security issues.