Back to home
Security

Security & Data Retention

Creator Studios Labs · Last updated: July 20, 2026

Token & Session Lifetimes

ItemLifetime
Access token1 hour
Refresh token90 days (renewable on use)
Pairing code10 minutes
Password reset token1 hour
Email verification token24 hours
Desktop session token90 days

Data Retention Periods

Data CategoryRetention Period
Account email & password hashUntil account deleted
Internal user IDUntil account deleted
Workspace configurationsUntil deleted by user or account deletion
Paired device identifiersUntil device unpaired or account deletion
Command history30 days
Security logs (logins, failed attempts, device changes)90 days
Desktop connection logs30 days
Analytics dataUp to 14 months
Crash reports90 days
Support correspondence90 days after account deletion
Transaction & purchase records7 years (legal requirement)
Aggregated anonymised analyticsIndefinite (no PII)

Deleted-account & backup retention

  • Account data marked for deletion — permanently removed from live systems within 30 days of verified request
  • Backup copies — purged within 30 days of deletion from live systems
  • Local device data — not affected by account deletion; users must clear manually

Temporary Data

  • Pairing codes — single-use; expire after 10 minutes and are discarded immediately after use or expiry
  • Remote command relay data — commands in transit are discarded within 60 seconds of delivery or failure
  • Password reset tokens — expire after 1 hour
  • Email verification tokens — expire after 24 hours

Token Storage & Revocation

  • Refresh tokens are hashed before storage — the server cannot retrieve the original token value
  • Pairing requests are single-use — a used or expired pairing code cannot be reused
  • Revoked desktop tokens are rejected on all subsequent connection attempts — the desktop agent will show a disconnected state
  • Secrets and credentials are not written to application or server logs

Access Controls

Access to production data is restricted as follows:

  • Only authorised personnel have access to production systems
  • Access is granted on a need-to-know basis
  • Authentication requires strong passwords and multi-factor authentication where supported
  • All access to production systems is logged and audited
  • Third-party service providers process data under data processing agreements

Desktop Token Revocation

Desktop agent tokens can be revoked in the following ways:

    In-app: Settings → Connected Devices → select desktop → Revoke AccessDesktop Agent: Open the Agent → Revoke Access or Sign OutAccount deletion: All tokens are revoked automaticallyPassword change: All sessions and tokens are invalidated

Breach Response Procedure

In the event of a data breach or security incident involving personal information, we will:

  1. 1Investigate the incident and contain the breach immediately
  2. 2Assess the scope and impact of the breach
  3. 3Notify affected users within 72 hours where required by applicable law
  4. 4Provide affected users with details of what data was involved and steps they should take
  5. 5Report the incident to the Nigeria Data Protection Commission (NDPC) as required
  6. 6Implement measures to prevent recurrence
  7. 7Document the incident and response for compliance purposes

If you suspect a security issue with your account or our services, please contact us immediately at support@creatorstudioslabs.stream.

Contact

For security-related enquiries or to report a vulnerability:

We practice coordinated disclosure and appreciate responsible reports of security issues.