Account data & retention
Export your account data, understand retention and delete the Aroyn account safely.
Where to find it#
Open the avatar menu → Account data in the signed-in dashboard. The page shows retention information and account-scoped export/deletion controls.
Export format and scope#
The download is JSONL: one JSON record per line. It includes the account profile, linked accounts, explicitly associated runtime history and supported stored snapshots. The browser only offers a completed stream with a final completion record.
The export excludes recognized server credentials and other accounts’ records. Arbitrary retained snapshot contents can include sensitive information if a client sent it. Keep the downloaded file private.
Older unassigned history is not claimed merely by matching a Roblox ID. Legacy v1 snapshots are not exported. Account association does not prove Roblox ownership, and export is not a guarantee of recovering every historical occurrence of an ID.
Delete the Aroyn account#
Deletion requires a Discord sign-in within the last 15 minutes and typing DELETE exactly. Cancel or Escape clears the confirmation. Access and keys are revoked first; an HTTP 202 response can mean cleanup is still pending, not that every storage target has already been removed.
After cleanup, a later sign-in creates a new empty Aroyn profile. Sign-in is blocked while the deletion job remains pending. This does not delete your Discord or Roblox accounts.
Retention windows#
| Data | Documented retention |
|---|---|
| Runtime history | 30 days without an update. |
| Stored snapshots | 7 days from the last stored update. |
| Inactive presence rows | 15 minutes; online freshness uses a separate stale window. |
| Profile & account links | Until deletion/unlinking. |
| Web sessions | Up to 30 days, with earlier revocation possible. |
| Anonymous aggregate samples/peaks | Retained without account IDs. |
| Active deletion journal | Minimal internal profile ID/request time, retained for 35 days after activation. |
Daily scheduled cleanup runs in bounded steps with saved progress and retries. Expiration means removal during a successful cleanup, not an exact deletion instant. The source reports an activated private deletion journal on its deployment; it must not be reinitialized during an upgrade.
Remaining boundaries#
Application cleanup cannot remotely erase exports, every browser cache on another device, provider logs or all backups. D1 and R2 are not one transaction. Failed targets leave access revoked and cleanup pending. See the original account-data document for historical verification scope and recovery constraints.