Nocturify Account Deletion & Data Retention

Version: 1.0

Effective:

Version: 1.0 Last updated: 8 August 2026

This notice explains how account deletion works in Nocturify and how information may be retained after an account is deleted or no longer used.

It should be read together with the Nocturify Privacy Policy and Terms of Service.

1. Deleting Your Nocturify account

Eligible consumer accounts can be deleted through the account settings available in the Nocturify application.

Account deletion is intended to permanently remove the consumer account rather than merely sign You out or temporarily deactivate it.

For security, Nocturify may require You to reauthenticate before an account-deletion request is accepted.

Once an eligible account has been successfully deleted, You should no longer be able to sign in using the deleted account credentials.

2. What is generally deleted with a consumer account?

Nocturify’s current account architecture is designed so that deleting an eligible consumer authentication identity also removes associated consumer-owned records according to the applicable deletion rules.

These records may include:

The exact technical implementation may evolve, but Nocturify’s principle is that ordinary consumer-account information should not be retained indefinitely without a valid reason after the account has been deleted.

3. Authentication identity and sessions

Successful consumer-account deletion removes the relevant Nocturify authentication identity.

The application also clears applicable local session and account state.

After deletion:

Some technical device or application information that is not itself part of the deleted account may remain where necessary for normal application operation or security.

4. Profile images

Where a profile image is associated with the deleted consumer account, Nocturify intends to remove the corresponding account-owned profile image as part of the account-deletion process.

Because file storage and authentication systems are separate technical systems, file cleanup may occasionally require additional reconciliation after the account itself has already been deleted.

Nocturify aims to identify and remove orphaned account-owned profile files where such a cleanup issue occurs.

This does not mean that account deletion may be falsely reported as unsuccessful after the authentication identity has already been permanently deleted.

5. Community reports

Under the current consumer-account model, reports directly associated with the deleted consumer account are configured to be removed with that account.

Aggregated information previously calculated from multiple community contributions may not necessarily represent an identifiable individual after the underlying account information has been removed.

Nocturify may maintain aggregate or statistical information that no longer identifies or is no longer reasonably linked to the deleted individual where permitted by applicable law.

6. NightMiles

NightMiles records associated with an eligible deleted consumer account are currently configured to be removed according to the consumer-account deletion rules.

Deleting an account therefore ends access to that account’s NightMiles balance and related consumer reward history.

NightMiles cannot be transferred to another account merely because an account is being deleted.

If future redemption, settlement or legally relevant transaction functionality requires different retention, the applicable rules and disclosures will be updated before such processing is introduced where required.

Nocturify records the versions of applicable legal documents accepted by a user.

Under the current consumer-account architecture, consumer legal-acceptance records are configured to be removed with the deleted authentication identity.

Nocturify may review this retention model as legal, accountability or evidentiary requirements develop.

If Nocturify determines that particular acceptance evidence must lawfully be retained after account deletion, the applicable retention rules and Privacy Policy will be updated before materially changing the deletion model where required.

Nocturify may maintain limited user-specific technical state for AI-assisted features, such as:

Current user-specific AI control records that are directly tied to the consumer authentication identity are configured to be removed with that account.

Some AI infrastructure records are shared rather than owned by one user. Examples may include:

Shared technical records are not necessarily deleted when one consumer account is deleted because they do not represent that consumer’s account record.

Nocturify aims to avoid storing unnecessary directly identifying information in shared AI infrastructure.

9. Operational, venue and partner accounts

Some Nocturify accounts may have responsibilities beyond ordinary consumer use.

For example, an account may be associated with:

Some of these records may need to remain intact for security, accountability, contractual, fraud-prevention, operational or legal reasons.

For this reason, an account connected to protected operational records may not be eligible for immediate self-service deletion.

Instead, Nocturify may require an assisted offboarding or de-identification process.

If self-service deletion is unavailable for Your account, contact:

support@nocturify.com

10. What assisted offboarding may involve

Depending on the account’s responsibilities, assisted offboarding may involve:

The purpose is not to prevent legitimate deletion requests.

The purpose is to avoid destroying operational or audit history that must appropriately remain while still respecting the individual’s applicable data-protection rights.

11. Venue and moderation history

Certain operational records may preserve historical information about actions taken on the platform even after the individual who performed the action no longer has an active account.

Where appropriate, direct user references may be removed or replaced while the underlying operational event remains.

This can be necessary to preserve information such as:

Retention of such information remains subject to applicable data-protection law and the principles of necessity and data minimization.

12. Aggregated and de-identified information

Deleting an account does not necessarily require deletion of information that has been genuinely aggregated or de-identified so that it no longer identifies or is no longer reasonably linked to the individual.

Nocturify may retain such information for purposes including:

Nocturify should not use the label “aggregated” merely to avoid deleting information that remains reasonably identifiable.

Where information can still reasonably be linked to an individual, it remains subject to applicable data-protection requirements.

13. Security and abuse-prevention information

In limited circumstances, Nocturify may retain information after account deletion where reasonably necessary and legally permitted to:

Such retention should be limited to what is reasonably necessary for the relevant purpose.

Account deletion is not intended to provide a mechanism for destroying evidence of fraud, abuse, security incidents or unlawful activity where lawful retention is justified.

14. Backups and technical copies

Deleted information may remain temporarily in protected technical backups or system copies where immediate deletion from every backup is not technically practical.

Where this occurs:

Nocturify will apply appropriate technical and organizational safeguards to retained backup information.

15. Retention periods

Nocturify does not apply one universal retention period to every category of information.

Retention depends on factors such as:

Where a specific fixed retention period is appropriate, Nocturify may define that period in its internal retention rules or applicable user-facing disclosure.

We do not intend to keep identifiable personal data indefinitely merely because storage is technically possible.

16. Unconfirmed accounts

Creating an account may create certain technical account, profile and legal-acceptance records before email verification is completed.

If an account does not successfully complete required email verification, Nocturify intends to automatically delete the unverified account and associated account-linked consumer records 30 days after the account was created.

This 30-day period is intended to provide a reasonable opportunity to complete verification while preventing abandoned unverified accounts from being retained indefinitely.

The automatic deletion may be delayed or limited where retention is reasonably necessary and legally permitted for purposes such as:

Successfully verifying the account before the applicable deletion point means the account is no longer treated as an unconfirmed account under this 30-day rule.

17. Deletion is different from signing out

Signing out does not delete Your account.

Signing out ends or removes the active local session as applicable, but Your Nocturify account and associated server-side information continue to exist.

To permanently delete an eligible consumer account, use the account-deletion functionality provided in Nocturify.

18. Deletion requests and GDPR rights

Account deletion through the application is one way Nocturify supports deletion of eligible consumer accounts.

It does not replace Your other rights under applicable data-protection law.

Depending on the circumstances, You may have rights to:

Some rights may be subject to legal limitations or exceptions.

For privacy or data-rights requests, contact:

support@nocturify.com

We may need to verify Your identity before processing a request.

19. Changes to deletion or retention practices

Nocturify’s account model and features may develop over time.

If we materially change:

we will update the relevant Nocturify disclosures where required before or when those changes take effect.

This Account Deletion & Data Retention notice should be read together with:

For questions about account deletion, retention or Your personal data:

support@nocturify.com