Categories of data
Account identifiers, optional email, OAuth tokens, chat payloads, moderation logs tied to incidents, and technical telemetry needed for uptime/security.
Legal bases
Contract performance for signed-in users, legitimate interests for fraud prevention, consent where cookies exceed strict necessity — aligned with GDPR-style transparency.
Retention
Messages persist until user deletion or overriding legal hold. Security logs rotate on a schedule documented internally and available upon authenticated account inquiry.