Draft — owner/legal review required before production launch.
Profile Deactivation and Deletion
Deactivate
An authenticated member can deactivate from the member area. The application immediately changes the profile from Active to Deactivated, removes it from public search/profile output, prevents sending or receiving new ratings, and revokes active sessions. Application records described in the Privacy Policy remain. Deactivation is reversible only through a fresh Steam OpenID sign-in, acceptance of all current document versions, and a successful own-profile Steam refresh.
Request deletion
An authenticated member can type the displayed confirmation and request deletion. The application immediately sets DeletionPending, records the request time, removes public visibility and rating eligibility, revokes all sessions, and removes ratings authored by or received by the member. This is an operational request, not a claim of immediate physical erasure from every backup.
Administrator completion
An authorized Entra administrator verifies the pending state and runs the restricted completion action. The chosen policy is removal rather than anonymized rating retention; the request already removed authored and received ratings. Completion verifies that state and deletes remaining member-linked aliases, consent, sessions, and profile records under database constraints. A minimal completed request and redacted moderation audit may retain action type, time, and operational evidence without the SteamID64 or public alias.
Backups and exceptional retention
Azure SQL backups or other protected operational copies may contain older data until the configured retention expires and are not edited row-by-row. Restored data must be subject to the deletion ledger/runbook before being returned to service. The owner may need to retain narrowly required evidence for security, dispute, or legal obligations; this draft does not define a new legal guarantee.
Status and contact
The member receives an immediate DeletionPending response before session revocation. The owner must publish a privacy contact for status questions and verified requests made when account access is unavailable. Never send a Steam password or API key to that contact.