Pretty sure that the gdpr specifically precludes forever retention. Data should be retained as long as is necessary and whether 1, 3, 5, 10 or however many years, sooner or later deletion is appropriate, and the timeline depends on what is reasonable.
3 years is a long time to not log in and if a court decided that it exceeded a 'reasonable' period for legitimate interest the fines can go to 10% of global revenue. The law encourages risk averse behaviour.
They could make a better system where the user sets the timeline but it would be impossible to predict the return.
On this one i think its probably driven by risk management not nefarious intent.