Data Retention & Deletion Policy
Version 2026-08-05-v1 · Effective date: [to be set on adoption]
Draft — not yet in force. This policy is under attorney review and does not take effect until an effective date is set above. It describes how StoryKinder is actually built, and we publish it now so parents can read it before we ask for anything.
For each kind of information we hold, this states what it is, why we collected it, why we need to keep it, and when it is deleted. It forms part of our privacy notice.
Principles
- We collect as little about a child as the service can function on.
- We keep it only as long as reasonably necessary for the purpose it was collected for.
- We never keep it indefinitely. Every category below has a deletion trigger.
- A parent can delete a child’s information at any time, and that deletion takes precedence over every schedule here.
Children’s information
| Category | Why collected | Why we keep it | Deleted |
|---|---|---|---|
| Child profile — nickname, avatar, optional age band | Separate each child’s reading within the family account | Needed continuously while the child uses the service | On parent deletion, or 90 days after account closure, or 24 months of profile inactivity |
| Reading progress — position in a story, choices made | Resume where the child left off | Needed while the book is in progress | With the profile, or 12 months after last activity on that book |
| Reading events — book opened, completed, ending reached, word tapped | Build the reading journal; pay authors; understand aggregate usage | The journal is a persistent record the child returns to, and author royalties need a verifiable completion record for the payment period | With the profile. Individual events de-identified after 24 months, retaining only aggregate counts |
| Journal and achievements — badges earned, words learned, streaks | The child’s record of their own reading | Core feature; its value is cumulative over years | With the profile |
| Request logs containing a child-profile identifier | Security, fraud prevention, debugging | Short-term operational need only | 30 days |
Parent information
| Category | Why collected | Deleted |
|---|---|---|
| Account email and authentication record | Account access, service and parental notices | 90 days after account closure |
| Parental consent records | Legal proof that consent was obtained | 7 years after consent is withdrawn or the account closes |
| Billing records — subscription status, card last four, processor reference | Billing, refunds, tax and accounting obligations | 7 years, per tax recordkeeping requirements |
| Support correspondence | Answering and resolving | 24 months after resolution |
| Email collected for a direct notice where consent was never given | To deliver the notice | 30 days if consent is not given |
A note on consent records: these prove we complied. They are records about the parent — method, timestamp, policy version, scope — and contain no child personal information. We keep them longer than anything else on purpose.
Deletion on request
A parent can delete a child profile at any time from the Parent Dashboard, or by emailing legal@storykinder.com.
Deletion is permanent and cascading. It removes the profile, all reading progress, all reading events, and all journal entries and achievements. It cannot be undone, and we say so before you confirm.
| Stage | Timeframe |
|---|---|
| Removed from the live service | Immediately |
| Purged from primary systems | Within 30 days |
| Purged from backups | Within 90 days, as backups age out on their normal cycle |
Our backups are managed by our hosting provider on a rolling window, so a single record cannot be surgically removed from a backup that already exists. The record is deleted from the live service immediately, is not accessible in backups except in a restore, and ages out entirely within the window above.
Aggregated and de-identified information
We keep aggregate statistics — total books completed, total words learned across all readers, book popularity — indefinitely. These contain no personal information, cannot be linked back to a child, and are used to operate the service, compute author royalties, and understand what children read.
StoryKinder pays its authors from its own revenue, and a closed payment period’s completion counts form part of our financial records, retained accordingly. Deleting a child profile removes that child’s individual events; it does not retroactively alter a closed period’s totals.
Inactivity deletion
A child profile with no reading activity for 24 months is deleted. We email the parent 30 days beforehand so they can keep it by having the child read something. An account with no sign-in for 36 months is closed and its data deleted after 30 days’ notice by email.
This is what makes “no indefinite retention” true in practice rather than only on paper.
How this is enforced
These schedules take effect on the effective date above. From that date, retention is enforced by automated scheduled jobs rather than by manual review: jobs are monitored, failures are treated as incidents under our security program, and we verify monthly that each job ran and deleted what was due.
Deletion you request yourself does not wait for any of that. It runs immediately, on the timetable in the table above.
Changes
Material changes are notified to parents by email. Each version carries an identifier, and we record which version was in force when consent was given. See also our Privacy Policy.
Contact
TradePals LLCPrivacy and legal: legal@storykinder.com
Everything else: support@storykinder.com
[STREET ADDRESS], San Antonio, TX [ZIP] · [PHONE]
