Version 1.0 · Effective 14 August 2026

Child Data Retention Schedule

The written retention policy for children's personal information — required by COPPA §312.10 and the UK Age-Appropriate Design Code. For each data category we set out the purpose, the business need for holding it, and when we delete it. If you want the plain-English overview, read our Children's Privacy Notice.

1. Principle

We keep child personal information for as long as is reasonably necessary to fulfil the purpose for which it was collected, and delete it when that purpose is fulfilled. “Reasonably necessary” is defined per data category below.

2. Retention by category (child-scoped)

Everything below is deleted when the parent either deletes an individual child profile (Parent Zone → trash icon on the profile) or deletes the whole Wundaloom account.

WhatPurposeDeletion triggerDeleted within
Child display name (first name or nickname)Address the child in the UI; personalisation input; identify the child's reading room.Parent deletes child or accountImmediately
Birth month + year (optional)Pitch age-appropriate story variants.SameImmediately
Reading events (opened / completed / abandoned / replayed)Reading rhythm, “Books I've read”, recommendations.SameImmediately
Quiz attempts and answersStar grading, mastery display.SameImmediately
Vocabulary words met“Words I've met” dictionary.SameImmediately
Favourites, custom shelves, thumbs-up/down reviewsPersonal Library organisation.SameImmediately
Streak days and earned badgesReading rhythm calendar; Dream Keeper level.SameImmediately
Personalised story text (text of any edition you created)The parent-purchased personalised story.Parent archives edition, deletes child, or deletes accountImmediately
Personalised narration audio (MP3 files)Read-aloud personalised edition. Currently unavailable at launch.SameWithin 30 days

3. Retention by category (parent-scoped)

WhatPurposeDeletion triggerDeleted within
Email address, password (hash), session tokensAccount identity, sign-in, session.Parent deletes accountImmediately
Parent PIN (hash)Adult-action gate.SameImmediately
Language / reading preferencesUI settings.SameImmediately
Consent records (versioned)COPPA + UK GDPR audit.SameImmediately

4. Deliberate residue after account deletion

The items below are retained AFTER a full-account deletion for defined lawful reasons. None of them contain child personal information in the clear. Each has a finite window justified below.

WhatWhyHeld until
Salted one-way hash of the deleted email (with the same salt, we can identify a re-signup by the same address; we cannot recover the address itself)Fraud prevention + late-refund reconciliation. Under UK GDPR the hash may still be personal data in our hands because we can single someone out; retention is therefore time-bounded.24 months provisionally chosen to cover late refund, reconciliation and fraud investigations; duration pending UK privacy review. Row purged at the end of the window.
Pseudonymous subscription reconciliation records (product identifier, dates; no personal identifiers)Reconciling refund or chargeback events that arrive after the account is deleted.24 months after `reconciled_at`.
Payment-webhook logs (identifying user id nulled on deletion)UK accounting evidence + reconciliation. Only the fields that qualify as UK accounting evidence are retained beyond the standard operational window.The minimum period required by UK tax law (currently: six years from the end of the accounting period they relate to, per HMRC guidance for companies) for records that constitute accounting evidence.
Account-deletion timestamp + platformProve we honoured the deletion request.24 months, then purged with the salted email hash above.

5. What we cannot delete on your behalf

Apple (App Store) and Google (Google Play) retain transaction information independently under their own policies. To ask them to purge records, use their privacy tools or support channels.

Some sub-processors have their own retention windows:

  • OpenAI — text personalisation traffic contains no child real-name identifiers (we send an anonymous placeholder). Personalised narration remains disabled until the Wundaloom OpenAI project is confirmed for the required data-control configuration; OpenAI-side retention will then follow that confirmed configuration and OpenAI's applicable Zero Data Retention / safety-retention terms.
  • RevenueCat — the customer record is deleted from RevenueCat by our server when you delete your Wundaloom account.
  • Vercel, Supabase, Cloudflare, Expo — infrastructure log retention per each provider's own policy.

6. How to request deletion or export

Delete an individual child: open Wundaloom → “Who's reading?” → tap the trash icon on that child. Parent PIN required.

Delete the whole account: Parent Zone → Delete account, or visit wundaloom.com/delete-account.

Request a copy of what we hold about you or your children: email support@wundaloom.com from the address on your account. Response within one calendar month per UK GDPR Art 12.

7. Schedule updates

Any change that adds a new data category or shortens/extends a retention window is reflected in the version number at the top of this page. Previous versions are available on request.