Version 1.0 · Effective 14 August 2026
Child Data Retention Schedule
The written retention policy for children's personal information — required by COPPA §312.10 and the UK Age-Appropriate Design Code. For each data category we set out the purpose, the business need for holding it, and when we delete it. If you want the plain-English overview, read our Children's Privacy Notice.
1. Principle
We keep child personal information for as long as is reasonably necessary to fulfil the purpose for which it was collected, and delete it when that purpose is fulfilled. “Reasonably necessary” is defined per data category below.
2. Retention by category (child-scoped)
Everything below is deleted when the parent either deletes an individual child profile (Parent Zone → trash icon on the profile) or deletes the whole Wundaloom account.
| What | Purpose | Deletion trigger | Deleted within |
|---|---|---|---|
| Child display name (first name or nickname) | Address the child in the UI; personalisation input; identify the child's reading room. | Parent deletes child or account | Immediately |
| Birth month + year (optional) | Pitch age-appropriate story variants. | Same | Immediately |
| Reading events (opened / completed / abandoned / replayed) | Reading rhythm, “Books I've read”, recommendations. | Same | Immediately |
| Quiz attempts and answers | Star grading, mastery display. | Same | Immediately |
| Vocabulary words met | “Words I've met” dictionary. | Same | Immediately |
| Favourites, custom shelves, thumbs-up/down reviews | Personal Library organisation. | Same | Immediately |
| Streak days and earned badges | Reading rhythm calendar; Dream Keeper level. | Same | Immediately |
| Personalised story text (text of any edition you created) | The parent-purchased personalised story. | Parent archives edition, deletes child, or deletes account | Immediately |
| Personalised narration audio (MP3 files) | Read-aloud personalised edition. Currently unavailable at launch. | Same | Within 30 days |
3. Retention by category (parent-scoped)
| What | Purpose | Deletion trigger | Deleted within |
|---|---|---|---|
| Email address, password (hash), session tokens | Account identity, sign-in, session. | Parent deletes account | Immediately |
| Parent PIN (hash) | Adult-action gate. | Same | Immediately |
| Language / reading preferences | UI settings. | Same | Immediately |
| Consent records (versioned) | COPPA + UK GDPR audit. | Same | Immediately |
4. Deliberate residue after account deletion
The items below are retained AFTER a full-account deletion for defined lawful reasons. None of them contain child personal information in the clear. Each has a finite window justified below.
| What | Why | Held until |
|---|---|---|
| Salted one-way hash of the deleted email (with the same salt, we can identify a re-signup by the same address; we cannot recover the address itself) | Fraud prevention + late-refund reconciliation. Under UK GDPR the hash may still be personal data in our hands because we can single someone out; retention is therefore time-bounded. | 24 months provisionally chosen to cover late refund, reconciliation and fraud investigations; duration pending UK privacy review. Row purged at the end of the window. |
| Pseudonymous subscription reconciliation records (product identifier, dates; no personal identifiers) | Reconciling refund or chargeback events that arrive after the account is deleted. | 24 months after `reconciled_at`. |
| Payment-webhook logs (identifying user id nulled on deletion) | UK accounting evidence + reconciliation. Only the fields that qualify as UK accounting evidence are retained beyond the standard operational window. | The minimum period required by UK tax law (currently: six years from the end of the accounting period they relate to, per HMRC guidance for companies) for records that constitute accounting evidence. |
| Account-deletion timestamp + platform | Prove we honoured the deletion request. | 24 months, then purged with the salted email hash above. |
5. What we cannot delete on your behalf
Apple (App Store) and Google (Google Play) retain transaction information independently under their own policies. To ask them to purge records, use their privacy tools or support channels.
Some sub-processors have their own retention windows:
- OpenAI — text personalisation traffic contains no child real-name identifiers (we send an anonymous placeholder). Personalised narration remains disabled until the Wundaloom OpenAI project is confirmed for the required data-control configuration; OpenAI-side retention will then follow that confirmed configuration and OpenAI's applicable Zero Data Retention / safety-retention terms.
- RevenueCat — the customer record is deleted from RevenueCat by our server when you delete your Wundaloom account.
- Vercel, Supabase, Cloudflare, Expo — infrastructure log retention per each provider's own policy.
6. How to request deletion or export
Delete an individual child: open Wundaloom → “Who's reading?” → tap the trash icon on that child. Parent PIN required.
Delete the whole account: Parent Zone → Delete account, or visit wundaloom.com/delete-account.
Request a copy of what we hold about you or your children: email support@wundaloom.com from the address on your account. Response within one calendar month per UK GDPR Art 12.
7. Schedule updates
Any change that adds a new data category or shortens/extends a retention window is reflected in the version number at the top of this page. Previous versions are available on request.