Version 1.4 · Effective 26 September 2026

Child Data Retention Schedule

The written retention policy for children's personal information — required by COPPA §312.10 and the UK Age-Appropriate Design Code. For each data category we set out the purpose, the business need for holding it, and when we delete it. If you want the plain-English overview, read our Children's Privacy Notice.

1. Principle

We keep child personal information for as long as is reasonably necessary to fulfil the purpose for which it was collected, and delete it when that purpose is fulfilled. “Reasonably necessary” is defined per data category below.

2. Retention by category (child-scoped)

Everything below is deleted when the parent either deletes an individual child profile (Parent Zone → trash icon on the profile) or deletes the whole Wundaloom account.

WhatPurposeDeletion triggerDeleted within
Child display name (first name or nickname)Address the child in the UI; identify the child's reading room. Not used as the personalisation input — the parent types a separate story name.Parent deletes child or accountImmediately
Year of birth (optional)Pitch age-appropriate story variants.SameImmediately
Reading events (opened / completed / abandoned / replayed)Reading rhythm, “Books I've read”, recommendations.SameImmediately
Quiz attempts and answersStar grading, mastery display.SameImmediately
Vocabulary words met“Words I've met” dictionary.SameImmediately
Favourites, custom shelves, thumbs-up/down reviewsPersonal Library organisation.SameImmediately
Streak daysReading rhythm calendar.SameImmediately
Personalised story text (text of any edition you created)The parent-purchased personalised story.Parent deletes child or account. Archiving only hides an edition and is reversible — nothing is deleted.Immediately
Personalised narration audio (MP3 files)Read-aloud personalised edition. Optional; runs only with parental AI consent. Withdrawing consent stops new narration but does not delete audio already created.SameWithin 30 days

3. Retention by category (parent-scoped)

WhatPurposeDeletion triggerDeleted within
Email address, password (hash), session tokensAccount identity, sign-in, session.Parent deletes accountImmediately
Parent PIN (hash)Adult-action gate.SameImmediately
Language / reading preferencesUI settings.SameImmediately
Consent records (versioned)COPPA + UK GDPR audit.SameImmediately

4. Deliberate residue after account deletion

The items below are retained AFTER a full-account deletion for defined lawful reasons. None of them contain child personal information in the clear. Each has a finite window justified below.

WhatWhyHeld until
Salted one-way hash of the deleted email (with the same salt, we can identify a re-signup by the same address; we cannot recover the address itself)Fraud prevention + late-refund reconciliation. Under UK GDPR the hash may still be personal data in our hands because we can single someone out; retention is therefore time-bounded.24 months provisionally chosen to cover late refund, reconciliation and fraud investigations; duration pending UK privacy review. Row purged at the end of the window.
Pseudonymous subscription reconciliation records (product identifier, dates; no personal identifiers)Reconciling refund or chargeback events that arrive after the account is deleted.24 months after `reconciled_at`.
Payment-webhook logs (identifying user id nulled on deletion)UK accounting evidence + reconciliation. Only the fields that qualify as UK accounting evidence are retained beyond the standard operational window.The minimum period required by UK tax law (currently: six years from the end of the accounting period they relate to, per HMRC guidance for companies) for records that constitute accounting evidence.
Account-deletion timestamp + platformProve we honoured the deletion request.24 months, then purged with the salted email hash above.

5. What we cannot delete on your behalf

Apple (App Store) and Google (Google Play) retain transaction information independently under their own policies. To ask them to purge records, use their privacy tools or support channels.

Some sub-processors have their own retention windows:

  • OpenAI — text personalisation traffic contains no child real-name identifiers (we send an anonymous placeholder). Personalised narration is optional and runs only with explicit parental consent; the narration request contains the story text, which includes the story name you chose, together with the narration instructions and the chosen voice. Zero Data Retention is not confirmed for the Wundaloom OpenAI project, so OpenAI-side retention of narration requests follows OpenAI's standard API terms, including temporary abuse-monitoring retention, unless and until that arrangement is confirmed.
  • RevenueCat — we ask RevenueCat to delete the customer record when you delete your Wundaloom account. Your Wundaloom data is removed either way.
  • Vercel, Supabase, Cloudflare, Expo — infrastructure log retention per each provider's own policy.

6. How to request deletion or export

Delete an individual child: open Wundaloom → “Who's reading?” → tap the trash icon on that child. Parent PIN required.

Delete the whole account: Parent Zone → Delete account, or visit wundaloom.com/delete-account.

Request a copy of what we hold about you or your children: email support@wundaloom.com from the address on your account. Response within one calendar month per UK GDPR Art 12.

7. Schedule updates

Any change that adds a new data category or shortens/extends a retention window is reflected in the version number at the top of this page. Previous versions are available on request.