What we keep, and for how long
Version 1, in effect since 15 September 2026.
Nothing here is kept indefinitely except the evidence that we asked permission, and that goes when the account goes.
The table
| What | How long | From when |
|---|---|---|
| A removed reader's books and pictures | 30 days | the reader is removed. The delay is so a parent who changes their mind can undo it. |
| A removed reader's profile | 30 days | the reader is removed. |
| A closed account, its sign-in and everything under it | 30 days | the account is closed. |
| A child's sign-in sessions | 30 days | the session expires. |
| Records of books being made, and what they cost | 90 days | the record is written. Long enough to reconcile a bill or explain a failure. |
| Payment events from our payment provider | 90 days | the event arrives. |
| A record of mail we sent you | 90 days | the message is sent. The row holds the address it went to, so it is not kept longer than a delivery question would take. |
| Safety decisions that have been dealt with | 90 days | the decision is resolved. An unresolved one is kept until somebody has looked at it. |
| An account nobody has signed in to | 365 days, then a 14-day warning | the last sign-in. Written to first and removed a fortnight later. Signing in stops the clock. |
| Consent records and the audit trail | kept while the account exists | never, while the account exists. They are the evidence that consent was obtained and what was done with it. They go when the account goes. |
| Card details | not held by us | held by our payment provider, never by us. We keep a one-way fingerprint of the card and nothing else. |
How it is enforced
A job runs every day at three in the morning and deletes what is past its window. It is not a reminder to somebody; it is the thing that does it. Every run writes what it removed to the audit trail, so there is a record that the policy ran even though the data it removed has gone.
Pictures live outside the database. They are deleted before the rows that point at them, so a file is never left behind with nothing referring to it.
The thirty days
Removing a reader, or closing an account, does not delete anything that day. It marks it, and the deletion happens thirty days later. This is deliberate: a deletion by accident is the one mistake a family cannot undo for themselves, and thirty days is long enough to notice. During that time the reader disappears from the app and no new books can be made for them. Cancelling is a single button in settings.
Quiet accounts
An account nobody has signed in to for 365 days is written to, and removed 14 days after that letter. The letter is the point: before it existed, the first a family heard about this was that their books had gone. Signing in clears the mark and starts the clock again.
A family can ask us for a longer window, and we can set one on their account. The job honours it.
What is not deleted on a schedule
Consent records and the audit trail. They are the evidence that consent was obtained and what was done with it, and a record that could be quietly removed would not be evidence of anything. They are deleted when the account is deleted, as part of it.
Changing this policy
The version number here goes up and the date changes. Shortening a window applies to everything already held; lengthening one never applies retroactively to something already deleted, because it is already gone.