Data Retention Policy

Why this policy exists

The U.S. Children's Online Privacy Protection Act (COPPA) requires us to keep a child's personal information only for as long as is reasonably necessary for the purpose we collected it, and to write down - for each kind of information - why we collect it, why we need to keep it, and when we delete it. This policy is that written record. It is also reproduced inside our Privacy Policy, which is the notice we present to you.

Our retention principle

We collect the minimum needed to run parent-managed chores, AI-assisted chore verification, parent review, and rewards, keep each item only while it serves that purpose, and then delete it. We do not retain children's information indefinitely, build public profiles, train models, run unrelated AI, track children, or advertise to them. When information is no longer reasonably necessary, we delete it and take reasonable measures to protect it during deletion.

What we keep, why, and for how long

• Child chore photo (review copy) - Purpose: verify a submitted chore and let you review or override the decision after you have consented, created the child profile, and paired the child device. Why we keep it briefly: you need to see the work if verification is ambiguous or you want to review history. Deletion: approved evidence is deleted after roughly 72 hours; rejected or disputed evidence may be kept for up to 30 days unless you delete it sooner; abandoned or unconfirmed uploads are deleted after 24 hours. Photo location metadata (EXIF/GPS) is stripped on the device before upload. The photo is uploaded as a private R2-compatible evidence object and parent review uses short-lived authorized download URLs, not public image URLs. If AI verification is enabled, the Worker and Bedrock process the verification image only transiently and do not store it outside the evidence-retention window. • Parent room-planning image - Purpose: propose editable chores from a room or area selected by a parent through Amazon Nova Pro on Amazon Bedrock. Deletion: discarded when suggestions return by default. After the separate quest-reference notice, the complete sanitized single-photo derivative may be stored in a dedicated private bucket and linked to saved chores. It is queued for deletion when Family access expires or is revoked and is never restored. It is also deleted after the final unlink, child or household deletion, or after 24 hours if an upload is never linked. Child submissions use the separate consent-gated /verify-chore path, not room planning. • Points ledger and balance - Purpose: track points earned and redeemed. Contents: identifiers, integers, and cryptographic signatures only—no names or photos. Deletion: retained during active access and the 12-calendar-month recovery window; removed at final deletion or sooner when you delete the child or account. • Chore submissions, limited chore/reward records, and reward redemptions - Purpose: let the app enforce balances and give you household history. Deletion: retained during active access and the 12-calendar-month recovery window; removed at final deletion or sooner when you delete the child or account. • Parent-supplied manual reward codes - Purpose: let a parent attach one single-use code to a reward. Contents: encrypted code, optional PIN or redemption URL/instructions, optional descriptive face value/currency, reservation state, and identifiers. Codes are never written to point ledgers, balances, logs, analytics, or menu/redemption lists. Deletion: archived by the parent or removed with the child or household. • Device pairing code and credential - Purpose: let a child's device join the household and remain paired while access is paused. The one-time code becomes unusable after 24 hours. The stable credential follows the structured-data recovery window unless the parent revokes it or deletes the child or account sooner. • Parental consent record - Purpose: evidence that verifiable parental consent was obtained. Contents: a version stamp and timestamp—no contact details beyond your own account. Deletion: follows the structured-data recovery window; renewed consent is required before restored child data reopens. • Age-verification signal - Purpose: a one-time check that the person setting up the app is an adult. Deletion: never stored - it is reduced to a yes/no result and immediately discarded, and is never reused for the child's age. • Child nickname, consent record, pairing, and private display symbol - Purpose: operate and label the private household workflow and preserve proof of consent. Deletion: retained during active access and the 12-calendar-month recovery window; deleted at final deletion or sooner when the child, pairing, or account is deleted. Renewed consent is required before restored child data reopens. The symbol is not sent to public mirrors, Bedrock prompts, photos, signed point ledgers, balances, analytics, or purchase surfaces.

How deletion actually happens

Your family's household data lives in Cloudflare D1 and household mutations are serialized through Durable Objects. Sanitized child evidence and opted-in room references live in separate private R2-compatible buckets. Review evidence keeps its independent short window: abandoned uploads about 24 hours, approved evidence about 72 hours, and rejected or disputed evidence up to 30 days. When Family access expires or is revoked, room-reference objects and metadata are queued for immediate deletion and are not restored. Structured household, child, chore, ledger, reward, and pairing data remains recoverable for 12 calendar months. We send best-effort parent-only warnings 30 and 7 days before final deletion. Resubscription before deletion starts cancels structured deletion and warnings. Once deletion starts, recovery closes. Immediate account deletion bypasses recovery and queues the same complete purge; it does not cancel the Apple subscription. Retryable failures use the deletion Queue and DLQ.

Your rights as a parent

You can review your child's photos and verification decisions, correct decisions where the app allows it, disable AI verification, delete a child's information using the in-app controls, request deletion of your entire account through an authenticated deletion request or by contacting us at [email protected], and revoke child-photo submission consent at any time. Withdrawing consent disables further child photo collection.

Changes & contact

If we materially change what we keep or for how long, we will update this policy and the Privacy Policy and ask you to review the change. Questions: Tidiest LLC, 12851 Tilden Dr., Rancho Cucamonga, CA, United States · +1 (909) 646-2488 · [email protected].