Data Retention Policy

Why this policy exists

The U.S. Children's Online Privacy Protection Act (COPPA) requires us to keep a child's personal information only for as long as is reasonably necessary for the purpose we collected it, and to write down - for each kind of information - why we collect it, why we need to keep it, and when we delete it. This policy is that written record. It is also reproduced inside our Privacy Policy, which is the notice we present to you.

Our retention principle

We collect the minimum needed to run parent-managed chores, separately authorized bounded Auto suggestions, AI-assisted chore verification, parent review, and rewards, keep each item only while it serves that purpose, and then delete it. We do not retain children's information indefinitely, build public profiles, train models, run unrelated AI, track children, or advertise to them. When information is no longer reasonably necessary, we delete it and take reasonable measures to protect it during deletion.

What we keep, why, and for how long

• Adult Composer evidence and Activity - Purpose: propose up to three adult-selected chores and verify each against an exclusive after photo in a solo workspace. The first sanitized capture stays in app memory until adult authentication, notice 2026-08-30-composer-v1, and verified paid access succeed. Full locked-before evidence remains only while its batch is active and moves through short-retention deletion after resolution. Each exclusive after object follows the same short-retention deletion path. Separately reduced private before/after thumbnails expire after 90 days. Text title, date, AI outcome, override, and dismissal metadata remains until the item, workspace, or account is deleted. Per-item and delete-all controls queue the related thumbnail deletion. Composer data is stored in separate adult-owned tables and a separate private media bucket; it is never put in child, reward, pairing, or ledger tables.

• Child chore photo (review copy) - Purpose: verify a submitted chore and let you review or correct the decision after you have consented, created the child profile, and paired the child device. Why we keep it briefly: you need to see the work if verification is ambiguous or you want to review history. Deletion: approved evidence is deleted after roughly 72 hours; rejected or disputed evidence may be kept for up to 30 days unless you delete it sooner; abandoned or unconfirmed uploads are deleted after 24 hours. Photo location metadata (EXIF/GPS) is stripped and the image is sanitized on device before upload. Local Vision status, confidence, regions, and bounded errors are diagnostic only and do not reject face-like objects. The photo is uploaded as a private R2-compatible evidence object and parent review uses short-lived authorized download URLs, not public image URLs. If AI verification is enabled, Amazon Nova Pro through AWS Bedrock or GPT-5.6 Luna through OpenAI's global API may process it for the authorized request. OpenAI's separate launch abuse-monitoring retention is described in the Privacy Policy. • Auto Mode before and after evidence - Purpose: after the separate 2026-07-30-auto-mode-v1 parent authorization, propose up to three bounded chores grounded in one sanitized before photo and verify each committed chore against its own sanitized after photo. One physical before object may support up to three committed chores without duplicating bytes; each after object belongs to exactly one chore and submission. The before object is locked against child replacement and retained only while an issued set or linked chore needs it for verification or parent review. After that, before and after evidence follow the same 24-hour abandoned, roughly 72-hour approved, and up-to-30-day rejected or disputed limits. • Parent room capture - Purpose: create an editable Manual chore draft or propose AI chores from a room or area selected by a parent through Amazon Nova Pro on AWS Bedrock or GPT-5.6 Luna through OpenAI's global API, and compare a linked chore's original room state with its completion photo when AI verification is enabled. The raw original is released after diagnostic Vision, metadata removal, 1024-pixel JPEG sanitation, and preview decoding. A local Vision candidate or error alone does not fail the capture. After room-photo notice 2026-08-30-before-after-verification-v3, the exact sanitized derivative is stored once in a dedicated private bucket and linked to all chores saved from that capture. It is deleted after the final unlink, child or household deletion, or after 24 hours if an upload is never linked. Paid expiry or revocation downgrades the household to Free and does not delete retained room references. Unsaved copies remain only in parent-shell memory until discard, sign-out, or final teardown. Child submissions use separate short-retention evidence even when compared with a linked room reference. • Account-deletion entitlement continuity - Purpose: allow an adult who permanently deletes Tidiest data without canceling an active Apple subscription to restore compatible paid access to a new empty account. The record contains only the hashed Apple subject, Apple's original transaction identifier, prior household identifier, product family, and creation time. It contains no child, chore, Activity, evidence, consent, reward, pairing, usage, or workspace settings and is consumed when the same freshly authenticated Apple identity restores the subscription. • Points ledger and balance - Purpose: track points earned and redeemed. Contents: identifiers, integers, and cryptographic signatures only—no names or photos. Deletion: retained while the household exists; removed when you delete the child or account. • Chore submissions, limited chore/reward records, and reward redemptions - Purpose: let the app enforce balances and give you household history. Deletion: retained while the household exists; removed when you delete the child or account. • Parent-supplied manual reward codes - Purpose: let a parent attach one single-use code to a reward. Contents: encrypted code, optional PIN or redemption URL/instructions, optional descriptive face value/currency, reservation state, and identifiers. Codes are never written to point ledgers, balances, logs, analytics, or menu/redemption lists. Deletion: archived by the parent or removed with the child or household. • Device pairing code and credential - Purpose: let a child's device join the household and remain paired while access is paused. The one-time code becomes unusable after 24 hours. The stable credential remains while the device is paired unless the parent revokes it or deletes the child or account. • Parental consent record - Purpose: evidence that verifiable parental consent was obtained. Contents: a version stamp and timestamp—no contact details beyond your own account. Deletion: retained while the household exists and removed with the applicable child or account data. • Age-verification signal - Purpose: a one-time check that the person setting up the app is an adult. Deletion: never stored - it is reduced to a yes/no result and immediately discarded, and is never reused for the child's age. • Child nickname, consent record, pairing, and private display symbol - Purpose: operate and label the private household workflow and preserve proof of consent. Deletion: retained while the household exists; deleted when the child, pairing, or account is deleted. The symbol is not sent to public mirrors, AI prompts, photos, signed point ledgers, balances, analytics, or purchase surfaces.

• Retired parent transactional-email records - Tidiest sends no new subscription email. Historical sent-notice status, opaque provider identifiers, and timestamps remain with the household record until account deletion; unfinished email notices are canceled, and ephemeral canary records are removed.

How deletion actually happens

Your family's household data lives in Cloudflare D1 and household mutations are serialized through Durable Objects. Sanitized child evidence and retained room references live in separate private R2-compatible buckets. Review evidence keeps its independent short window: abandoned uploads about 24 hours, approved evidence about 72 hours, and rejected or disputed evidence up to 30 days. Cancellation or expiry of an Auto chore does not restore the household's daily quota; shared before evidence is released only after no linked chore still needs it. Revoking Auto authorization turns every child's Auto policy off and prevents new Auto processing, while existing evidence continues only for deletion or any still-applicable parent review window. Paid expiry or revocation downgrades the household to Free and turns every child's Auto policy off; it does not queue retained room references or structured data for deletion. Immediate parent-requested child or account deletion queues the applicable complete purge; account deletion does not cancel the Apple subscription. Retryable failures use the deletion Queue and DLQ.

Your rights as a parent

You can review your child's before and after photos and verification decisions, correct decisions where the app allows it, disable AI verification, revoke Auto Mode authorization, delete a child's information using the in-app controls, request deletion of your entire account through an authenticated deletion request or by contacting us at [email protected], and revoke child-photo submission consent at any time. Withdrawing consent disables further child photo collection and Auto processing.

Changes & contact

If we materially change what we keep or for how long, we will update this policy and the Privacy Policy and ask you to review the change. Questions: Tidiest LLC, 12851 Tilden Dr., Rancho Cucamonga, CA, United States · +1 (909) 646-2488 · [email protected].