What we keep, and for how long

Version 1, in effect since 15 September 2026.

Nothing here is kept indefinitely except the evidence that we asked permission, and that goes when the account goes.

The table

WhatHow longFrom when
A removed reader's books and pictures30 daysthe reader is removed. The delay is so a parent who changes their mind can undo it.
A removed reader's profile30 daysthe reader is removed.
A closed account, its sign-in and everything under it30 daysthe account is closed.
A child's sign-in sessions30 daysthe session expires.
Records of books being made, and what they cost90 daysthe record is written. Long enough to reconcile a bill or explain a failure.
Payment events from our payment provider90 daysthe event arrives.
A record of mail we sent you90 daysthe message is sent. The row holds the address it went to, so it is not kept longer than a delivery question would take.
Safety decisions that have been dealt with90 daysthe decision is resolved. An unresolved one is kept until somebody has looked at it.
An account nobody has signed in to365 days, then a 14-day warningthe last sign-in. Written to first and removed a fortnight later. Signing in stops the clock.
Consent records and the audit trailkept while the account existsnever, while the account exists. They are the evidence that consent was obtained and what was done with it. They go when the account goes.
Card detailsnot held by usheld by our payment provider, never by us. We keep a one-way fingerprint of the card and nothing else.

How it is enforced

A job runs every day at three in the morning and deletes what is past its window. It is not a reminder to somebody; it is the thing that does it. Every run writes what it removed to the audit trail, so there is a record that the policy ran even though the data it removed has gone.

Pictures live outside the database. They are deleted before the rows that point at them, so a file is never left behind with nothing referring to it.

The thirty days

Removing a reader, or closing an account, does not delete anything that day. It marks it, and the deletion happens thirty days later. This is deliberate: a deletion by accident is the one mistake a family cannot undo for themselves, and thirty days is long enough to notice. During that time the reader disappears from the app and no new books can be made for them. Cancelling is a single button in settings.

Quiet accounts

An account nobody has signed in to for 365 days is written to, and removed 14 days after that letter. The letter is the point: before it existed, the first a family heard about this was that their books had gone. Signing in clears the mark and starts the clock again.

A family can ask us for a longer window, and we can set one on their account. The job honours it.

What is not deleted on a schedule

Consent records and the audit trail. They are the evidence that consent was obtained and what was done with it, and a record that could be quietly removed would not be evidence of anything. They are deleted when the account is deleted, as part of it.

Changing this policy

The version number here goes up and the date changes. Shortening a window applies to everything already held; lengthening one never applies retroactively to something already deleted, because it is already gone.