Data Retention Policy
Why this policy exists
The U.S. Children's Online Privacy Protection Act (COPPA) requires us to keep a member's personal information only for as long as is reasonably necessary for the purpose we collected it, and to write down - for each kind of information - why we collect it, why we need to keep it, and when we delete it. This policy is that written record and forms part of our Privacy Policy.
Our retention principle
We collect the minimum needed to run household manager-managed chores, separately authorized bounded Auto suggestions, AI-assisted chore verification, household manager review, and rewards, keep each item only while it serves that purpose, and then delete it. We do not retain members' information indefinitely, build public profiles, train models, run unrelated AI, track members, or advertise to them. When information is no longer reasonably necessary, we delete it and take reasonable measures to protect it during deletion.
What we keep, why, and for how long
• Adult Composer evidence and Activity - Purpose: propose up to six adult-selected chores and verify each against an exclusive after photo in a solo workspace. The first sanitized capture stays in app memory until adult authentication, notice 2026-08-30-composer-v1, and verified Free or paid access succeed. Full before photos remains only while its batch is active and moves through short-retention deletion after resolution. Each after photo follows the same short-retention deletion path. Separately reduced private before/after thumbnails expire after 90 days. Text title, date, AI outcome, override, and dismissal metadata remains until the item, workspace, or account is deleted. Per-item and delete-all controls queue the related thumbnail deletion. Composer information is private to the adult workspace and is not used as member, pairing, points, or reward information.
• Member chore photo (review copy) - Purpose: verify a submitted chore and let you review or correct the decision after you have consented, created the member profile, and paired the member device. Why we keep it briefly: you need to see the work if verification is ambiguous or you want to review history. Deletion: approved evidence is deleted after roughly 72 hours; rejected or disputed evidence may be kept for up to 30 days unless you delete it sooner; abandoned or unconfirmed uploads are deleted after 24 hours. Photo location metadata (EXIF/GPS) is stripped and the image is sanitized on device before upload. The processed photo is stored privately and accessible only to authorized family members. If AI verification is enabled, OpenAI may process it for the authorized request. OpenAI's separate abuse-monitoring retention is described in the Privacy Policy.
• Auto Mode before and after evidence - Purpose: after the separate 2026-07-30-auto-mode-v1 household manager authorization, propose up to six bounded chores grounded in one sanitized before photo and verify each committed chore against its own sanitized after photo. One before photo may support up to six accepted chores; each requires its own after photo. The original before photo is retained only while the suggestions or related chores need it for verification or household manager review. After that, before and after evidence follow the same 24-hour abandoned, roughly 72-hour approved, and up-to-30-day rejected or disputed limits.
• Household manager room capture - Purpose: create an editable Manual chore draft or propose AI chores from a room or area selected by a household manager through OpenAI, and compare a linked chore's original room state with its completion photo when AI verification is enabled. Photos are processed on your device to remove location metadata and reduce image size before upload. Raw originals are not uploaded. After room-photo notice 2026-08-30-before-after-verification-v3, the processed photo is privately retained and associated to all chores saved from that capture. It is deleted after the final unlink, member or household deletion, or after 24 hours if an upload is never linked. Paid expiry or revocation downgrades the household to Free and does not delete retained room references. Unsaved copies remain temporarily on your device until discard, sign-out, or the household manager workspace closes. Member submissions use separate short-retention evidence even when compared with a linked room reference.
• Account-deletion entitlement continuity - Purpose: allow an adult who permanently deletes Tidiest data without canceling an active Apple subscription to restore compatible paid access to a new empty account. The record contains only protected account and subscription references, prior workspace reference, subscription type, and creation time. It contains no member, chore, Activity, evidence, consent, reward, pairing, usage, or workspace settings and is consumed when the same freshly authenticated Apple identity restores the subscription.
• Points ledger and balance - Purpose: track points earned and redeemed. Contents: identifiers, integers, and integrity-protection information only—no names or photos. Deletion: retained while the household exists; removed when you delete the member or account.
• Chore submissions, limited chore/reward records, and reward redemptions - Purpose: let the app enforce balances and give you household history. Deletion: retained while the household exists; removed when you delete the member or account.
• Household manager-supplied manual reward codes - Purpose: let a household manager attach one single-use code to a reward. Contents: encrypted code, optional PIN or redemption URL/instructions, optional descriptive face value/currency, reservation state, and identifiers. Codes are never written to point ledgers, balances, logs, analytics, or menu/redemption lists. Deletion: archived by the household manager or removed with the member or household.
• Device pairing code and credential - Purpose: let a member's device join the household and remain paired while access is paused. The one-time code becomes unusable after 24 hours. The stable credential remains while the device is paired unless the household manager revokes it or deletes the member or account.
• Parental consent record - Purpose: evidence that verifiable parental consent was obtained. Contents: a version stamp and timestamp—no contact details beyond your own account. Deletion: retained while the household exists and removed with the applicable member or account data.
• Age-verification signal - Purpose: a one-time check that the person setting up the app is an adult. Deletion: never stored - it is reduced to a yes/no result and immediately discarded, and is never reused for the member's age.
• Member nickname, consent record, pairing, and private display symbol - Purpose: operate and label the private household workflow and preserve proof of consent. Deletion: retained while the household exists; deleted when the member, pairing, or account is deleted. The symbol is not sent to public records, AI prompts, photos, point history, balances, analytics, or purchase surfaces.
• Retired household manager transactional-email records - Tidiest sends no new subscription email. Historical sent-notice status, opaque provider identifiers, and timestamps remain with the household record until account deletion; unfinished email notices are canceled, and ephemeral canary records are removed.
How deletion actually happens
Abandoned or unconfirmed uploads are deleted after about 24 hours, approved evidence after about 72 hours, and rejected or disputed evidence within 30 days unless you delete it sooner. Auto before photos are retained only while related suggestions or chores need them for verification or household manager review, then follow the applicable deletion window. Cancelling an Auto chore does not restore its daily allowance. Revoking Auto authorization turns every member's Auto policy off and prevents new Auto processing; existing photos remain only for applicable household manager review or deletion. Paid expiry or revocation downgrades the household to Free and turns Auto policies off; it does not delete retained room photos or household records. Member or account deletion immediately revokes the applicable access and starts permanent deletion without a recovery window. Private-photo cleanup may finish afterward, and failed deletions are retried. Account deletion does not cancel your Apple subscription.
Your rights as a household manager
You can review your member's before and after photos and verification decisions, correct decisions where the app allows it, disable AI verification, revoke Auto Mode authorization, delete a member's information using the in-app controls, request deletion of your entire account through an authenticated deletion request or by contacting us at support@tidiest.app, and revoke member-photo submission consent at any time. Withdrawing consent disables further member photo collection and Auto processing.
Changes & contact
If we materially change what we keep or for how long, we will update this policy and the Privacy Policy and ask you to review the change. Questions: Tidiest LLC, 12851 Tilden Dr., Rancho Cucamonga, CA, United States · +1 (909) 646-2488 · support@tidiest.app.
Updated apps use the same photo-grounded generation and verification stages for Solo Composer and authorized Auto Mode. Each photo may support up to six selected chores. Generation and verification do not request numeric confidence scores; verification checks the visible target and the chore’s required criteria. Older apps and existing three-chore sets keep their original limits. Consent, household manager authorization, access, private evidence, review, deletion, and reward controls continue to apply.