Data Retention Policy

Why this policy exists

The U.S. Children's Online Privacy Protection Act (COPPA) requires us to keep a child's personal information only for as long as is reasonably necessary for the purpose we collected it, and to write down - for each kind of information - why we collect it, why we need to keep it, and when we delete it. This policy is that written record. It is also reproduced inside our Privacy Policy, which is the notice we present to you.

Our retention principle

We collect the minimum needed to run parent-managed chores, separately authorized bounded Auto suggestions, AI-assisted chore verification, parent review, and rewards, keep each item only while it serves that purpose, and then delete it. We do not retain children's information indefinitely, build public profiles, train models, run unrelated AI, track children, or advertise to them. When information is no longer reasonably necessary, we delete it and take reasonable measures to protect it during deletion.

What we keep, why, and for how long

• Child chore photo (review copy) - Purpose: verify a submitted chore and let you review or correct the decision after you have consented, created the child profile, and paired the child device. Why we keep it briefly: you need to see the work if verification is ambiguous or you want to review history. Deletion: approved evidence is deleted after roughly 72 hours; rejected or disputed evidence may be kept for up to 30 days unless you delete it sooner; abandoned or unconfirmed uploads are deleted after 24 hours. Photo location metadata (EXIF/GPS) is stripped and visible faces are rejected on the device before upload. The photo is uploaded as a private R2-compatible evidence object and parent review uses short-lived authorized download URLs, not public image URLs. If AI verification is enabled, the Worker sends the verification image to Bedrock only transiently for the authorized request. • Auto Mode before and after evidence - Purpose: after the separate 2026-07-30-auto-mode-v1 parent authorization, propose up to three bounded chores grounded in one sanitized before photo and verify each committed chore against its own sanitized after photo. One physical before object may support up to three committed chores without duplicating bytes; each after object belongs to exactly one chore and submission. The before object is locked against child replacement and retained only while an issued set or linked chore needs it for verification or parent review. After that, before and after evidence follow the same 24-hour abandoned, roughly 72-hour approved, and up-to-30-day rejected or disputed limits. • Parent room-planning image - Purpose: propose editable chores from a room or area selected by a parent through Amazon Nova Pro on Amazon Bedrock. Deletion: discarded when suggestions return by default. After the separate quest-reference notice, the complete sanitized single-photo derivative may be stored in a dedicated private bucket and linked to saved chores. It is queued for deletion when Family access expires or is revoked and is never restored. It is also deleted after the final unlink, child or household deletion, or after 24 hours if an upload is never linked. Child submissions use the separate consent-gated /verify-chore path, not room planning. • Points ledger and balance - Purpose: track points earned and redeemed. Contents: identifiers, integers, and cryptographic signatures only—no names or photos. Deletion: retained during active access and the 12-calendar-month recovery window; removed at final deletion or sooner when you delete the child or account. • Chore submissions, limited chore/reward records, and reward redemptions - Purpose: let the app enforce balances and give you household history. Deletion: retained during active access and the 12-calendar-month recovery window; removed at final deletion or sooner when you delete the child or account. • Parent-supplied manual reward codes - Purpose: let a parent attach one single-use code to a reward. Contents: encrypted code, optional PIN or redemption URL/instructions, optional descriptive face value/currency, reservation state, and identifiers. Codes are never written to point ledgers, balances, logs, analytics, or menu/redemption lists. Deletion: archived by the parent or removed with the child or household. • Device pairing code and credential - Purpose: let a child's device join the household and remain paired while access is paused. The one-time code becomes unusable after 24 hours. The stable credential follows the structured-data recovery window unless the parent revokes it or deletes the child or account sooner. • Parental consent record - Purpose: evidence that verifiable parental consent was obtained. Contents: a version stamp and timestamp—no contact details beyond your own account. Deletion: follows the structured-data recovery window; renewed consent is required before restored child data reopens. • Age-verification signal - Purpose: a one-time check that the person setting up the app is an adult. Deletion: never stored - it is reduced to a yes/no result and immediately discarded, and is never reused for the child's age. • Child nickname, consent record, pairing, and private display symbol - Purpose: operate and label the private household workflow and preserve proof of consent. Deletion: retained during active access and the 12-calendar-month recovery window; deleted at final deletion or sooner when the child, pairing, or account is deleted. Renewed consent is required before restored child data reopens. The symbol is not sent to public mirrors, Bedrock prompts, photos, signed point ledgers, balances, analytics, or purchase surfaces.

• Parent transactional-email delivery - Purpose: send the promised two-day annual-trial reminder and the 30-day and 7-day recovery warnings. Tidiest stores only operational delivery state, opaque provider message identifiers, and timestamps with the applicable trial or household lifecycle record. Canary records contain labels rather than recipient addresses and are deleted after seven days. Resend processes the verified parent email and exact transactional message for delivery and may retain its delivery record for up to 30 days under the configured provider policy. Open and click tracking are disabled. No child name, chore, balance, photo, or child identifier is sent to Resend.

How deletion actually happens

Your family's household data lives in Cloudflare D1 and household mutations are serialized through Durable Objects. Sanitized child evidence and opted-in room references live in separate private R2-compatible buckets. Review evidence keeps its independent short window: abandoned uploads about 24 hours, approved evidence about 72 hours, and rejected or disputed evidence up to 30 days. Cancellation or expiry of an Auto chore does not restore the household's daily quota; shared before evidence is released only after no linked chore still needs it. Revoking Auto authorization turns every child's Auto policy off and prevents new Auto processing, while existing evidence continues only for deletion or any still-applicable parent review window. When Family access expires or is revoked, room-reference objects and metadata are queued for immediate deletion and are not restored. Structured household, child, chore, ledger, reward, pairing, consent, and Auto authorization-history data remains recoverable for 12 calendar months. We send best-effort parent-only warnings 30 and 7 days before final deletion. Resubscription before deletion starts cancels structured deletion and warnings. Once deletion starts, recovery closes. Immediate account deletion bypasses recovery and queues the same complete purge; it does not cancel the Apple subscription. Retryable failures use the deletion Queue and DLQ.

Your rights as a parent

You can review your child's before and after photos and verification decisions, correct decisions where the app allows it, disable AI verification, revoke Auto Mode authorization, delete a child's information using the in-app controls, request deletion of your entire account through an authenticated deletion request or by contacting us at support@tidiest.app, and revoke child-photo submission consent at any time. Withdrawing consent disables further child photo collection and Auto processing.

Changes & contact

If we materially change what we keep or for how long, we will update this policy and the Privacy Policy and ask you to review the change. Questions: Tidiest LLC, 12851 Tilden Dr., Rancho Cucamonga, CA, United States · +1 (909) 646-2488 · support@tidiest.app.