Last updated: 2026-08-29
This policy sets out how long 11+ Help keeps each kind of data and how deletion works. It supports the rights described in the Privacy Policy.
| Action | Where | Effect |
|---|---|---|
| Export everything | Account → "Download my data (JSON)" | Immediate download of the full family record (parent, each child, learning data, tickets, subscription status). Backed by public.export_my_data(). |
| Delete account | Account → "Delete my account" (type DELETE) | Calls public.request_account_deletion(): the account and all child profiles are soft-deleted immediately (no longer visible or usable) and a row is written to deletion_requests. |
| Data | Retention | Basis |
|---|---|---|
| Parent account (email, name, preferences) | Life of the account | Contract |
| Child profile + learning data (answers, scores, mistake book, XP) | Life of the account; hard-erased 30 days after deletion | Contract / data minimisation |
| Ask the Tutor conversations | Life of the account; erased with the child profile | Contract |
| Support tickets / feedback | 24 months after resolution, then anonymised | Legitimate interests (service quality, audit trail) |
| Payment & invoice records (processor IDs, plan, amounts) | 7 years | Legal obligation (UK tax law) |
| Server / security logs (IP, request metadata) | 30 days | Legitimate interests (security) |
| Backups containing the above | Rolling: daily ×7, weekly ×5, monthly ×12 | Legitimate interests (disaster recovery) — deleted data ages out of backups within the monthly window |
| Marketing opt-in list | Until you unsubscribe | Consent |
Between soft-delete and hard-erase you can undo a deletion by emailing [contact email — to be added] from the account address. After 30 days a scheduled job permanently removes the child profiles and learning data; the deletion_requests row is retained (without personal content) as proof the request was honoured.
Backups are encrypted and stored in a separate account/region. We do not restore individual records from backup on request; deleted data is not reintroduced and simply expires from the backup rotation within ~12 months at the latest, sooner for the daily/weekly tiers.
Rectification, restriction, objection, and any deletion that can't go through the in-app flow: email [contact email — to be added]. We respond within one calendar month and will tell you if we need to extend for complexity.
Version dated 2026-08-29. First drafts for beta — under professional review before public launch.