Data Retention Policy
Version 1.0.0-draftEffective 16 August 2026Updated 15 August 2026
How long Kibu keeps each kind of information, why we need to keep it that long, and what happens when the time is up. COPPA requires us to publish this, and we treat it as a specification our systems must actually implement — not a statement of intent.
Our principles
- We set a period for every category. Nothing about a child is kept indefinitely.
- Deletion means the record is removed from our database and the file is removed from our storage. It is not a hidden flag.
- You can always delete sooner than the periods below. These are maximums, not commitments to keep things.
- Where we need a record for accounting or legal-defence reasons, we remove everything identifying the child and keep only the figures.
Retention schedule
| Category | What it is | Business need | Retention period | Trigger | On expiry |
|---|---|---|---|---|---|
| Child's source photograph | The photo taken to generate an avatar | Needed only for the moment of generation | Not retained | Deleted as soon as the avatar is generated | Deleted from storage |
| Generated avatar | The cartoon image | It is the child's picture in the app | Life of the child profile | Profile deleted, or a new avatar replaces it | Deleted from storage, including any superseded version |
| Mission proof photographs | Photos a child attaches to a completed mission | So a parent can review and approve, and briefly afterwards so they can look back | 90 days after the mission is approved or rejected | Review completed | Photo deleted from storage; the mission record keeps only that it was completed |
| Post photographs and captions | What a child shares with friends | The social feature | 180 days, or until deleted | Age, parent deletion, child deletion, or social feature turned off | Row and image both deleted |
| Family chat messages | Messages between family members | So a family can see its own conversation | 365 days | Age of the message | Deleted |
| Child profile fields | Name, date of birth, gender, username | To operate the profile | Life of the profile | Profile deleted, or dormant for 24 months | Deleted. We warn you by email before deleting a dormant profile. |
| Mission history, points, badges, streaks | Game progress | To run the game and show progress over time | Life of the profile | Profile deleted | Deleted |
| Daily question answers | Free text a child writes | To run that day's activity | 90 days | Age | Deleted |
| Weekly reports | The parent's summary | So a parent can look back over recent weeks | 52 weeks | Age | Deleted |
| Parent AI chat | Conversations with the parent assistant | So the conversation has continuity | 90 days | Age | Deleted |
| Content reports | A report about a post, and the reviewer's decision | Safety record, repeat-offender detection, and to answer a regulator | 24 months after the report is closed | Closure | Deleted. Reports escalated to an authority follow that authority's requirements instead. |
| Analytics events about a child | Usage events held by our analytics provider | Product improvement | 14 months | Age, or consent withdrawn | Deletion requested from the provider and the confirmation recorded |
| Device notification tokens | The address for push notifications | To deliver notifications | Until the device unregisters or the profile is deleted | Sign-out, uninstall, or deletion | Deleted |
| Parent account | Name, email, phone, password hash | To operate the account | Life of the account, then 30 days | Deletion request | Deleted after the grace period, which exists so an accidental deletion can be undone |
| Billing and transaction records | Subscription and payment records | Tax, accounting and audit obligations | 10 years | End of the financial year | Deleted. On account deletion, all links to a child are removed immediately and only the figures remain. |
| Consent records | What you consented to, when, which notice version, and the verification reference | This is our evidence that we collected your child's data lawfully. Deleting it would destroy the proof that we complied. | 7 years after the account closes | Account closure | Deleted. These records hold no content about your child. |
| Security and access logs | Sign-in attempts, administrative access | Detecting and investigating misuse | 365 days | Age | Deleted |
| Application logs | Diagnostic logs | Fixing faults | 30 days | Age | Deleted. Logs are configured not to record children's content or location. |
When you ask us to delete sooner
When you delete a child's profile or your family account, we do not wait for the periods above. Everything about that child is deleted within 30 days, from both our database and our file storage.
The only exceptions are the consent records and the anonymised billing figures described above, neither of which identifies your child.
Backups are overwritten on a 35-day cycle. A deleted record can persist in a backup until that cycle completes, and is never restored to live systems.
Governance
A scheduled job runs daily and applies every period above. Its results are monitored, and a failure is treated as an incident.
Reviewed annually, and on any change to what we collect.
Owned by our Privacy Owner.
The full policy set
This policy is one of 13. The rest cover children’s privacy, consent, retention, security, AI and the terms you agree to.
For parents
Privacy Policy
Kibu is a family app used by parents and by children. This policy explains what we collect, why, who we share it with, how long we keep it, and how you control it. Because most of our users are children, we hold ourselves to children's privacy rules everywhere we operate — not only where the law compels it.
/privacy-policy
For parents
Children's Privacy Policy
This is the notice required by the United States Children's Online Privacy Protection Act (COPPA), and it also serves as our children's privacy statement for the United Kingdom, the European Union, Saudi Arabia and the US states with children's design codes. It sits alongside our main Privacy Policy and, where the two differ, this one governs anything to do with a child.
/childrens-privacy
For parents
Parental Consent Notices
Kibu asks for your consent separately for each thing we want to do with your child's information, so that agreeing to one never silently agrees to another. This page holds the full text of every consent we ask for. Each is the notice referenced by the corresponding checkbox in the app.
/parental-consent
For parents
Terms of Service
The agreement between you and Kibu. It covers who may hold an account, what you are responsible for, subscriptions and refunds, and how either of us can end the agreement.
/terms
For parents
Cookies and Tracking
What the Kibu website stores on your device, and what the Kibu app stores on your phone. There is no advertising tracking anywhere in Kibu, and nothing at all is tracked on a child's device without a parent's verified consent.
/cookies
Parents and kids
Community Guidelines and Content Moderation Policy
What is allowed on Kibu, how we check, what happens when something breaks the rules, and how to report it. This is a safety document as much as a legal one — it exists because children can see what other children post.
/community-guidelines
For parents
Your Rights and How to Use Them
What you can ask us to do with your family's data, how to ask, what we need from you, and how long we take. Everything here is free, and most of it you can do yourself in the app without contacting us at all.
/your-rights
For parents
Service Providers and Sub-processors
Every company that handles your family's data on our behalf, what each one receives, where it is processed, and what we require of them in writing. We publish this because you cannot judge whether your child's data is safe without knowing who holds it.
/subprocessors
For parents
How Kibu Uses AI
Kibu uses AI in four places. This page says exactly where, what is sent, who receives it, what we forbid them to do with it, and what your child can and cannot do with AI. Children never talk to an AI in Kibu.
/ai
For schools
Kibu and Schools — FERPA and Student Privacy
Kibu is a consumer family product. We contract with parents, not with schools, and we hold no education records. This page explains our position on FERPA and US state student-privacy laws, and states plainly what we will not do.
/schools
For parents
Security at Kibu
A public summary of how we protect your family's data. The full written programme is an internal document; this page tells you what it covers and how to reach us if you find a problem.
/security
Written for kids
Your Privacy, Explained
A version of our privacy policy written for the children who use Kibu. Required by the ICO Children's Code, which says information must be presented in a way children can actually understand — and by the EU's rules on protecting minors online.
/privacy-for-kids