Skip to content

Data Retention Policy

Version 1.0.0-draftEffective 16 August 2026Updated 15 August 2026

How long Kibu keeps each kind of information, why we need to keep it that long, and what happens when the time is up. COPPA requires us to publish this, and we treat it as a specification our systems must actually implement — not a statement of intent.

Our principles

  • We set a period for every category. Nothing about a child is kept indefinitely.
  • Deletion means the record is removed from our database and the file is removed from our storage. It is not a hidden flag.
  • You can always delete sooner than the periods below. These are maximums, not commitments to keep things.
  • Where we need a record for accounting or legal-defence reasons, we remove everything identifying the child and keep only the figures.

Retention schedule

CategoryWhat it isBusiness needRetention periodTriggerOn expiry
Child's source photographThe photo taken to generate an avatarNeeded only for the moment of generationNot retainedDeleted as soon as the avatar is generatedDeleted from storage
Generated avatarThe cartoon imageIt is the child's picture in the appLife of the child profileProfile deleted, or a new avatar replaces itDeleted from storage, including any superseded version
Mission proof photographsPhotos a child attaches to a completed missionSo a parent can review and approve, and briefly afterwards so they can look back90 days after the mission is approved or rejectedReview completedPhoto deleted from storage; the mission record keeps only that it was completed
Post photographs and captionsWhat a child shares with friendsThe social feature180 days, or until deletedAge, parent deletion, child deletion, or social feature turned offRow and image both deleted
Family chat messagesMessages between family membersSo a family can see its own conversation365 daysAge of the messageDeleted
Child profile fieldsName, date of birth, gender, usernameTo operate the profileLife of the profileProfile deleted, or dormant for 24 monthsDeleted. We warn you by email before deleting a dormant profile.
Mission history, points, badges, streaksGame progressTo run the game and show progress over timeLife of the profileProfile deletedDeleted
Daily question answersFree text a child writesTo run that day's activity90 daysAgeDeleted
Weekly reportsThe parent's summarySo a parent can look back over recent weeks52 weeksAgeDeleted
Parent AI chatConversations with the parent assistantSo the conversation has continuity90 daysAgeDeleted
Content reportsA report about a post, and the reviewer's decisionSafety record, repeat-offender detection, and to answer a regulator24 months after the report is closedClosureDeleted. Reports escalated to an authority follow that authority's requirements instead.
Analytics events about a childUsage events held by our analytics providerProduct improvement14 monthsAge, or consent withdrawnDeletion requested from the provider and the confirmation recorded
Device notification tokensThe address for push notificationsTo deliver notificationsUntil the device unregisters or the profile is deletedSign-out, uninstall, or deletionDeleted
Parent accountName, email, phone, password hashTo operate the accountLife of the account, then 30 daysDeletion requestDeleted after the grace period, which exists so an accidental deletion can be undone
Billing and transaction recordsSubscription and payment recordsTax, accounting and audit obligations10 yearsEnd of the financial yearDeleted. On account deletion, all links to a child are removed immediately and only the figures remain.
Consent recordsWhat you consented to, when, which notice version, and the verification referenceThis is our evidence that we collected your child's data lawfully. Deleting it would destroy the proof that we complied.7 years after the account closesAccount closureDeleted. These records hold no content about your child.
Security and access logsSign-in attempts, administrative accessDetecting and investigating misuse365 daysAgeDeleted
Application logsDiagnostic logsFixing faults30 daysAgeDeleted. Logs are configured not to record children's content or location.

When you ask us to delete sooner

When you delete a child's profile or your family account, we do not wait for the periods above. Everything about that child is deleted within 30 days, from both our database and our file storage.

The only exceptions are the consent records and the anonymised billing figures described above, neither of which identifies your child.

Backups are overwritten on a 35-day cycle. A deleted record can persist in a backup until that cycle completes, and is never restored to live systems.

Governance

A scheduled job runs daily and applies every period above. Its results are monitored, and a failure is treated as an incident.

Reviewed annually, and on any change to what we collect.

Owned by our Privacy Owner.

The full policy set

This policy is one of 13. The rest cover children’s privacy, consent, retention, security, AI and the terms you agree to.