Guardian account and consent records
Purpose and business need: Authenticate the adult, operate the family account, preserve the privacy choices that authorize child-profile use, and provide account support.
Deletion timeframe or trigger: Kept while the family account is active. Active account records are deleted when verified account closure completes, except for the narrow legal, security, and trial-eligibility records described below.
Child profile, placement, progress, and game records
Purpose and business need: Select reading activities, preserve game progress, adapt support, and show the guardian what the child practiced.
Deletion timeframe or trigger: Kept only while the guardian maintains the child profile and family account. Deleted when the guardian deletes the profile or closes the family account. StarSeeker does not keep a separate advertising or analytics copy.
Child voice recordings and optional Tadamo learning copies
Purpose and business need: Produce a kind, immediate pronunciation assessment and, only under a separate Tadamo guardian agreement and four current import/retention choices for the same speaker, build that speaker's private Tadamo speech model.
Deletion timeframe or trigger: StarSeeker's ordinary audio-retention path stays disabled at the database level, and it never stores a transcript. Without the separate Tadamo choices, the recording is discarded after assessment. If a guardian turns on optional Open Radio background listening, each short background clip (up to 10 seconds, captured only while reading text is on screen) follows the same rule: it is discarded after its pronunciation assessment, no recording or transcript is kept, and it is never copied to Tadamo. With all four current same-speaker Tadamo choices, a failed delivery may remain only as an AES-256-GCM encrypted outbound request for no more than 24 hours; no plaintext audio or prompt, transcript, key, or provider response is stored in that queue. StarSeeker purges the ciphertext after delivery, revocation, profile or account deletion, expiry, or any integrity or decryption failure. Tadamo may keep a qualifying imported copy for up to 24 months after guardian review. Revocation or deletion queues the imported audio and private Azure datasets, models, and endpoints for deletion, with 30 days as the outside completion limit.
Non-audio assessment results (from voice coaching or optional Open Radio)
Purpose and business need: Track reading practice and adapt feedback using results such as the feedback band, coverage, and word-level verdicts — including which on-screen words were read confidently in an optional Open Radio background clip — without retaining the recording or transcript.
Deletion timeframe or trigger: Kept only while the guardian maintains the child profile and family account, and only accumulates while voice coaching or optional Open Radio stays on for that child. Deleted when the guardian deletes the profile or closes the family account; turning voice coaching or Open Radio off stops new data from accumulating.
Authentication sessions and reset links
Purpose and business need: Keep the guardian or selected child signed in and support password recovery.
Deletion timeframe or trigger: Sessions end at logout, expiry, password/security revocation, child-session replacement, or account deletion. Supabase controls one-time verification and recovery-link expiry; used or expired links cannot be used as a lasting credential.
Subscription and checkout records
Purpose and business need: Provide the trial, subscription, billing portal, cancellation, receipts, charge support, and payment-fraud protection.
Deletion timeframe or trigger: Active billing references are removed or detached during account deletion. Stripe retains transaction records for its legal and financial obligations. StarSeeker retains only records reasonably required for accounting, disputes, security, and one-trial-per-family enforcement, then deletes or de-identifies them when that need ends.
Support and privacy-request correspondence
Purpose and business need: Resolve the request, document the response, and prevent an unauthorized disclosure or deletion.
Deletion timeframe or trigger: Normally deleted within 24 months after the request is resolved. A message may be kept longer only while a legal obligation, active dispute, fraud investigation, or security incident requires it.
Application backups
Purpose and business need: Recover from a service failure or corrupted database.
Deletion timeframe or trigger: Root-only application backups are automatically aged out so none remains longer than 14 days. Provider infrastructure backups follow the provider cycle and are used only for disaster recovery. Completed deletion requests must be reapplied before a restored service resumes.