Data retention and deletion policy

Keep only what the family still needs.

This written policy states why each information category exists, how long it is kept, what ends the retention period, and how deletion continues through short-lived backups. It is part of the StarSeeker Privacy Policy.

Effective July 10, 2026

Policy owner and scope

Star Seeker Games, a DBA of Bare Getaways LLC maintains this policy for playstarseeker.com. It covers guardian account information, child-profile and learning information, security records, billing references, support correspondence, and application backups.

StarSeeker does not retain child information indefinitely. A category is kept only while its stated product, security, legal, or guardian-request purpose remains necessary.

Retention schedule

Guardian account and consent records

Purpose and business need: Authenticate the adult, operate the family account, preserve the privacy choices that authorize child-profile use, and provide account support.

Deletion timeframe or trigger: Kept while the family account is active. Active account records are deleted when verified account closure completes, except for the narrow legal, security, and trial-eligibility records described below.

Child profile, placement, progress, and game records

Purpose and business need: Select reading activities, preserve game progress, adapt support, and show the guardian what the child practiced.

Deletion timeframe or trigger: Kept only while the guardian maintains the child profile and family account. Deleted when the guardian deletes the profile or closes the family account. StarSeeker does not keep a separate advertising or analytics copy.

Child voice recordings and optional Tadamo learning copies

Purpose and business need: Produce a kind, immediate pronunciation assessment and, only under a separate Tadamo guardian agreement and four current import/retention choices for the same speaker, build that speaker's private Tadamo speech model.

Deletion timeframe or trigger: StarSeeker's ordinary audio-retention path stays disabled at the database level, and it never stores a transcript. Without the separate Tadamo choices, the recording is discarded after assessment. If a guardian turns on optional Open Radio background listening, each short background clip (up to 10 seconds, captured only while reading text is on screen) follows the same rule: it is discarded after its pronunciation assessment, no recording or transcript is kept, and it is never copied to Tadamo. With all four current same-speaker Tadamo choices, a failed delivery may remain only as an AES-256-GCM encrypted outbound request for no more than 24 hours; no plaintext audio or prompt, transcript, key, or provider response is stored in that queue. StarSeeker purges the ciphertext after delivery, revocation, profile or account deletion, expiry, or any integrity or decryption failure. Tadamo may keep a qualifying imported copy for up to 24 months after guardian review. Revocation or deletion queues the imported audio and private Azure datasets, models, and endpoints for deletion, with 30 days as the outside completion limit.

Non-audio assessment results (from voice coaching or optional Open Radio)

Purpose and business need: Track reading practice and adapt feedback using results such as the feedback band, coverage, and word-level verdicts — including which on-screen words were read confidently in an optional Open Radio background clip — without retaining the recording or transcript.

Deletion timeframe or trigger: Kept only while the guardian maintains the child profile and family account, and only accumulates while voice coaching or optional Open Radio stays on for that child. Deleted when the guardian deletes the profile or closes the family account; turning voice coaching or Open Radio off stops new data from accumulating.

Authentication sessions and reset links

Purpose and business need: Keep the guardian or selected child signed in and support password recovery.

Deletion timeframe or trigger: Sessions end at logout, expiry, password/security revocation, child-session replacement, or account deletion. Supabase controls one-time verification and recovery-link expiry; used or expired links cannot be used as a lasting credential.

Subscription and checkout records

Purpose and business need: Provide the trial, subscription, billing portal, cancellation, receipts, charge support, and payment-fraud protection.

Deletion timeframe or trigger: Active billing references are removed or detached during account deletion. Stripe retains transaction records for its legal and financial obligations. StarSeeker retains only records reasonably required for accounting, disputes, security, and one-trial-per-family enforcement, then deletes or de-identifies them when that need ends.

Support and privacy-request correspondence

Purpose and business need: Resolve the request, document the response, and prevent an unauthorized disclosure or deletion.

Deletion timeframe or trigger: Normally deleted within 24 months after the request is resolved. A message may be kept longer only while a legal obligation, active dispute, fraud investigation, or security incident requires it.

Application backups

Purpose and business need: Recover from a service failure or corrupted database.

Deletion timeframe or trigger: Root-only application backups are automatically aged out so none remains longer than 14 days. Provider infrastructure backups follow the provider cycle and are used only for disaster recovery. Completed deletion requests must be reapplied before a restored service resumes.

How deletion works

  1. The guardian starts deletion from account security and re-enters the current password.
  2. StarSeeker stops managed billing before removing the account so a subscription cannot continue without account access.
  3. Guardian and child sessions are revoked, then active family, consent, profile, progress, and game records are removed from Supabase and the application database.
  4. Deletion tombstones prevent a restored or delayed application record from silently recreating access.
  5. Short-lived application backups age out within the published 14-day maximum. Any disaster restore must reapply completed deletion requests before service resumes.

Guardian review, correction, export, and deletion

A verified guardian may review or correct the child profile and family settings, request an export, delete a child profile, refuse further collection, or close the family account. Use the in-account controls or email support@playstarseeker.com from the guardian account address. StarSeeker verifies the requester before disclosing or deleting child information.

Related notices

Read the Privacy Policy for collection and provider details and the Children's Privacy Notice for the direct guardian-facing summary.