This policy explains how long Rise Ohana keeps your family’s data, and what happens when it’s time to delete it.
This page has two parts. Part 1 is a plain-English summary. Part 2 is the full policy with every detail. Both parts say the same things — Part 1 just says them faster.
Our guiding principles: We keep data only as long as we need it. We tell you exactly how long that is. You can request deletion at any time.
| Data | How Long | Then What |
|---|---|---|
| Your child’s photos | 30 days | Auto-deleted from our servers |
| Photo metadata (AI scores, your review decisions) | 1 year | Auto-deleted |
| Quest activity (assignments, completions) | 1 year | Auto-deleted |
| Device session logs | 90 days | Auto-deleted |
| Push notification tokens | Until logout or account deletion | Deregistered from Firebase |
| Wallet and transaction history | 3 years | Deleted (financial audit requirement) |
| Parental consent records | 3 years | Deleted (COPPA compliance) |
| Audit logs | 1 year | Auto-deleted |
| Child profile (name, birth month/year, avatar) | Lifetime of account | Deleted when account is closed |
| Parent account data | Lifetime of account | Deleted when account is closed |
How: Use the Parental Dashboard in the app, email privacy@riseohana.com.
We use cloud-hosted databases with automated backups for disaster recovery. When we delete data from our primary systems, it may persist in backups for up to 90 days. We cannot delete individual records from backups on demand — this is a technical limitation of how database backups work. After 90 days, the data is permanently purged from all systems, including backups.
| Provider | What They Handle | Their Retention |
|---|---|---|
| OpenAI | Quest photo analysis | No longer than 30 days (per our DPA) |
| Firebase Cloud Messaging | Push notification delivery | Token deregistered on logout/deletion |
| Stripe | Parent subscription billing | Per Stripe’s terms (typically 3–5 years) |
| OAuth (Google/Apple/Microsoft) | Parent sign-in | Per their privacy policies |
We require Data Processing Agreements with all providers who handle child data. No child data is sold, rented, or shared for advertising.
Email privacy@riseohana.com. We respond within 7 business days.
See also: Privacy Policy • Terms of Service
Effective Date: March 2026 • Rise Ohana, Inc., a Delaware C-Corporation
Rise Ohana (“RO” or “Company”) is committed to protecting the privacy of all users, particularly children under 13, in compliance with the Children’s Online Privacy Protection Act (COPPA) and applicable privacy laws. This Data Retention Policy describes how Rise Ohana collects, retains, and deletes personal information.
Key Principles: Minimization (retain only what’s needed), Transparency (parents know what, why, and how long), Control (parents can request deletion at any time), Security (reasonable measures to protect data), Honesty (we disclose technical limitations).
Photos, images, or video submitted by a child as evidence of quest completion, plus any derivative analysis, metadata, or descriptions generated from the image. Photos are classified as personal information under COPPA.
Quest verification (AI-powered and parental review), parental review and override, and system improvement (anonymized data only).
| Status | Retention | Trigger |
|---|---|---|
| Active submission | 7 days | Photo submitted |
| Under review | 30 days total | Photo submitted |
| Approved & archived | 30 days from submission | Photo submitted |
| Rejected | 1–7 days | Photo submitted |
| Deleted by parent | Immediate | Parent request |
| Child account deleted | Purged at hard-delete | 30 days after soft-delete |
Summary: Photos are deleted from primary storage no later than 30 days after submission. Photos may persist in automated backups for up to 90 days after deletion from primary storage, after which they are permanently purged from all systems.
Primary database: Permanent deletion via database DELETE operation. Automated daily at 2:00 AM UTC. Backups: Purged per provider schedule, no later than 90 days after deletion from primary storage.
Parents can request deletion via the Parental Dashboard or email (privacy@riseohana.com). Upon request: flagged immediately, physically deleted within 24 hours, confirmation within 7 days.
| Data | Retained After Photo Deletion | Rationale |
|---|---|---|
| Quest completion record | 1 year | Parent historical reference |
| AI confidence score | 1 year | System improvement and analytics |
| Parent override decision | 1 year | Parental decision history |
| Submission timestamp | 1 year | Activity history |
Anonymized, de-identified data derived from photos (aggregate completion rates, AI accuracy metrics) is not subject to COPPA’s retention requirements and may be retained indefinitely. Anonymized data is used only for system improvement, not for marketing or behavioral targeting.
| Data Type | Retention | Purpose |
|---|---|---|
| Quest assignments & completions | 1 year from completion | Parent dashboard history |
| Evidence submission history | 1 year from submission | Parent reference, dispute resolution |
| Parental override decisions | 1 year from decision | Account management |
| Child device session logs | 90 days | Security, fraud detection |
| Login history | 90 days | Account security |
| Failed auth attempts | 30 days | Fraud detection |
| AI confidence scores (per child) | 1 year | AI accuracy measurement |
| Aggregate statistics | Indefinite | System health (anonymized) |
| Data Type | Retention | Purpose |
|---|---|---|
| Email address, name | Account lifetime | Account identification, notifications |
| OAuth tokens | Account lifetime | Authentication |
| Billing information | Per Stripe terms (typically 3 years) | Subscription management |
| Family relationships | Account lifetime | Account structure |
| Parental consent records | 3 years or account lifetime | COPPA compliance |
Upon account deletion: soft delete (immediate), 30-day grace period, then hard delete of all data except consent records (3 years), financial records (3 years), and audit logs (1 year).
| Data Type | Retention | Purpose |
|---|---|---|
| First name or nickname | Account lifetime | Account identification |
| Birth month and year | Account lifetime | Age eligibility, COPPA, AI personalization |
| Avatar customization | Account lifetime | Personalization |
| Device provisioning data | Duration of session | Child device authentication |
| Push notification token | Until logout or account deletion | Quest reminders, activity alerts |
Upon child account deletion: soft delete (immediate access block), 30-day grace period, then hard delete of all profile data, photos, quest activity, wallet history, session data, and push notification tokens (deregistered from Firebase Cloud Messaging). Exceptions: financial records (3 years), consent records (3 years), audit logs (1 year).
Photos are transmitted to OpenAI’s Vision API for quest verification. OpenAI does not retain photos submitted via API calls. Rise Ohana maintains a Data Processing Agreement (DPA) prohibiting retention and secondary use of child photos. Photos are not used to train AI models.
Parent subscription billing only. No child data is shared with Stripe. Stripe retains billing information per its standard practices (typically 3–5 years).
Parent authentication only (Google, Apple, Microsoft). No child data is shared. Retention governed by each provider’s privacy policy.
Push notification delivery to parent and child devices. Only an app-specific push token is shared — no child names, photos, or quest data. Rise Ohana does not use Firebase Analytics, Crashlytics, or any other Firebase service. Tokens are deregistered on logout or account deletion.
Rise Ohana only shares child personal information with third parties when necessary to provide the service. All third parties processing child data are bound by Data Processing Agreements. No child data is sold or shared for advertising or behavioral targeting.
| Log Type | Retention | Purpose |
|---|---|---|
| Photo submission/deletion events | 1 year | Compliance audit |
| Parental consent records | 3 years or account lifetime | COPPA legal compliance |
| Parent dashboard access logs | 90 days | Security, fraud detection |
| Account modification logs | 1 year | User support, dispute resolution |
| Administrative access logs | 1 year | Security, access control |
If Rise Ohana becomes aware of pending litigation, government investigation, or legal process, a litigation hold may be placed on affected data. Data under litigation hold is preserved until the legal matter concludes. Parents will be notified in writing unless prohibited by law.
Rise Ohana complies with government subpoenas, court orders, and regulatory requests. Retention periods in this policy do not apply when overridden by valid legal process.
Rise Ohana uses cloud-hosted databases with automated backups (daily and weekly, retained 30–90 days). Individual records cannot be deleted from backups on demand. All data is permanently purged from backups no later than 90 days after deletion from the primary database.
Contact: privacy@riseohana.com
Backups: Rise Ohana uses cloud-hosted databases with automated backups. Individual records cannot be deleted from backups on demand. Backups are purged per the provider’s standard retention schedule (up to 90 days).
Third-party data: Once data is shared with OpenAI or other third parties, Rise Ohana cannot delete it from their systems directly. Deletion is enforced via contractual Data Processing Agreements.
This policy is reviewed at least annually. Material changes (extending retention periods, adding new purposes, reducing parental rights) will be communicated to parents via email before taking effect. Minor clarifications do not require notification.
Last updated: March 2026 (v1.1)
Related documents: Privacy Policy • Terms of Service