Data Retention Policy
This policy explains how long Rise Ohana keeps your family’s data, and what happens when it’s time to delete it.
This page has two parts. Part 1 is a plain-English summary. Part 2 is the full policy with every detail. Both parts say the same things — Part 1 just says them faster.
Our guiding principles: We keep data only as long as we need it. We tell you exactly how long that is. You can request deletion at any time.
How Long We Keep Your Data
| Data | How Long | Then What |
|---|---|---|
| Your child’s photos | 30 days | Auto-deleted from our servers |
| Photo metadata (AI scores, your review decisions) | 1 year | Auto-deleted |
| Quest activity (assignments, completions) | 1 year | Auto-deleted |
| Device session logs | 90 days | Auto-deleted |
| Push notification tokens | Until logout or account deletion | Deregistered from Firebase |
| Wallet and transaction history | 3 years | Deleted (financial audit requirement) |
| Parental consent records | 3 years | Deleted (COPPA compliance) |
| Audit logs | 1 year | Auto-deleted |
| Child profile (name, birth month/year, avatar) | Lifetime of account | Deleted when account is closed |
| Parent account data | Lifetime of account | Deleted when account is closed |
What Happens When You Delete an Account
- Immediate: Access is blocked. No more data is collected.
- 30-day grace period: Your data stays stored but inaccessible. You can change your mind and restore the account during this time.
- After 30 days: All personal information — profile data, photos, quest history, wallet balance, session data, push notification tokens — is permanently deleted.
- Backups: Data may persist in automated backups for up to 90 days after deletion, then it’s permanently purged from all systems.
Your Deletion Rights
- Delete any photo — removed from primary storage within 24 hours
- Delete your child’s entire account — 30-day grace period, then permanent
- Revoke consent — immediately blocks your child’s access and schedules deletion
- Export your child’s data — in CSV or JSON format within 30 days of your request
- No penalties for exercising any of these rights
How: Use the Parental Dashboard in the app, email privacy@riseohana.com.
A Note About Backups
We use cloud-hosted databases with automated backups for disaster recovery. When we delete data from our primary systems, it may persist in backups for up to 90 days. We cannot delete individual records from backups on demand — this is a technical limitation of how database backups work. After 90 days, the data is permanently purged from all systems, including backups.
What About Third Parties?
| Provider | What They Handle | Their Retention |
|---|---|---|
| OpenAI | Quest photo analysis | No longer than 30 days (per our DPA) |
| Firebase Cloud Messaging | Push notification delivery | Token deregistered on logout/deletion |
| Stripe | Parent subscription billing | Per Stripe’s terms (typically 3–5 years) |
| OAuth (Google/Apple/Microsoft) | Parent sign-in | Per their privacy policies |
We require Data Processing Agreements with all providers who handle child data. No child data is sold, rented, or shared for advertising.
Questions?
Email privacy@riseohana.com. We respond within 7 business days.
See also: Privacy Policy • Terms of Service
Read the Full Data Retention Policy
Rise Ohana Data Retention Policy
Effective Date: March 2026 • Rise Ohana, Inc., a Delaware C-Corporation
Executive Summary
Rise Ohana (“RO” or “Company”) is committed to protecting the privacy of all users, particularly children under 13, in compliance with the Children’s Online Privacy Protection Act (COPPA) and applicable privacy laws. This Data Retention Policy describes how Rise Ohana collects, retains, and deletes personal information.
Key Principles: Minimization (retain only what’s needed), Transparency (parents know what, why, and how long), Control (parents can request deletion at any time), Security (reasonable measures to protect data), Honesty (we disclose technical limitations).
1. Photo Data Retention and Deletion
1.1 What Is Photo Data?
Photos, images, or video submitted by a child as evidence of quest completion, plus any derivative analysis, metadata, or descriptions generated from the image. Photos are classified as personal information under COPPA.
1.2 Why We Collect Photos
Quest verification (AI-powered and parental review), parental review and override, and system improvement (anonymized data only).
1.3 Photo Retention Periods
Primary Storage
| Status | Retention | Trigger |
|---|---|---|
| Active submission | 7 days | Photo submitted |
| Under review | 30 days total | Photo submitted |
| Approved & archived | 30 days from submission | Photo submitted |
| Rejected | 1–7 days | Photo submitted |
| Deleted by parent | Immediate | Parent request |
| Child account deleted | Purged at hard-delete | 30 days after soft-delete |
Summary: Photos are deleted from primary storage no later than 30 days after submission. Photos may persist in automated backups for up to 90 days after deletion from primary storage, after which they are permanently purged from all systems.
1.4 Photo Deletion Methods
Primary database: Permanent deletion via database DELETE operation. Automated daily at 2:00 AM UTC. Backups: Purged per provider schedule, no later than 90 days after deletion from primary storage.
1.5 Parental Rights: Photo Deletion
Parents can request deletion via the Parental Dashboard or email (privacy@riseohana.com). Upon request: flagged immediately, physically deleted within 24 hours, confirmation within 7 days.
1.6 Metadata Linked to Photos
| Data | Retained After Photo Deletion | Rationale |
|---|---|---|
| Quest completion record | 1 year | Parent historical reference |
| AI confidence score | 1 year | System improvement and analytics |
| Parent override decision | 1 year | Parental decision history |
| Submission timestamp | 1 year | Activity history |
1.7 Anonymized Analytics
Anonymized, de-identified data derived from photos (aggregate completion rates, AI accuracy metrics) is not subject to COPPA’s retention requirements and may be retained indefinitely. Anonymized data is used only for system improvement, not for marketing or behavioral targeting.
2. Behavioral and Activity Data
| Data Type | Retention | Purpose |
|---|---|---|
| Quest assignments & completions | 1 year from completion | Parent dashboard history |
| Evidence submission history | 1 year from submission | Parent reference, dispute resolution |
| Parental override decisions | 1 year from decision | Account management |
| Child device session logs | 90 days | Security, fraud detection |
| Login history | 90 days | Account security |
| Failed auth attempts | 30 days | Fraud detection |
| AI confidence scores (per child) | 1 year | AI accuracy measurement |
| Aggregate statistics | Indefinite | System health (anonymized) |
3. Parental Information
| Data Type | Retention | Purpose |
|---|---|---|
| Email address, name | Account lifetime | Account identification, notifications |
| OAuth tokens | Account lifetime | Authentication |
| Billing information | Per Stripe terms (typically 3 years) | Subscription management |
| Family relationships | Account lifetime | Account structure |
| Parental consent records | 3 years or account lifetime | COPPA compliance |
Upon account deletion: soft delete (immediate), 30-day grace period, then hard delete of all data except consent records (3 years), financial records (3 years), and audit logs (1 year).
4. Child Profile Information
| Data Type | Retention | Purpose |
|---|---|---|
| First name or nickname | Account lifetime | Account identification |
| Birth month and year | Account lifetime | Age eligibility, COPPA, AI personalization |
| Avatar customization | Account lifetime | Personalization |
| Device provisioning data | Duration of session | Child device authentication |
| Push notification token | Until logout or account deletion | Quest reminders, activity alerts |
Upon child account deletion: soft delete (immediate access block), 30-day grace period, then hard delete of all profile data, photos, quest activity, wallet history, session data, and push notification tokens (deregistered from Firebase Cloud Messaging). Exceptions: financial records (3 years), consent records (3 years), audit logs (1 year).
5. Third-Party Data Retention
5.1 OpenAI
Photos are transmitted to OpenAI’s Vision API for quest verification. OpenAI does not retain photos submitted via API calls. Rise Ohana maintains a Data Processing Agreement (DPA) prohibiting retention and secondary use of child photos. Photos are not used to train AI models.
5.2 Stripe
Parent subscription billing only. No child data is shared with Stripe. Stripe retains billing information per its standard practices (typically 3–5 years).
5.3 OAuth Providers
Parent authentication only (Google, Apple, Microsoft). No child data is shared. Retention governed by each provider’s privacy policy.
5.4 Firebase Cloud Messaging
Push notification delivery to parent and child devices. Only an app-specific push token is shared — no child names, photos, or quest data. Rise Ohana does not use Firebase Analytics, Crashlytics, or any other Firebase service. Tokens are deregistered on logout or account deletion.
5.5 General Principle
Rise Ohana only shares child personal information with third parties when necessary to provide the service. All third parties processing child data are bound by Data Processing Agreements. No child data is sold or shared for advertising or behavioral targeting.
6. Audit Logs and Compliance Records
| Log Type | Retention | Purpose |
|---|---|---|
| Photo submission/deletion events | 1 year | Compliance audit |
| Parental consent records | 3 years or account lifetime | COPPA legal compliance |
| Parent dashboard access logs | 90 days | Security, fraud detection |
| Account modification logs | 1 year | User support, dispute resolution |
| Administrative access logs | 1 year | Security, access control |
7. Legal Holds and Compliance Exceptions
If Rise Ohana becomes aware of pending litigation, government investigation, or legal process, a litigation hold may be placed on affected data. Data under litigation hold is preserved until the legal matter concludes. Parents will be notified in writing unless prohibited by law.
Rise Ohana complies with government subpoenas, court orders, and regulatory requests. Retention periods in this policy do not apply when overridden by valid legal process.
8. Backups and Disaster Recovery
Rise Ohana uses cloud-hosted databases with automated backups (daily and weekly, retained 30–90 days). Individual records cannot be deleted from backups on demand. All data is permanently purged from backups no later than 90 days after deletion from the primary database.
9. Parent Rights and Data Access
- Right to Access: Request a copy of all data collected from your child (CSV or JSON, within 30 days).
- Right to Deletion: Request deletion of specific photos (within 24 hours) or the entire child account (30-day grace period, then permanent).
- Right to Withdraw Consent: Revoke consent at any time — immediately blocks child access, schedules data deletion after 30-day grace period. Push notification tokens are deregistered from Firebase Cloud Messaging.
- Right to Correct: Request correction of inaccurate information (within 7 business days).
- No Discrimination: Rise Ohana does not deny service or charge different fees for exercising these rights.
Contact: privacy@riseohana.com
10. Technical Limitations
Backups: Rise Ohana uses cloud-hosted databases with automated backups. Individual records cannot be deleted from backups on demand. Backups are purged per the provider’s standard retention schedule (up to 90 days).
Third-party data: Once data is shared with OpenAI or other third parties, Rise Ohana cannot delete it from their systems directly. Deletion is enforced via contractual Data Processing Agreements.
11. Policy Updates
This policy is reviewed at least annually. Material changes (extending retention periods, adding new purposes, reducing parental rights) will be communicated to parents via email before taking effect. Minor clarifications do not require notification.
Last updated: March 2026 (v1.1)
Related documents: Privacy Policy • Terms of Service