WordHit Kids
Data Retention Policy
Version 1.0.0-draft · Effective date [not yet configured — operator confirmation required]
Every period below is a draft. Automatic deletion stays switched off until the operator and counsel approve the schedule (no approval is configured yet).
The schedule
| Category | What it contains | Draft period | Then |
|---|---|---|---|
| Unverified sign-up address | A grown-up email address that never completed confirmation. | 30 days after sign-up | Deleted |
| Grown-up account & profile | Account email, display name, optional grown-up name, avatar, goal. | While the account exists, then removed on account deletion | Deleted |
| Child profile | Child nickname, avatar, age band, world, learning targets. | While the profile exists, then removed on deletion | Deleted |
| Inactive child profile | A child profile with no learning activity for a long period. | 24 months of inactivity (draft) | Deleted, or irreversibly anonymised where records must stay consistent |
| Learning & progress data | Attempts, mastery scores, review schedule, placement results, rewards. | While the child profile exists (draft) | Deleted, or irreversibly anonymised where records must stay consistent |
| Product analytics events | Coarse counters with a rotating per-day device code. No names, no ids. | 180 days (already enforced by the existing purge routine) | Deleted |
| Parental consent records | Consent status, method, policy versions accepted, timestamps. | While the profile is active, plus 24 months after withdrawal (draft) | Deleted |
| Privacy audit history | Event type, actor, versions, correlation id. No content, no raw IP. | 36 months (draft) | Deleted |
| Support & safety requests | Grown-up name, email, topic, message, status. | 24 months after the request is closed (draft) | Deleted |
| Authentication & security records | Sign-in and webhook processing records held by the platform. | Platform-managed; app-side webhook history 180–400 days | Deleted |
| Data export packageExport tooling is not built yet in this delivery. | A generated copy of a grown-up's own data, awaiting download. | 7 days, then the download link expires (draft) | Deleted |
| Deletion receiptsDeletion tooling is not built yet in this delivery. | Correlation id, category list and timestamps. No child details. | 36 months (draft) | Deleted |
| Billing & tax recordsPayments are disabled, so no billing data is processed. | Nothing — payments are not enabled in this build. | Not applicable until payments are enabled | Deleted |
Data that only lives on the device
Guest progress, accessibility preferences and offline lesson copies are stored in the browser, not on our servers. No retention period applies to them because we never receive them; they disappear when the browser’s storage for this app is cleared.
Deletion requests come first
A deletion request from a grown-up is honoured regardless of the periods above. Where a record must be kept for a legitimate reason — for example a payment record required by law — we keep only the minimum and say so in the response.
Who is responsible
- Operator
- [not yet configured — operator confirmation required]
- Address
- [not yet configured — operator confirmation required]
- Governing law
- [not yet configured — operator confirmation required]
- Privacy contact
- privacy@wordhitgh.com
- Support contact
- support@wordhitgh.com
- Data-protection registration
- Not stated. We make no registration claim.
Some operator details are not configured yet (4 fields). This page shows placeholders rather than invented details.