Legal
Child Data Retention Policy
Last updated: July 26, 2026
COPPA requires us to publish why we collect children’s personal information, why we need to keep it, and when it is deleted. This is that policy. We do not keep children’s personal information indefinitely.
Our Rules
- Collect only what a parent-selected learning feature actually needs.
- Create nothing about a child until an adult has been verified and has given affirmative consent.
- Never store raw microphone audio or full conversation transcripts.
- Delete information when its stated purpose ends, even though storage is cheap.
- Never sell children’s data, use it for targeted advertising, or allow child-facing third-party product analytics.
The Schedule
| What | Why we need it | How long we keep it | How it goes away |
|---|---|---|---|
| Live microphone audio and speech text | Produce the current spoken reply | Not stored by Rusty at all | Nothing is written; see Section 3 for our AI provider |
| Child profile: name, age, grade, avatar, goals, interests, preferences | Run the profile you set up | While the profile is active and your consent is valid | Deleted when you delete the child or the account |
| Learning sessions, activity events, evidence, skill states, plans, summaries | Show progress and let the next session build on the last | 12 months | Automatic daily deletion job, plus child/account deletion |
| Safety event category and short non-verbatim note | Alert you to a possible serious concern | 30 days | Automatic daily deletion job |
| Voice session security records | Rate limiting and abuse investigation | 30 days | Automatic daily deletion job |
| Pending, failed, or expired adult-verification metadata | Finish or debug a verification that did not complete | 30 days | Automatic daily deletion job |
| Successful adult-verification result and consent history | Show what you authorized and when | While the family account is active | Deleted with the account |
| Parent account and family membership | Sign you in and run parent controls | While the account is active | In-app account deletion |
| Subscription and entitlement records | Provide and reconcile purchases; tax and legal duties | As long as required for those duties | Apple and RevenueCat processes, plus account deletion |
| Parent data export you request | Give you a copy of your child’s information | Not stored on our servers | Generated on demand; the app removes its temporary copy |
Our AI Provider's Retention
Rusty stores no audio or transcripts. Our AI provider, Google, is separate and has its own rules.
We have deliberately not enabled provider features that would create additional copies of your child’s content: no request/response logging, no conversation caching, no session resumption, and no web-search or maps grounding. Our server refuses to open a child session if any of those are configured.
Backups and Logs
Encrypted backups exist so we can recover from a failure. They expire on a short cycle and restoring one never returns deleted child data to the product. Operational logs record that a request happened and whether it succeeded — they do not contain a child’s speech, transcripts, or answers.
Deleting Sooner
You never have to wait for these timers. In Parent Settings → Privacy & Data you can delete a single child’s information or your whole account at any time, and stored files are removed before the database records that point at them. If a deletion cannot be completed, we tell you rather than reporting success. See our Contact & Privacy Rights page or email privacy@userusty.com.