Legal
Child Data Retention Policy
Last updated: September 13, 2026
COPPA requires us to publish why we collect children’s personal information, why we need to keep it, and when it is deleted. This is that policy. We do not keep children’s personal information indefinitely.
Our Rules
- Collect only what a parent-selected learning feature actually needs.
- Upload no child profile and process no live child voice until the adult has seen the direct notice, completed the authorization step shown in the app, and made the required consent choices.
- Never store raw microphone audio or full conversation transcripts.
- Delete information when its stated purpose ends, even though storage is cheap.
- Never sell children’s data or intentionally send child profile, learning, voice, or safety information for targeted advertising. The separate Meta one-time install and recurring cold-launch activation attribution signals are limited to the app, device, and network data described below.
The Schedule
| What | Why we need it | How long we keep it | How it goes away |
|---|---|---|---|
| Live microphone audio and speech text | Produce the current spoken reply | Not stored by Rusty at all | Nothing is written; see Section 3 for our AI provider |
| Child profile: name, age, grade, avatar, goals, interests, preferences | Run the profile you set up | While the profile is active and your consent is valid | Deleted when you delete the child or the account |
| Learning sessions, activity events, evidence, skill states, plans, summaries | Show progress and let the next session build on the last | 12 months | Automatic daily deletion job, plus child/account deletion |
| Safety event category and short non-verbatim note | Alert you to a possible serious concern | 30 days | Automatic daily deletion job |
| Voice session security records | Rate limiting and abuse investigation | 30 days | Automatic daily deletion job |
| Pending, failed, or expired adult-authorization metadata | Finish or debug a verification that did not complete | 30 days | Automatic daily deletion job |
| Successful adult-authorization result and consent history | Show what you authorized and when | While the family account is active | Deleted with the account |
| Parent account and family membership | Sign you in and run parent controls | While the account is active | In-app account deletion |
| Subscription and entitlement records | Provide and reconcile purchases; tax and legal duties | As long as required for those duties | Apple and RevenueCat processes, plus account deletion |
| Parent data export you request | Give you a copy of your child’s information | Not stored on our servers | Generated on demand; the app removes its temporary copy |
| Meta install and cold-launch activation attribution | Measure which Meta advertising campaigns lead to an install and attribute minimal activation/session signals on first and later cold launches | Rusty keeps no separate copy. Meta controls its own retention under its terms and privacy policy; Rusty does not claim a retention period it cannot verify. | Meta controls its deletion and rights processes; contact Rusty for help with a request |
Meta Install and Cold-Launch Activation Attribution
On the first active screen, iOS asks for tracking permission before Meta initializes or transmits. After that decision, the Meta App Install event is sent once and a minimal activation/session attribution signal may be sent on later cold launches. Rusty does not tie those signals to a child profile or intentionally send Meta any account, name, age, interest, child or family profile identifier, lesson activity, answer, voice or transcript, safety record, purchase, receipt, or subscription information. Advertiser tracking and IDFA collection are enabled only after Allow; they remain disabled after Ask App Not to Track. Automatic event and purchase logging are always disabled.
Contact privacy@userusty.com if you want help understanding or exercising rights related to this attribution.
Our AI Provider's Retention
Rusty stores no audio or transcripts. Our AI provider, Google, is separate and has its own rules.
We have deliberately not enabled provider features that would create additional copies of your child’s content: no request/response logging, no conversation caching, no session resumption, and no web-search or maps grounding. Our server refuses to open a child session if any of those are configured.
Backups and Logs
Encrypted provider backups and operational logs may exist for recovery, security, and diagnosing failures. Rusty does not intentionally put child speech recordings, full transcripts, or free-text child answers in them. Operational logs are kept for no more than 30 days. A residual copy of a deleted database record may remain in an encrypted, access-restricted backup for up to 30 days after removal from the active service, after which the backup copy is overwritten or expires. Backups are not used for product personalization or routine access; if one must be restored for disaster recovery, Rusty reapplies completed deletion requests before returning the data to active use.
Deleting Sooner
You never have to wait for these timers. In Parent Settings → Account and the selected child’s privacy controls, you can delete a single child’s information or your whole account at any time, and stored files are removed before the database records that point at them. If a deletion cannot be completed, we tell you rather than reporting success. See our Contact & Privacy Rights page or email privacy@userusty.com.
