1. Account and billing records
Active account records are kept while the account exists. Deleted-account data is removed from active systems subject to security, fraud, financial, tax, dispute, and backup obligations. Payment processors retain transaction data under their own legal obligations; GroupLock stores entitlement and transaction references rather than full payment-card data.
2. Messages and attachments
Messages and attachments remain while the authorized conversation and account relationship require them, unless deleted earlier. Account deletion, circle deletion, message deletion, child-profile deletion, or attachment cleanup triggers removal from active systems and private object storage where supported. Unsupported screenshots or external copies cannot be recalled.
3. Invitations and authorization receipts
Pending requests expire according to the product workflow. Consent receipts and their tamper-evident history may be retained after revocation or expiration to prove what was authorized, denied, suspended, or terminated, but access to their underlying protected content ends with the authorization.
4. Managed child information
GroupLock stores only the child information required for Guardian Protection, such as a family-approved nickname, age band, guardian relationship, approved circles, supervised devices, safety records, and authorization evidence. Failed verification sessions are scheduled for deletion after 90 days; temporary provider metadata is minimized after 30 days; child-code attempts after 30 days; notification evidence after one year; and child audit/privacy-request records after three years unless a shorter legal or contractual period applies.
5. Guardian deletion and stop-collection requests
A guardian may stop collection immediately, which pauses the profile and revokes active child authorizations. A child-profile deletion request uses a seven-day safety window during which the guardian may cancel. After the window, the profile, child-authored messages, associated private media, devices, and child-specific records are deleted or de-identified except for narrowly required safety, legal, fraud, or transaction evidence.
6. Safety and moderation evidence
Routine safety cases are retained only long enough for investigation, action, appeal, and trend prevention. Evidence concerning exploitation, serious threats, legal obligations, or preservation requests may be retained longer under restricted access. Sensitive message content is not copied into ordinary notification or audit records unless necessary for a safety investigation.
7. Institution programs
Each approved institution child program has a finite retention period, program end date, staff-access review, and parent-controlled enrollment. School or organization records are not reused for advertising, unrelated commercial purposes, or model training.
8. Review cycle
GroupLock reviews this schedule at least annually and when the service, law, vendors, safety program, or children’s data flow materially changes.
