Data Retention Policy
Last updated: July 26, 2026
This policy says what Lunela keeps, why, and for how long. It sits alongside our Privacy Policy, which explains what we collect and who it goes to.
The short version: we keep a child’s information only while it is being used to continue their story, and no longer. There is no “soft delete” here — when something is deleted, it is gone, not hidden behind a flag.
What we keep, and for how long
- Your child’s profile — first name, age, pronouns, chosen interests, and anything you entered about fears or themes: kept while the service relationship is live (see below).
- Stories and audio — episodes, one-off stories, worlds, characters and narration files: the same.
- Your account — your Apple identifier, your email if you chose to share it, and your notification token: the same.
- A narration voice you recorded — removed when you delete it, when you delete your account, or automatically after 365 days without being used, whichever comes first.
- The raw voice recording itself — never stored. It is sent to create the voice and not written to our systems at all.
- A record of your purchase — kept after account deletion, because we are required to keep records of sales for tax and accounting. It holds subscription state and an anonymous customer id: no child data, no stories, no names.
- Usage analytics — none. No analytics or crash-reporting service is switched on, so nothing about how your family uses the app is collected at all.
What “while the relationship is live” means
One rule, the same for everybody. We keep your family’s data while either the app has been opened in the last 18 months, or you have a subscription running. An active subscription always keeps your account, whether or not you have opened the app recently.
If neither is true, we should not still be holding a child’s details, so the account is removed — but never without telling you first:
- We email you, saying exactly what will be deleted and when.
- You have 30 days. Opening the app is all it takes to cancel it — no reply, nothing to click.
- Only then is the account erased, through the same process as the delete button in the app.
If that email cannot be sent, nothing is deleted; the account waits and is reconsidered later. Deletion for inactivity never happens without a warning having reached you first.
What causes deletion
- You delete your account — Profile → Delete account. Immediate and permanent: the child profile, every story, every audio file, any narration voice including the model held by our voice provider, and our records of rejected content. No grace period and no recovery window.
- You delete a voice — Profile → Reading Preferences. Removed from our systems and from our voice provider.
- A voice goes unused for 365 days — removed automatically, with no human involvement.
- The relationship lapses — as described above.
- You ask us in writing — email [email protected] and we will action it by the same routes.
If your plan has ended but you recorded a voice while it was active, that voice stays visible in Reading Preferences so you can still remove it. Your ability to delete your own data never depends on paying us.
Our providers
The companies listed in our Privacy Policy delete what they hold on our instruction. Two are worth stating plainly:
- Our story provider keeps a log of requests for up to 30 days to detect misuse of its own service, then deletes it. Your child’s exact age is never in it, because we never send it. Their first name is not in the request that writes the story — that one uses a placeholder — but it is in the request that reads the story aloud, because a name has to be spoken to be narrated.
- Our voice provider holds the narration voice model you created, and destroys it on the triggers above. When a story is read in that voice, it also receives the story text. It is not used to train anyone’s systems.
Backups
Deleting something removes it from our live systems immediately. Backups are a separate copy, and we would rather be exact than reassuring: today the service runs without retained backups, so a deletion really is immediate and total — there is no copy of it anywhere.
That will change when we move to a backed-up plan, which we intend to do before a wider launch. From that point a deleted record can survive inside a backup until the oldest backup rolls past it, and this section will be updated to state that window. Backups are only ever used to recover from failure, never to look up an individual account, and we do not edit inside them on request — the commitment is the window, after which no copy remains.
Changes
We review this policy whenever our providers, our systems or our deletion rules change, and at least once a year. If we change it we will revise the date above, and for material changes we will tell you in the app.
Contact
Questions or requests: [email protected].