Data Retention and Deletion Policy

This page says exactly how long we keep everything, and why. Most privacy policies in this category say "as long as necessary", which means nothing and commits to nothing. We would rather publish the numbers and be held to them.

Effective from 19 September 2026. Version 1.1.


The short version #

Shared records — messages, expenses, swaps, plan versions 7 years from the last activity in your family, then permanently deleted
Your personal profile Deleted or anonymised when you close your account
Your drafts and private notes Never stored at all
Export access Permanent and free, including after cancellation, for as long as we hold the records

If you close your account, your profile goes and the shared record stays — because it is your co-parent's record as much as yours, and because it may be needed if either of you ends up in court. Section 3 explains this properly.


1. The principles we apply #

  1. We keep what we need for as long as we need it, and no longer. That is the storage limitation principle in UK GDPR and it is the rule this whole page follows.
  2. We publish real numbers. A retention period you cannot state is a retention period you have not thought about.
  3. Evidential records are different. The whole value of an append-only record is that it is still there, complete, when someone needs to rely on it. That justifies a longer period than an ordinary app needs — but not an indefinite one.
  4. One parent cannot destroy the other parent's record. Not by leaving, not by asking, not by threatening.
  5. We never hold records to ransom. Export is free, permanent, and available on every plan and after cancellation.

2. The retention schedule #

2.1 Family records #

Data Retention period Why
Messages (content, timestamps, first-viewed receipts) 7 years from the last activity in the family Evidential — Article 17(3)(e) UK GDPR, establishment, exercise or defence of legal claims
Expense records — entries, approvals, declines, settlements, confirmations, splits at the time 7 years from last family activity Evidential; also relevant to Child Maintenance Service and financial disputes
Receipts and expense attachments 7 years from last family activity As above
Swap requests and responses 7 years from last family activity Evidential — what was agreed, and when
Parenting plan versions and acceptances 7 years from last family activity Evidential — the core agreement record
Money agreement and its change history 7 years from last family activity Evidential
Calendar history (the schedule as it actually ran, including swaps) 7 years from last family activity Evidential — overnight counts matter for CMS shared-care bands, sometimes retrospectively
Calendar future (generated forward schedule) Regenerated continuously; historical materialisations not retained separately Operational
Professional access log — who had access, in what capacity, when 7 years from last family activity Transparency and evidential; both parents are entitled to a permanent record of who saw what
Hash chain and integrity metadata For the life of the records it covers Without it the records cannot be verified

"Last activity in the family" means the most recent of: either parent logging in, either parent creating a record, an active subscription, or an export being generated. The clock restarts each time.

2.2 The Info Bank and children's data #

Data Retention period Why
Info Bank entries — medical, school, sizes, contacts While the family is active. Either parent can delete an entry at any time. Deleted entries are removed within 30 days and are not part of the evidential record Operational, not evidential. Current information about a child should be current, and stale medical information is a hazard rather than an asset
Documents uploaded to the Info Bank As above — deletable by either parent, removed within 30 days As above
Children's names, dates of birth and schedule With the family record — 7 years from last family activity Necessary to make the evidential record intelligible. A record of arrangements that does not say which child is not a record
Anything about a child written into a message or a plan With that message or plan — 7 years It is part of the shared record and cannot be separated from it

We apply data minimisation to children's data deliberately: the Info Bank is entirely optional, we do not require it to use OurPath, and we do not prompt for information we have no use for.

2.3 Account and identity #

Data Retention period
Name, email, profile, settings Life of the account; deleted or irreversibly anonymised within 30 days of closure
Password hash Life of the account; deleted on closure
Profile photo Life of the account; deleted on closure
Draft messages Never stored
Private notes Life of the account; deleted on closure
Device tokens and push registrations Life of the account, or 90 days after last use, whichever is sooner
Session and authentication tokens 30 days from expiry
Invitations that were never accepted 12 months, then deleted

2.4 Payments and finance #

Data Retention period Why
Invoices, transaction records, subscription history 6 years from the end of the financial year they relate to Companies Act 2006 and HMRC requirements
Card details We never hold them. Stripe holds them under its own retention rules
Last four digits, card type, expiry Life of the subscription, then with the invoice record Billing support and dispute resolution
Refund and chargeback records 6 years Legal obligation
Corporation tax and statutory company records 6 years Companies Act 2006, HMRC.
Fee waiver and discount attribution With the subscription record, 6 years Audit of the legal aid waiver and professional discount

2.5 Technical and security #

Data Retention period
Security and access logs (logins, failed attempts, admin access) 12 months
Application and error logs 90 days
Crash and error reports 90 days
IP addresses in web server logs 30 days
Product analytics events (funnel only, never content) 25 months, then aggregated and the identifiers removed
Rate-limiting and abuse-prevention records 12 months
Bot-check (Turnstile) tokens Not retained by us — the token is validated and discarded

2.6 Backups #

Point-in-time recovery Rolling 7 days
Nightly encrypted snapshots 35 days, then overwritten

Deletion and backups. When we delete something, it is removed from the live system immediately (or within the period stated) but may persist in an encrypted backup until that backup is overwritten — up to 35 days. Backups are not used for any purpose other than disaster recovery, and where we restore a backup we re-apply any deletions made in the meantime. This is the standard position for any system with backups and we state it rather than pretending otherwise.

2.7 Communications and support #

Data Retention period
Support correspondence 3 years from the last message in the thread
Complaints and their outcomes 6 years — we need to show what we did
Safeguarding concerns raised with us and our response 7 years, and longer where a matter remains live or a legal obligation applies
Data subject request records (what was asked, what we did) 3 years
Breach records 6 years — accountability under UK GDPR

2.8 Marketing and website #

Data Retention period
Marketing contacts Until you unsubscribe. Then 2 years on a suppression list, so we do not contact you again by accident
Waiting list sign-ups 24 months, or until you ask us to remove you
Free tool submissions (plan builder, nights calculator) Not retained against an identity unless you ask us to email you a copy; then 12 months
Website analytics See the Cookie Policy

2.9 Professionals #

Data Retention period
Professional account and profile Life of the account; deleted or anonymised within 30 days of closure
Record of which professional had access to which family, and when With the family record — 7 years — because both parents are entitled to a permanent record of professional access
Evidence of registration, accreditation and insurance Life of the account plus 6 years

3. Account closure — what goes and what stays #

3.1 What is deleted within 30 days #

3.2 What is retained #

The shared record your family created, with your name replaced by a neutral label such as "Parent A".

3.3 Why #

Two reasons, and both are real:

Your co-parent's rights. The shared record is their record too. It documents things they may need to rely on — an agreement, an approval, a refusal, a pattern. Allowing either parent to destroy it by closing an account would make the record worthless, and would hand a tactical advantage to whichever parent left first. We will not build that.

Legal claims. Article 17(3)(e) UK GDPR permits retention where necessary for the establishment, exercise or defence of legal claims. Family proceedings, CMS disputes, enforcement applications and variations routinely look back over years. A parent who closes an account in March may be in a hearing in November.

3.4 Why seven years #

We considered shorter and longer, and settled on seven because:

Seven years from last family activity, not from account closure, because an active family's older records still matter to that family.

3.5 Deleting the shared record early #

The shared record is deleted before seven years only where:

If you ask alone, we will tell you within one month, tell you exactly what we deleted and what we kept, give you the specific legal basis, and tell you how to complain — to us and to the ICO.

3.6 Death and incapacity #

On notification of a parent's death with reasonable evidence, we freeze the account and preserve the record as it stood. We do not delete it. The surviving parent retains access and export rights. The seven-year clock continues to run from the family's last activity.

For a parent who lacks capacity, we consider requests from an attorney under a lasting power of attorney or a court-appointed deputy, on evidence of that authority.

4. How deletion actually happens #

Where we are notified of, or reasonably anticipate, legal proceedings, a regulatory investigation or a complaint involving specific data, we may place a legal hold on it and retain it beyond the periods above until the matter is resolved.

If a legal hold affects your data, we will tell you, unless we are legally prohibited or a safeguarding reason prevents it.

6. Your options #

You want to What to do
Get a copy of everything Use the export feature. Free, permanent, no account needed to verify it
Remove Info Bank content Delete it yourself in the app, at any time
Correct an error Correct it in the app, or email hello@ourpath.app for anything you cannot change yourself
Correct something in a shared record You cannot edit it, but you can add a correction to the record, which is the right remedy for a disputed fact
Close your account Account settings, or email hello@ourpath.app
Delete the shared record Both parents email hello@ourpath.app
Challenge what we have kept hello@ourpath.app, then the ICO — see the Privacy Policy

7. Changes to this policy #

We will give at least 30 days' notice of any change that extends a retention period or reduces what you can delete. Previous versions are kept at ourpath.app/legal/data-retention/archive.

Version history #

Version Date Change
1.1 19 September 2026 First published

Our Path Digital Ltd · Registered in England and Wales, company number 17406043 · ICO registration ZC250261 · hello@ourpath.app