Data Retention and Deletion Policy
This page says exactly how long we keep everything, and why. Most privacy policies in this category say "as long as necessary", which means nothing and commits to nothing. We would rather publish the numbers and be held to them.
Effective from 19 September 2026. Version 1.1.
The short version #
| Shared records — messages, expenses, swaps, plan versions | 7 years from the last activity in your family, then permanently deleted |
| Your personal profile | Deleted or anonymised when you close your account |
| Your drafts and private notes | Never stored at all |
| Export access | Permanent and free, including after cancellation, for as long as we hold the records |
If you close your account, your profile goes and the shared record stays — because it is your co-parent's record as much as yours, and because it may be needed if either of you ends up in court. Section 3 explains this properly.
1. The principles we apply #
- We keep what we need for as long as we need it, and no longer. That is the storage limitation principle in UK GDPR and it is the rule this whole page follows.
- We publish real numbers. A retention period you cannot state is a retention period you have not thought about.
- Evidential records are different. The whole value of an append-only record is that it is still there, complete, when someone needs to rely on it. That justifies a longer period than an ordinary app needs — but not an indefinite one.
- One parent cannot destroy the other parent's record. Not by leaving, not by asking, not by threatening.
- We never hold records to ransom. Export is free, permanent, and available on every plan and after cancellation.
2. The retention schedule #
2.1 Family records #
| Data | Retention period | Why |
|---|---|---|
| Messages (content, timestamps, first-viewed receipts) | 7 years from the last activity in the family | Evidential — Article 17(3)(e) UK GDPR, establishment, exercise or defence of legal claims |
| Expense records — entries, approvals, declines, settlements, confirmations, splits at the time | 7 years from last family activity | Evidential; also relevant to Child Maintenance Service and financial disputes |
| Receipts and expense attachments | 7 years from last family activity | As above |
| Swap requests and responses | 7 years from last family activity | Evidential — what was agreed, and when |
| Parenting plan versions and acceptances | 7 years from last family activity | Evidential — the core agreement record |
| Money agreement and its change history | 7 years from last family activity | Evidential |
| Calendar history (the schedule as it actually ran, including swaps) | 7 years from last family activity | Evidential — overnight counts matter for CMS shared-care bands, sometimes retrospectively |
| Calendar future (generated forward schedule) | Regenerated continuously; historical materialisations not retained separately | Operational |
| Professional access log — who had access, in what capacity, when | 7 years from last family activity | Transparency and evidential; both parents are entitled to a permanent record of who saw what |
| Hash chain and integrity metadata | For the life of the records it covers | Without it the records cannot be verified |
"Last activity in the family" means the most recent of: either parent logging in, either parent creating a record, an active subscription, or an export being generated. The clock restarts each time.
2.2 The Info Bank and children's data #
| Data | Retention period | Why |
|---|---|---|
| Info Bank entries — medical, school, sizes, contacts | While the family is active. Either parent can delete an entry at any time. Deleted entries are removed within 30 days and are not part of the evidential record | Operational, not evidential. Current information about a child should be current, and stale medical information is a hazard rather than an asset |
| Documents uploaded to the Info Bank | As above — deletable by either parent, removed within 30 days | As above |
| Children's names, dates of birth and schedule | With the family record — 7 years from last family activity | Necessary to make the evidential record intelligible. A record of arrangements that does not say which child is not a record |
| Anything about a child written into a message or a plan | With that message or plan — 7 years | It is part of the shared record and cannot be separated from it |
We apply data minimisation to children's data deliberately: the Info Bank is entirely optional, we do not require it to use OurPath, and we do not prompt for information we have no use for.
2.3 Account and identity #
| Data | Retention period |
|---|---|
| Name, email, profile, settings | Life of the account; deleted or irreversibly anonymised within 30 days of closure |
| Password hash | Life of the account; deleted on closure |
| Profile photo | Life of the account; deleted on closure |
| Draft messages | Never stored |
| Private notes | Life of the account; deleted on closure |
| Device tokens and push registrations | Life of the account, or 90 days after last use, whichever is sooner |
| Session and authentication tokens | 30 days from expiry |
| Invitations that were never accepted | 12 months, then deleted |
2.4 Payments and finance #
| Data | Retention period | Why |
|---|---|---|
| Invoices, transaction records, subscription history | 6 years from the end of the financial year they relate to | Companies Act 2006 and HMRC requirements |
| Card details | We never hold them. Stripe holds them under its own retention rules | — |
| Last four digits, card type, expiry | Life of the subscription, then with the invoice record | Billing support and dispute resolution |
| Refund and chargeback records | 6 years | Legal obligation |
| Corporation tax and statutory company records | 6 years | Companies Act 2006, HMRC. |
| Fee waiver and discount attribution | With the subscription record, 6 years | Audit of the legal aid waiver and professional discount |
2.5 Technical and security #
| Data | Retention period |
|---|---|
| Security and access logs (logins, failed attempts, admin access) | 12 months |
| Application and error logs | 90 days |
| Crash and error reports | 90 days |
| IP addresses in web server logs | 30 days |
| Product analytics events (funnel only, never content) | 25 months, then aggregated and the identifiers removed |
| Rate-limiting and abuse-prevention records | 12 months |
| Bot-check (Turnstile) tokens | Not retained by us — the token is validated and discarded |
2.6 Backups #
| Point-in-time recovery | Rolling 7 days |
| Nightly encrypted snapshots | 35 days, then overwritten |
Deletion and backups. When we delete something, it is removed from the live system immediately (or within the period stated) but may persist in an encrypted backup until that backup is overwritten — up to 35 days. Backups are not used for any purpose other than disaster recovery, and where we restore a backup we re-apply any deletions made in the meantime. This is the standard position for any system with backups and we state it rather than pretending otherwise.
2.7 Communications and support #
| Data | Retention period |
|---|---|
| Support correspondence | 3 years from the last message in the thread |
| Complaints and their outcomes | 6 years — we need to show what we did |
| Safeguarding concerns raised with us and our response | 7 years, and longer where a matter remains live or a legal obligation applies |
| Data subject request records (what was asked, what we did) | 3 years |
| Breach records | 6 years — accountability under UK GDPR |
2.8 Marketing and website #
| Data | Retention period |
|---|---|
| Marketing contacts | Until you unsubscribe. Then 2 years on a suppression list, so we do not contact you again by accident |
| Waiting list sign-ups | 24 months, or until you ask us to remove you |
| Free tool submissions (plan builder, nights calculator) | Not retained against an identity unless you ask us to email you a copy; then 12 months |
| Website analytics | See the Cookie Policy |
2.9 Professionals #
| Data | Retention period |
|---|---|
| Professional account and profile | Life of the account; deleted or anonymised within 30 days of closure |
| Record of which professional had access to which family, and when | With the family record — 7 years — because both parents are entitled to a permanent record of professional access |
| Evidence of registration, accreditation and insurance | Life of the account plus 6 years |
3. Account closure — what goes and what stays #
3.1 What is deleted within 30 days #
- Your display name and profile
- Your photo
- Your email address, except where a legal or accounting obligation requires it on an invoice record
- Your account settings and preferences
- Your drafts and private notes
- Your payment details held by us
- Your device tokens and sessions
3.2 What is retained #
The shared record your family created, with your name replaced by a neutral label such as "Parent A".
3.3 Why #
Two reasons, and both are real:
Your co-parent's rights. The shared record is their record too. It documents things they may need to rely on — an agreement, an approval, a refusal, a pattern. Allowing either parent to destroy it by closing an account would make the record worthless, and would hand a tactical advantage to whichever parent left first. We will not build that.
Legal claims. Article 17(3)(e) UK GDPR permits retention where necessary for the establishment, exercise or defence of legal claims. Family proceedings, CMS disputes, enforcement applications and variations routinely look back over years. A parent who closes an account in March may be in a hearing in November.
3.4 Why seven years #
We considered shorter and longer, and settled on seven because:
- the ordinary limitation period for contract and tort claims in England and Wales is six years (Limitation Act 1980), and seven gives a margin for a claim issued at the end of it;
- financial records must be kept six years for tax purposes anyway;
- children's proceedings can revisit historical arrangements well after the events;
- indefinite retention is not acceptable to us. Several products in this category effectively retain forever, behind "as long as necessary for potential claims". That is not a retention period; it is the absence of one, and it does not satisfy storage limitation.
Seven years from last family activity, not from account closure, because an active family's older records still matter to that family.
3.5 Deleting the shared record early #
The shared record is deleted before seven years only where:
- both parents ask us to, and there is no legal reason to retain it; or
- a court orders it.
If you ask alone, we will tell you within one month, tell you exactly what we deleted and what we kept, give you the specific legal basis, and tell you how to complain — to us and to the ICO.
3.6 Death and incapacity #
On notification of a parent's death with reasonable evidence, we freeze the account and preserve the record as it stood. We do not delete it. The surviving parent retains access and export rights. The seven-year clock continues to run from the family's last activity.
For a parent who lacks capacity, we consider requests from an attorney under a lasting power of attorney or a court-appointed deputy, on evidence of that authority.
4. How deletion actually happens #
- Automated. Retention periods are enforced by scheduled jobs, not by someone remembering. Records that reach the end of their period are deleted, not archived.
- Anonymisation where deletion is not possible. Where a record must remain for another person's benefit, we remove or replace the identifiers rather than keeping the whole thing.
- Irreversible. Deleted means deleted. There is no recycle bin and we cannot restore a record after the backup window has passed, even if you ask us to.
- Verified. We review this policy and audit the deletion jobs at least annually, and whenever we add a feature that creates a new class of data.
5. Legal holds #
Where we are notified of, or reasonably anticipate, legal proceedings, a regulatory investigation or a complaint involving specific data, we may place a legal hold on it and retain it beyond the periods above until the matter is resolved.
If a legal hold affects your data, we will tell you, unless we are legally prohibited or a safeguarding reason prevents it.
6. Your options #
| You want to | What to do |
|---|---|
| Get a copy of everything | Use the export feature. Free, permanent, no account needed to verify it |
| Remove Info Bank content | Delete it yourself in the app, at any time |
| Correct an error | Correct it in the app, or email hello@ourpath.app for anything you cannot change yourself |
| Correct something in a shared record | You cannot edit it, but you can add a correction to the record, which is the right remedy for a disputed fact |
| Close your account | Account settings, or email hello@ourpath.app |
| Delete the shared record | Both parents email hello@ourpath.app |
| Challenge what we have kept | hello@ourpath.app, then the ICO — see the Privacy Policy |
7. Changes to this policy #
We will give at least 30 days' notice of any change that extends a retention period or reduces what you can delete. Previous versions are kept at ourpath.app/legal/data-retention/archive.
Version history #
| Version | Date | Change |
|---|---|---|
| 1.1 | 19 September 2026 | First published |
Our Path Digital Ltd · Registered in England and Wales, company number 17406043 · ICO registration ZC250261 · hello@ourpath.app