Data Retention and Deletion Policy
We keep data only as long as it is needed to provide Beadbar, then delete it. A job runs every day to carry out the scheduled deletions below. If it fails, we are alerted and fix it.
| Data | Why we keep it | When it is deleted |
|---|---|---|
| A child’s details, lesson records, weekly plans, notes, and family reports | So guides can plan and track progress | At once when the school deletes the child, or with the school |
| Lesson marks that staff removed | So a mistaken removal can be undone | Kept archived and restorable for 2 years after removal, then deleted. Deleted at once with the child or the school |
| All of a school’s or family account’s data | To provide Beadbar to the school or family | 7 days after a head of school asks to delete the school (the request can be cancelled until then), or when the period the school sets after its contract ends runs out (0 to 60 days; 60 unless the school chooses less) |
| Staff membership, classroom assignments, training progress, and presentation sign-offs | So each person sees the right classrooms and can be trained | When the person leaves the school, or with the school. Records a staff member made stay with the child |
| Your account: name, email address, state, favorites, Google sign-in details | To sign you in | At once when you delete your account |
| An account with no school that nobody has signed in to for about 2 years | No longer needed | We email a warning after about 23 months without a sign-in, then delete it 30 days later if nobody signs in |
| Sign-in sessions (IP address, browser) | To keep you signed in | When the session ends, at most 30 days after your last visit, or when you sign out |
| Sign-in codes | To sign you in | Stop working after 10 minutes; deleted by the next daily job |
| Counts of recent sign-in attempts (IP address) | To block repeated attempts | After 1 day |
| Family access (a family member’s link to a child) | So the family can see the child’s progress | When the school removes it, the family member leaves, or the child or school is deleted |
| Family invites (email address, child) | So a family member can join | Links stop working after 14 days; the invite record is deleted 30 days after that, used or not |
| Staff invites (email address, role, classrooms) | So staff can join | Links stop working after 14 days; the invite record is deleted 30 days after that, used or not |
| Change log entries | So a school can see who changed a record | With the school |
| The plan, its status, and Stripe’s account numbers for a paid plan | To know what the school or family has paid for | With the school or family account. Stripe keeps its own payment records (billing name, email, address, invoices) as tax and financial laws require |
| Records of which documents a person accepted | To show what was agreed | While the account exists. After the account is deleted, until 3 years after the acceptance. A school’s acceptance of the School Data Agreement is deleted with the school |
| Emails we sent | Our email service keeps them for troubleshooting | Within 45 days |
| The copy the Record screen keeps on a staff member’s device | So recording works without a connection | When they sign out on that device |
| Backups | To recover from mistakes or failures | Deleted data is gone from backups within 7 days |
| Deletion records (what was deleted, when, at whose request, and how many records; no names or content) | To confirm a deletion when asked | Kept while we operate Beadbar |
If the law requires us to keep something longer, such as under a court order, we keep only that data, only as long as required, and tell the school unless the law forbids it.
Asking for deletion
Staff whose role allows it delete a child in Beadbar, and a head of school deletes the school. Anyone can delete their own account from Your account. A school’s only head of school must first make someone else head, or delete the school. Parents ask their child’s school. You can also write to privacy@aprative.com. When asked, we confirm a deletion in writing.
Change log
| Version | Date | Change |
|---|---|---|
| 1.0 | 2026-09-25 | First version for the pilot. |
| 1.1 | 2026-09-26 | Added paid-plan billing records. |