OT Elevate

Retention schedule

Last updated: September 26, 2026

Summary. Every category of data OT Elevate holds, how long we keep it, what makes us delete it, and how long until it is gone from our backups too. Nothing on this page says “indefinitely.” If a category is missing from this table, tell us and we will either add it or stop collecting it.

How to read the table. Retention is the longest we keep something in normal operation. Deletion trigger is what starts the clock. Backup purge is the outside window for the data to be gone from every backup copy as well; our backups are encrypted and rotate on a 30-day cycle, so the usual answer is 35 days. If a backup is restored, deletions made since that backup are re-applied as part of the restore procedure in Information security program.

Data category Retention Deletion trigger Backup purge
Parent account identity (name, email) Life of the account Account deletion 35 days
Account sign-in (the Apple sign-in identifier, held by our sign-in provider, Firebase — no password) Life of the account Account deletion 35 days
Subscription status from the App Store Life of the account Account deletion 35 days
Age-screen refusal record (no personal information; a device-level flag that an under-13 answer was given) 12 months Automatic expiry Not backed up
Athlete profile (name or nickname, age or birth year, grad year, school, state, sport, position) Life of the account Account deletion, or parent deletes the athlete 35 days
Academic record (GPA, test scores, coursework notes) Life of the account Account deletion, or parent deletes the entry 35 days
Athletic record (teams, seasons, stats, testing numbers, awards) Life of the account Account deletion, or parent deletes the entry 35 days
Consumer health data (injuries, symptoms, clearance dates and status, restrictions, load and wellness logs) Life of the account Account deletion, parent or athlete deletion, or withdrawal of consent to collection 35 days
Physical-exam and document images uploaded for extraction Life of the athlete’s record — kept as proof of clearance, not deleted on extraction Parent deletes it at any time, or account deletion 35 days
Fields extracted from those images Life of the account Account deletion, or parent deletes the entry 35 days
Spend entries and receipts Life of the account Account deletion, or parent deletes the entry 35 days
Eli conversation transcripts 24 months after the last message in the conversation Parent deletes the conversation (immediate), account deletion, or automatic expiry 24 months after the last message 35 days
Eli memory about an athlete (the durable facts Eli keeps so it does not re-ask) Life of the account Parent deletes it at any time in Family (immediate), or account deletion 35 days
Rules-engine query log (question asked, rule applied, answer given) 12 months Automatic expiry; account deletion removes the account-linked copy 35 days
Text and photos sent to the third-party AI providers Not retained by us. Anthropic: deleted within 30 days, unless its safety systems flag it (then up to 2 years) or the law requires longer. Voyage AI: not kept (storage and training turned off for our account) The provider’s published retention Not in our backups
Server and application logs 90 days Automatic expiry Not backed up beyond the 90 days
Security and audit logs (administrative access, permission changes, data exports, deletions) 90 days Automatic expiry 35 days
Google Cloud’s own record of administrative actions on our cloud account (who changed access, settings or the database, and when; no family content) 400 days, set by Google Automatic expiry by Google; nobody, including us, can shorten it or delete it sooner Not in our backups
Support correspondence 24 months after the ticket closes Automatic expiry, or on request 35 days
Rights-request records (what was asked, what we did, when) 24 months, as the record that we honored the request Automatic expiry 35 days
Crisis referral counts (category, date, athlete or parent — no content, no names) 7 years, for the annual report to California’s Office of Suicide Prevention Automatic expiry 35 days
Crisis parent-notification records (that a notification was sent, when, which category) 24 months Automatic expiry, or account deletion 35 days
Pinned verdicts (a verdict a family acted on, held past the rules-engine query log’s normal clock) Life of the account Account deletion 35 days
The recruiting question a family stated (which division and program gender to read the calendars for) Life of the account Account deletion, or parent or athlete withdraws it 35 days
Push notification preference (which division/gender to track) Life of the account Account deletion, or parent or athlete deletes the entry 35 days
Registered push-notification device token Life of the account Account deletion 35 days
Push notification delivery record (what was sent, when, whether it succeeded) 24 months Automatic expiry, or account deletion 35 days
Account data export files we generate for you 7 days from generation Automatic expiry after download window Not backed up
Account-deletion record (a minimal tombstone: that an account with this identifier was deleted, and when) 24 months, so a deletion can be proven and not silently reversed Automatic expiry 35 days
Billing and tax records held by the Company (Apple’s records of the transaction, not card data) 7 years from the transaction Automatic expiry 7 years after the transaction. Deleting the account unlinks these records from it but does not shorten the 7 years 35 days
College football staff work details (name, title, published work email, public X account), from their schools’ athletics websites Until the school’s website stops listing the person, checked at each monthly refresh The monthly refresh finds the person no longer listed, or the person asks us to remove them Not in our backups. The directory is a file rebuilt whole at each refresh; earlier monthly copies stay in the history of the code repository it is kept in
Backups themselves 30-day rotation Automatic rotation n/a

Notes#

See Privacy policy for what each category is and why we have it, and Information security program for how deletion from backups actually works.