Retention schedule
Last updated: September 26, 2026
Summary. Every category of data OT Elevate holds, how long we keep it, what makes us delete it, and how long until it is gone from our backups too. Nothing on this page says “indefinitely.” If a category is missing from this table, tell us and we will either add it or stop collecting it.
How to read the table. Retention is the longest we keep something in normal operation. Deletion trigger is what starts the clock. Backup purge is the outside window for the data to be gone from every backup copy as well; our backups are encrypted and rotate on a 30-day cycle, so the usual answer is 35 days. If a backup is restored, deletions made since that backup are re-applied as part of the restore procedure in Information security program.
| Data category | Retention | Deletion trigger | Backup purge |
|---|---|---|---|
| Parent account identity (name, email) | Life of the account | Account deletion | 35 days |
| Account sign-in (the Apple sign-in identifier, held by our sign-in provider, Firebase — no password) | Life of the account | Account deletion | 35 days |
| Subscription status from the App Store | Life of the account | Account deletion | 35 days |
| Age-screen refusal record (no personal information; a device-level flag that an under-13 answer was given) | 12 months | Automatic expiry | Not backed up |
| Athlete profile (name or nickname, age or birth year, grad year, school, state, sport, position) | Life of the account | Account deletion, or parent deletes the athlete | 35 days |
| Academic record (GPA, test scores, coursework notes) | Life of the account | Account deletion, or parent deletes the entry | 35 days |
| Athletic record (teams, seasons, stats, testing numbers, awards) | Life of the account | Account deletion, or parent deletes the entry | 35 days |
| Consumer health data (injuries, symptoms, clearance dates and status, restrictions, load and wellness logs) | Life of the account | Account deletion, parent or athlete deletion, or withdrawal of consent to collection | 35 days |
| Physical-exam and document images uploaded for extraction | Life of the athlete’s record — kept as proof of clearance, not deleted on extraction | Parent deletes it at any time, or account deletion | 35 days |
| Fields extracted from those images | Life of the account | Account deletion, or parent deletes the entry | 35 days |
| Spend entries and receipts | Life of the account | Account deletion, or parent deletes the entry | 35 days |
| Eli conversation transcripts | 24 months after the last message in the conversation | Parent deletes the conversation (immediate), account deletion, or automatic expiry 24 months after the last message | 35 days |
| Eli memory about an athlete (the durable facts Eli keeps so it does not re-ask) | Life of the account | Parent deletes it at any time in Family (immediate), or account deletion | 35 days |
| Rules-engine query log (question asked, rule applied, answer given) | 12 months | Automatic expiry; account deletion removes the account-linked copy | 35 days |
| Text and photos sent to the third-party AI providers | Not retained by us. Anthropic: deleted within 30 days, unless its safety systems flag it (then up to 2 years) or the law requires longer. Voyage AI: not kept (storage and training turned off for our account) | The provider’s published retention | Not in our backups |
| Server and application logs | 90 days | Automatic expiry | Not backed up beyond the 90 days |
| Security and audit logs (administrative access, permission changes, data exports, deletions) | 90 days | Automatic expiry | 35 days |
| Google Cloud’s own record of administrative actions on our cloud account (who changed access, settings or the database, and when; no family content) | 400 days, set by Google | Automatic expiry by Google; nobody, including us, can shorten it or delete it sooner | Not in our backups |
| Support correspondence | 24 months after the ticket closes | Automatic expiry, or on request | 35 days |
| Rights-request records (what was asked, what we did, when) | 24 months, as the record that we honored the request | Automatic expiry | 35 days |
| Crisis referral counts (category, date, athlete or parent — no content, no names) | 7 years, for the annual report to California’s Office of Suicide Prevention | Automatic expiry | 35 days |
| Crisis parent-notification records (that a notification was sent, when, which category) | 24 months | Automatic expiry, or account deletion | 35 days |
| Pinned verdicts (a verdict a family acted on, held past the rules-engine query log’s normal clock) | Life of the account | Account deletion | 35 days |
| The recruiting question a family stated (which division and program gender to read the calendars for) | Life of the account | Account deletion, or parent or athlete withdraws it | 35 days |
| Push notification preference (which division/gender to track) | Life of the account | Account deletion, or parent or athlete deletes the entry | 35 days |
| Registered push-notification device token | Life of the account | Account deletion | 35 days |
| Push notification delivery record (what was sent, when, whether it succeeded) | 24 months | Automatic expiry, or account deletion | 35 days |
| Account data export files we generate for you | 7 days from generation | Automatic expiry after download window | Not backed up |
| Account-deletion record (a minimal tombstone: that an account with this identifier was deleted, and when) | 24 months, so a deletion can be proven and not silently reversed | Automatic expiry | 35 days |
| Billing and tax records held by the Company (Apple’s records of the transaction, not card data) | 7 years from the transaction | Automatic expiry 7 years after the transaction. Deleting the account unlinks these records from it but does not shorten the 7 years | 35 days |
| College football staff work details (name, title, published work email, public X account), from their schools’ athletics websites | Until the school’s website stops listing the person, checked at each monthly refresh | The monthly refresh finds the person no longer listed, or the person asks us to remove them | Not in our backups. The directory is a file rebuilt whole at each refresh; earlier monthly copies stay in the history of the code repository it is kept in |
| Backups themselves | 30-day rotation | Automatic rotation | n/a |
Notes#
- Deletion in live systems is immediate. When a parent deletes a conversation, clears Eli’s memory, or deletes the account, it is gone from the app and from our production database at once. The backup purge window is the tail, not the wait.
- Account deletion is complete. It removes the account, both parent and athlete data, the record, the conversations, and Eli’s memory, subject only to the crisis referral counts (which contain no content or names) and the billing and tax records, which we keep for 7 years from the transaction, no longer linked to the account.
- Withdrawing consent to consumer health data deletes that data on the same timeline as any other deletion. Parts of the app that depend on it will stop working, and we will say which.
- No indefinite retention. Every row above has an end. If we ever need to hold something longer — a legal hold, for instance — we will say so here and say why.
See Privacy policy for what each category is and why we have it, and Information security program for how deletion from backups actually works.