Controller: Daralexion Ltd · Last updated: 16 July 2026 · Version 1.0
This policy sets out how long Daralexion Ltd keeps personal data collected through the Maevious Learn app, and how it is deleted. It satisfies the app stores' deletion requirements (including Apple's requirement for in-app account deletion) and the UK GDPR storage-limitation and right-to-erasure principles.
We keep personal data only for as long as it is needed to provide the app to your family, and no longer. Because the app is built on data minimisation, there is very little to retain in the first place.
| Data | Retained while… | On deletion |
|---|---|---|
| Parent account (email, password hash, display name) | The account is active | Removed immediately on account deletion |
| Learner profiles (nickname, year level, avatar) | The account is active | Cascade-deleted with the account |
| Progress, XP, streaks | The account is active | Cascade-deleted with the account |
| Question reports you raised | The account is active (used to fix content) | Cascade-deleted with the account |
| Contact / concern messages | Until resolved + a short admin period, then the account's lifetime | Cascade-deleted with the account |
| Referral code / count | The account is active | Cascade-deleted with the account |
| Analytics events (PostHog EU) | Aggregate product metrics, keyed to a random id — no name/email/child data | Not linkable to you after deletion; retained under PostHog's standard EU-hosted retention policy |
| Weekly-summary email delivery logs (Resend) | Short operational window | Per Resend's standard retention policy |
Learning content (lessons, questions) is not personal data. It is never hard-deleted; superseded content is retired so that offline caches learn to remove it (a design requirement of the sync model), not for any personal-data reason.
You may also ask us to erase your data by contacting info@maevious.com. We will verify you are the account holder and action it, normally within one month (UK GDPR).
Personal data may persist briefly in encrypted database backups after deletion. Backups roll off on our provider's schedule (typically a small number of days for the point-in-time window), after which the data is gone from backups too. Restored backups are re-subjected to any outstanding deletion requests.
On termination of a processor relationship, or on instruction, our processors (Supabase, PostHog, Cloudflare R2, Resend) delete or return personal data per their data-processing terms.
This policy is reviewed at least annually and whenever the data model changes.