Data Retention & Deletion Policy
ArtClass Labs LLC · Last updated: August 23, 2026
Published as part of, and incorporated into, our Privacy Policy. It satisfies the COPPA requirement (16 C.F.R. Part 312, as amended 2025) to publish a written retention policy stating the purpose of collection, the business need for retention, and a deletion timeline, and supports the storage-limitation duties in GDPR and Kosovo Law No. 06/L-082.
1. Principles
We keep children's personal data only as long as necessary for the purpose it was collected for. We never retain children's personal data indefinitely. When data is no longer needed, or when a parent withdraws consent or asks for deletion, we delete it or irreversibly anonymise it within the timelines below.
Where a record must be kept for accounting or tax reasons but no longer needs to identify a person, we strip the personal data and keep the transaction. This lets us meet financial record-keeping duties without holding names and addresses longer than necessary.
2. Retention schedule
| Data | Purpose | Business need | Retention |
|---|---|---|---|
| Child's name, grade, class, school | Identify and display artwork to the linked parent | Only while the child is active with valid consent | Until consent is withdrawn, the account closes, or 12 months after the school relationship ends — whichever comes first |
| Artwork images | Display and product fulfilment | Needed while consent is valid and to complete any open order | As above. Copies held for an in-progress order are deleted 90 days after fulfilment |
| Student email and login | Optional student access | Only while the student account is active | Deleted when the account closes or the school relationship ends |
| Teacher notes, parent messages, AI-generated text about a child | Communication about the child's work | Only while the child is active with valid consent | Same as the child's name |
| Parent or guardian contact details | Manage consent, support orders, communicate | Active relationship and record-keeping | 24 months after last activity |
| Consent records — what, when, how, which notice version | Evidence that consent was valid | Compliance evidence; we must be able to prove consent | Duration of the relationship plus 3 years after the child's data is deleted |
| Buyer identity on an order — name link, shipping street, city, postcode, phone, payment email | Fulfil and support the order | Only while the order may need support, dispute or return handling | 3 years from the order date, then automatically stripped |
| Order and financial record — amount, currency, date, status, payment reference, tax jurisdiction, fundraising attribution | Accounting, tax, fundraising reconciliation | Statutory financial record-keeping | 7 years, then deleted |
| Fundraising, payout and teacher reward records | Pay schools and teachers, tax reporting | Statutory financial record-keeping | 7 years |
| Security and access logs | Detect and respond to incidents | Security | 12 months |
| Email and campaign interaction data | Measure whether service messages worked | Operational | 24 months, then aggregated so no individual is identifiable |
| Teacher applications that are declined | Assess the application | Short-term record | 12 months, then deleted |
| Deletion records — what was removed, when, at whose request | Evidence a request was honoured | Compliance evidence, holds no personal data about the child | Retained; contains only counts and an opaque reference |
On the seven-year figure. US federal limitation periods are generally three years, extending to six where income is substantially understated, and Florida sales-tax records are generally three. Seven years is a conservative single period that covers those windows with margin. It is a policy choice rather than a statutory minimum, and it is paired with the three-year strip above so that personal data is not held for the full period.
3. What triggers deletion
We delete or anonymise a child's personal data when any of these happens:
- a parent withdraws consent or asks for deletion;
- a parent declines consent at the invitation stage — pending uploads for that child are deleted within 30 days;
- the account closes, or the school relationship ends;
- the retention period above expires;
- the data is no longer needed for the purpose it was collected for.
4. How deletion works
Requests can be made from the Privacy & data section of a parent's account, or by emailing info@artclass.me. We action them within 30 days and confirm by email when the deletion is complete.
When we delete a child's data we remove:
- the child's record, class enrolments and parent links;
- every artwork, including the image files themselves from our storage, not merely the database entry;
- AI-generated titles, descriptions and stories about the child;
- portfolio books and their PDF files;
- the child's own login account, where the school had enabled one;
- notifications and campaign records referring to the child.
We retain, in anonymised form, the financial record of any order — the amount, date, currency, payment reference and fundraising attribution — with the child's identity removed and no link back to them. This is the minimum needed to meet accounting and tax obligations.
We also keep a record that the deletion happened: who asked, when, and how many records were removed. That record contains no information about the child and is linked only by an opaque reference.
Where an order is still open. If a paid or cash-on-delivery order has not yet shipped, we will complete or cancel it before erasing the artwork it depends on, so that nobody is left waiting for a product we can no longer make.
Backups. Deleted data may persist in encrypted backups until those backups age out on our hosting provider's schedule. During that window backup data is access-restricted and is not used for any purpose.
5. What we cannot reach
We are honest about the limits of deletion. The following are outside our systems and are governed by the third party's own retention:
- Stripe retains payment records for the transactions it processed, as it must for financial and anti-fraud purposes.
- Resend retains logs of emails already sent, which may include a child's first name in an activity notification.
- OpenAI received artwork images for any AI suggestion already generated. It does not use them for training, but the request has already left our systems.
- Backups held by our hosting provider, until they age out.
- Search engines and third parties may hold cached copies of any page that was made public. We ask search engines not to index student pages, and public display requires your explicit consent — but once something has been public on the internet, we cannot guarantee its removal from every third party.
One further limitation, stated plainly: our deletion process removes notifications that reference a child by name or by a link to their artwork. A notification that referred to the child in some other wording could survive. We consider this a small residual and are working to make the match exact.
6. Responsibility
Jehona Lluka owns this policy, reviews it at least annually, and ensures deletions are carried out and logged.
