This policy explains (a) how long Medhaverse keeps the personal data we hold about Parents and Children, and (b) the safeguards we apply to prevent data loss, leakage, and unauthorised access. It complements our Privacy Policy.
Part A — Retention
1. Principle
We keep personal data only for as long as it is needed to provide the Service, to meet legal obligations, to resolve disputes, and to enforce our agreements. When that purpose ends, we either delete the data or irreversibly anonymise it.
2. Retention timelines
| Data category | Retention period |
|---|---|
| Parent account (name, email, profile, preferences) | For the life of the account. Deleted within 30 days of account deletion. |
| Child learner profile (display name, avatar, grade, medium) | For the life of the profile. Deleted within 30 days of profile deletion. |
| Learning activity (answers, mastery, time on task) | Up to 24 months after the last activity, then aggregated or deleted. |
| Chat transcripts with the AI tutor | Up to 12 months, unless the Parent deletes them sooner from the dashboard. |
| Support emails and grievance correspondence | Up to 36 months from last contact. |
| Server logs and security audit logs | 90 days for application logs; up to 12 months for security-relevant logs. |
| Database backups | Encrypted daily snapshots retained for 30 days, then rotated out. |
| Tax, invoicing, and billing records | As required by Indian tax law (currently 8 years). |
3. Deletion requests
Parents can delete their account or any child profile from the parent dashboard. Deletion is performed within 30 days across primary databases. Encrypted backups containing the deleted records are not actively scrubbed — instead, they roll off naturally within the backup-retention window described above. While they exist, those backups are accessible only for disaster-recovery and are not used for any other purpose.
4. Anonymisation
Where it is useful to retain learning patterns for content and model improvement, we may anonymise data — for example, by removing all direct identifiers and aggregating answers across many learners. Anonymised data is no longer personal data and is not covered by the retention periods above.
Part B — Prevention
5. Encryption
- All traffic between your device and our servers is encrypted using TLS 1.2 or higher.
- Databases and backups are encrypted at rest.
- Secrets (API keys, OAuth tokens) are stored in a secrets manager, never in source code.
6. Access control
- Production data is accessible only to a small set of authorised engineers, on a need-to-know basis.
- Multi-factor authentication is required for all admin access.
- Every access to production systems is logged and reviewable.
7. Network and infrastructure
- Servers are hosted with reputable providers in the EU and accessed via a Cloudflare tunnel; databases are not exposed to the public internet.
- Firewall rules limit traffic to required ports only.
- Operating-system and dependency updates are applied regularly.
8. Application security
- Input validation, output encoding, and parameterised queries to prevent injection attacks.
- Cross-site scripting and request-forgery protections enabled by default.
- Rate-limiting on authentication and AI endpoints to prevent abuse.
- Regular automated dependency scanning and prompt patching of known vulnerabilities.
9. Backups and disaster recovery
- Automated daily encrypted backups with a 30-day rolling window.
- Periodic restore tests to verify recoverability.
- Documented recovery procedures with a target recovery time of 24 hours and target recovery point of 24 hours.
10. Breach response
If we discover a personal-data breach, our team will (a) contain the incident immediately, (b) assess scope and impact, (c) notify affected Parents and the Data Protection Board of India where the DPDP Act requires it, and (d) document the incident and corrective actions for future prevention.
11. Vendor management
Third-party vendors that process personal data on our behalf (cloud hosting, email delivery, error monitoring, LLM providers, payment processors) are bound by data-protection agreements and are limited to the purposes we authorise. We review our vendor list periodically and remove anything we no longer need.
12. Training and policy review
Everyone with access to production data is briefed on data-protection responsibilities and on this policy. We review this policy at least once every 12 months, and whenever there is a material change to the Service.
13. Contact
Questions or a deletion request? Email hello@medhaverse.in.