Skip to main content

Children's Data Retention Policy

Last Updated: August 2, 2026

This policy is publicly available at https://olyadmit.org/retention and is linked from our Privacy Policy.

This Data Retention Policy outlines our practices regarding the retention and deletion of personal information, specifically concerning users under the age of 18, in compliance with the Children's Online Privacy Protection Act (COPPA) Section 312.10. Our platform does not permit registration by users under the age of 13. This policy applies to the personal information of all users, with particular attention to users aged 13–17.

1. Core Retention Principle

We do not retain children's personal information indefinitely. We retain personal information only as long as is reasonably necessary to fulfill the specific educational and operational purposes for which it was collected, or to comply with our legal and safety obligations. Once data is no longer necessary for these purposes, it is securely deleted or irreversibly anonymized.

2. Data Categories, Purposes, and Timeframes

The following schedule details the specific data categories we collect, the purpose for collection, and the precise timeframe for which it is retained.

Age Verification & Identity Data

Purpose for Collection: COPPA compliance and under-13 screening.

Mandatory Registration & Onboarding: During registration, we collect the month and year of birth client-side for age verification. For age calculation purposes, the specific day is strictly defaulted to the 1st of the month. If you fail the initial age gate (the month/year input), device fingerprinting applies a technical block to the device to prevent repeat attempts. During onboarding, we collect first name and last initial.

Didit Verification (Mandatory): When platform systems detect behavioral indicators suggesting a user may be under 13, users are redirected to Didit's hosted verification page. Didit processes the facial image and government ID entirely on their infrastructure. OlyAdmit receives only limited verification data—verification status, document type, first name, last name, date of birth, age, front camera face match score, and any warnings. OlyAdmit stores only the verification result (verified/not verified), method, and timestamp. We never receive or store biometric media, document images, government ID numbers, or physical addresses.

Voluntary Age Verification: We offer an opt-in, non-punitive verification option from the profile page. For users who aren't flagged, they can voluntarily verify with no retry limits, no permanent blocking, and no account deletion on failure.

Retention Period: Immediate discard of birth month/year data for users determined to be under 13. Device fingerprinting data is retained for exactly 72 hours to enforce the repeat-attempt block, after which it expires. For mandatory verification: If an account is suspended pending age verification and the process remains unresolved or incomplete, the account and all associated data are automatically deleted after exactly 72 hours (3 days). For users aged 13 and older who successfully verify, the stored verification result, method, and timestamp are retained as part of the user's account profile, subject to the standard deletion cycle. For failed voluntary verification attempts, the verification attempt result is retained as part of the user's account profile, but does not result in account deletion or permanent blocking.

Account Data (Email address, authentication records, OAuth provider links)

Purpose for Collection: Account access, user communication, and platform provision. OlyAdmit is entirely passwordless and does not store user passwords.

Retention Period: Duration of account (see Section 3).

Parent Email Data

Purpose for Collection: Utilizing the parent_emails table to send authorized updates and parent activity reports via our transactional email provider.

Retention Period: Duration of the student's account, or immediately upon the parent opting out/unsubscribing.

Educational & College Planning Data

Purpose for Collection: AI admissions guidance and algorithmic scholarship matching. This includes GPA, test scores (ACT, SAT), coursework, interests, activities, career goals, college visits, recommendation letters, application tasks and subtasks, college application tracking, and saved scholarships.

Retention Period: Duration of account (see Section 3).

Counselor-Related Data (Opt-In)

Purpose for Collection: B2B integration to allow counselor collaboration. This includes counselor_student_relationships, essay comments, tracked essay versions, comment mentions, and essay analytics.

Retention Period: Duration of the account, or until the student actively revokes sharing access. Note: Data exported by the counselor prior to revocation cannot be retrieved by OlyAdmit.

System-Generated Data

Purpose for Collection: Providing personalized scholarship recommendations, milestones, and timestamps.

Retention Period: Duration of account (see Section 3).

Essay Content (Drafts, AI feedback, Athena Editor)

Purpose for Collection: Providing AI-assisted writing review and admissions feedback. Our Athena Essay Editor evaluates all essay types (Common App, college supplementary, scholarship applications).

Retention Period: Duration of account. All essay drafts and feedback are processed through Vercel AI Gateway with strict Zero Data Retention (ZDR)—enforced by routing exclusively to models that natively guarantee ZDR—and are immediately hard-deleted from our databases upon account deletion.

Chat History

Purpose for Collection: Providing contextual, unified cross-page AI assistance.

Retention Period: A 5-message rolling window is maintained in the user's local browser sessionStorage (cleared immediately upon close/sign-out). Before transmission to Vercel AI Gateway, sensitive-category messages are automatically filtered out. The remaining window is transmitted strictly under our Zero Data Retention (ZDR) policy by utilizing specific models that guarantee non-retention.

Demographic & Financial Data (Income ranges, location, ethnicity, family background, residency)

Purpose for Collection: Algorithmic scholarship matching and specific program eligibility. Highly sensitive demographic categories (such as ethnicity, family background, and residency) are conditionally transmitted to Vercel AI Gateway only if relevant to the user's specific prompt to provide highly personalized guidance. (Note: First name, last initial, school name, and birthday are never transmitted to our AI models).

Retention Period: Duration of account (see Section 3).

Usage Data (App interactions, session info, activities, feedback)

Purpose for Collection: Platform improvement, debugging, security monitoring, recording user feedback, and managing notifications/preferences.

Retention Period: Retained on a rolling 12-month basis, then securely deleted.

Content Moderation Logs

Purpose for Collection: Storing safety events in the moderation_deflection_logs table for crisis content detection, deflection, and resource delivery.

Retention Period: Retained strictly for safety compliance on a rolling 12-month basis, then securely deleted.

Audit Logs (Metadata-only system triggers)

Purpose for Collection: General system auditing and integrity.

Retention Period: Retained on a rolling 12-month basis, then securely deleted.

Deleted Accounts Audit Records

Purpose for Collection: GDPR and COPPA compliance documentation utilizing the deleted_accounts_audit table.

Retention Period: Retained for 12 months on a rolling basis after account deletion to prove compliance, after which it is securely deleted.

3. The Standard Deletion Cycle

When an account is deleted — whether initiated by the user, triggered automatically upon failed mandatory age verification, or triggered by the 72-hour auto-deletion of an unresolved suspended account — the following technical lifecycle applies to ensure data is thoroughly and securely eradicated from our systems:

Primary Database Purge:

Upon triggering of the deletion, all active personal data, account profiles, educational data, system-generated data, demographic data, and highly sensitive user content (including user-generated essay drafts) are immediately and permanently hard-deleted from our active primary production databases.

90-Day Backup Overwrite:

Following the primary database purge, data may remain in routine encrypted, offline disaster-recovery backups for a maximum of 90 days, after which those backups are systematically overwritten and the data is permanently destroyed.

4. Sub-Processor and Independent Controller Retention

We utilize third-party sub-processors to process user data and operate the platform. We contractually prohibit any sub-processor from retaining our users' data for the purpose of training their public AI models. Our active sub-processors, independent controllers, and their specific retention commitments are as follows:

Vercel AI Gateway (Sub-Processor): Zero Data Retention (ZDR) is strictly enforced by model. We exclusively select and route requests to specific models (llama-3.1-8b for Atlas endpoints and gpt-oss-120b for Athena editing functions) that natively guarantee ZDR. All inference is routed exclusively to AWS Bedrock via single-provider routing using Vercel-managed API keys. AWS Bedrock functions as Vercel's sub-processor under the Vercel DPA and is contractually prohibited from retaining prompts, storing outputs, or using data for model training. OlyAdmit has no direct contractual relationship with AWS Bedrock. No data is stored, and no data is used for model training.

Resend (Sub-Processor): Utilized for transactional emails (welcome emails, counselor invitations, parent activity reports). Data is securely deleted within 90 days post-account termination in accordance with its DPA.

Supabase (Sub-Processor): Retained for the duration of the account (database host).

Didit (Sub-Processor): Governed by standard DPA. Biometric media is processed on Didit's infrastructure and is never transmitted to or retained by OlyAdmit; verification result data is retained per DPA terms.

Stripe (Independent Controller): Utilized for payment processing for counselor subscriptions. Stripe operates as an independent controller for payment card data under PCI DSS, further governed by a standard DPA.

Google OAuth & Discord OAuth (Independent Controllers): Process authentication data as independent controllers under their own respective privacy policies. No DPA is required for this controller-to-controller transfer.

Sentry (Sub-Processor): 90-day maximum retention. All personal data is programmatically stripped before transmission via beforeSend hooks.

Vercel (Sub-Processor): Request-level data and platform analytics retained per standard DPA.

Updated sub-processor information is maintained in our Privacy Policy and Written Information Security Program (WISP).