GoNerds — Data Retention Policy
Last updated: 15 July 2026
1. Purpose
This policy explains how long GoNerds (operated by GoNerds Technologies) keeps personal data, and how we delete or anonymise it when it is no longer needed. It supports the storage‑limitation and data‑minimisation principles of India's Digital Personal Data Protection Act, 2023 ("DPDP Act"), the EU/UK GDPR, and applicable U.S. laws, and it complements our Privacy Policy.
2. Principles
- Keep only as long as needed. We retain personal data only for as long as necessary to fulfil the purposes for which it was collected, to provide the Service, to meet legal or regulatory obligations, to resolve disputes, and to enforce our agreements.
- Minimise children's data. We retain a Child's personal data only for as long as needed to provide the Service to that Child, and we delete it promptly when the Child profile or account is deleted, or sooner on a verified parental request.
- Delete or anonymise. When a retention period ends, we either securely delete the data or irreversibly anonymise it so it no longer identifies anyone.
- Document and review. We review retention periods periodically and adjust them as our processing or legal obligations change.
3. Retention schedule
The periods below are our standard defaults. They are maximums; we often delete sooner when data is no longer needed. Confirm each period with your legal/operational requirements before publishing.
| Data category | What it includes | Retention period | Trigger / basis |
|---|---|---|---|
| Account data | Email, hashed password, name, Google sign‑in identifier | Life of the account, then deleted within 90 days of account deletion |
Account deletion request |
| Learner profile data (incl. children) | Profile nickname, avatar, age band, learning track | Life of the profile/account, then deleted within 30 days of profile/account deletion (sooner on verified parental request for a minor) |
Profile/account deletion; parental request |
| Learning progress | Module progress, scores, preferences | With the related profile; deleted within 30 days of profile/account deletion |
Profile/account deletion |
| Authentication tokens | Access/refresh/session tokens | Until logout or token expiry; refreshed/rotated routinely | Logout / expiry |
| Feedback | Ratings, free‑text comments, module context | 24 months, or de‑identified/aggregated for product analytics thereafter |
Time‑based |
| Support communications | Emails and support tickets | 24 months after the matter is resolved |
Time‑based |
| Server & application logs | Diagnostic/error logs, timestamps | 90 days |
Time‑based (rolling) |
| Security & access logs | IP addresses, auth events, abuse signals | 180 days (longer if needed to investigate an incident) |
Security need |
| Backups | Encrypted system backups | Rolling 30‑day cycle, then overwritten |
Backup rotation |
| Advertising request signals | Non‑identifying contextual ad signals | We retain none; held only transiently by our ad partner under its own policy | N/A |
| Records required by law | Records we must keep (e.g., tax, legal, dispute) | For the period required by the applicable law, then deleted | Legal obligation |
4. Deletion on request
- A Grown‑up can delete a Child profile or the whole account in‑app, or by emailing privacy@gonerds.in. Verified deletion requests are honoured within the periods above (and without undue delay as required by the DPDP Act and GDPR).
- After deletion, residual copies may persist briefly in encrypted backups until those backups rotate out (see schedule), after which they are overwritten. We do not restore deleted personal data from backups except as needed to recover the system, after which the deletion is re‑applied.
5. Legal holds
If data is relevant to an actual or reasonably anticipated legal claim, investigation, or regulatory request, we may retain it beyond the standard period for as long as necessary for that purpose. The hold is lifted, and normal deletion resumes, once the matter concludes.
6. Anonymisation
Where we wish to keep insights from data without keeping personal data, we irreversibly anonymise it (for example, aggregating feedback so it cannot be linked to an individual). Anonymised data is not personal data and may be retained indefinitely for product improvement and reporting.
7. Security during retention and disposal
Throughout the retention period, data is protected by the safeguards described in our Privacy Policy. When data is disposed of, we use secure deletion methods designed to prevent recovery.
8. Changes to this policy
We may update this policy as our practices or legal obligations change. Material changes will be reflected by updating the "Last updated" date and, where appropriate, by notice.
Contact: privacy@gonerds.in · Grievance Officer (India): GoNerds, grievance@gonerds.in