Data Retention, Deletion & Security
Effective October 2, 2026. Written for parents, in plain language.
How long we keep information
| Information | How long we keep it |
|---|---|
| Grown-up account (email, hashed password, consent record) | While the account is open. Deleted within 30 days after you ask us to close it. |
| Reader profile and learning progress | While the account is open, so your reader can keep going. Deleted with the account, or sooner if you ask. |
| Accounts that were never confirmed | Sign-ups whose email address was never confirmed may be deleted after 30 days. |
| Sign-in sessions | Up to 7 days, or until you sign out. |
| Sign-in and sign-up attempt counters | Rolling 15-minute windows, stored only in scrambled form. |
| Membership, payment and scholarship order records | As long as tax and accounting laws and Step Up For Students’ program rules require. |
| Emails and support conversations | As long as needed to help you, then up to 2 years after our last conversation, unless you ask us to delete them sooner. |
| Website server logs | Kept by our hosting provider for a short period under its own schedule. |
Asking us to delete your information
Email hello@readingadventureworlds.com with the subject “Deletion request” from your account email. We may ask a simple question to confirm it’s really you. We will delete your account and your reader’s information within 30 days and confirm by email.
If you have an active card membership, please cancel it first (or ask us to) so you aren’t charged again. We may keep information we are legally required to keep (such as tax and scholarship order records), information needed to resolve a dispute or prevent fraud, and a note that you asked us not to contact you. Copies in backups are removed as those backups are replaced.
How we protect information
- We collect very little. The best protection is not holding data in the first place.
- Passwords are never stored. We keep only a salted, scrambled version that can’t be turned back into your password.
- Encrypted connections. The website and app are served only over HTTPS, with strict browser security settings.
- Secure sessions. The sign-in cookie can’t be read by page scripts, and sensitive grown-up actions ask for your password again.
- Abuse limits. Repeated sign-in and sign-up attempts are slowed down.
- Limited access and trusted providers. Only people who need customer information to serve you can see it, and we use established providers for hosting, database, email and payments. We never see or store full card numbers.
No system is perfectly secure. If a security incident affects your personal information, we will notify you and the appropriate authorities as required by law, including Florida’s Information Protection Act.
Your part
Use a strong password that you don’t use anywhere else, keep your Step Up (EMA) password private, and sign out on shared devices. We will never ask for your passwords or full card numbers by email.
