Data Retention Policy
Last updated: 31 July 2026
This Policy sets out, in accordance with the storage-limitation principle of Article 5(1)(e) GDPR, exactly how long each category of personal data processed by SLP Command is retained, and what happens to it thereafter.
| Data category | Retention period | Trigger for deletion |
|---|---|---|
| Account credentials (email, password hash) | Life of account | Deleted within 30 days of account deletion |
| Written responses (Writing) | Life of account | Deleted within 30 days of account deletion |
| Speaking audio recordings | Until deleted by user, or life of account | Individually deletable at any time; permanently deleted within 30 days of account deletion |
| AI-generated transcripts | Life of account | Deleted within 30 days of account deletion |
| Scores, estimated levels, exercise history | Life of account | Deleted within 30 days of account deletion |
| Adaptive Coach / Intelligence Dashboard data | Life of account | Deleted within 30 days of account deletion |
| Support requests ("Report a Problem") | 12 months, or life of account, whichever is sooner | Automatically purged after 12 months; deleted immediately on account deletion where already resolved |
| Product usage analytics (pseudonymous) | Up to 12 months | Automatically aged out; not linked back to your account identity after deletion |
| Crash / error diagnostics | 30–90 days | Automatically purged by our diagnostics provider |
| Security audit trail | 12 months from the event, irrespective of account deletion | Automatically and permanently purged 12 months after creation |
1. General principle
Except for the security audit trail described in §2, all personal data associated with your account is permanently deleted within 30 days of a verified account deletion request, in accordance with your right to erasure under Article 17 GDPR.
2. The security audit trail exception
- A limited set of security-relevant events (account login, account creation, account deletion, administrative actions performed on your account) is retained for 12 months from the date of the event, even after you delete your account.
- This exception exists on the basis of our legitimate interest (Article 6.1.f GDPR) in investigating fraud, unauthorised access, and security incidents that may only come to light after an account has already been deleted (for example, a compromised account deleted by an attacker to conceal unauthorised access).
- This log entry contains only: an event type, a pseudonymous user identifier, a hashed (non-reversible) IP address, and a timestamp. It never contains your email address, written content, audio, or transcripts.
- Once your account is deleted, the pseudonymous identifier retained in this log no longer resolves to any identifiable individual within our systems — it cannot, on its own, be used to re-identify you.
- Every entry in the security audit trail is automatically and permanently purged exactly 12 months after its creation, with no exception and no manual extension process.
3. Retention of subscription and billing records
SLP Command may retain certain minimal technical and transactional records, duly dissociated from your account, where necessary for the reconciliation of transactions, the prevention of fraud, the handling of claims, defence against liability, or compliance with an applicable legal obligation. These records are retained only for as long as necessary for those purposes.
Specifically: when you delete your account, your subscription/billing event records are not deleted outright. Instead, the identifiers capable of linking those records back to you within our systems — your account identifier and the RevenueCat subscriber identifier, alias and subscriber-attribute fields embedded in them — are irreversibly removed. The record that remains keeps only technical and financial fields relevant to the transaction itself (product purchased, price, currency, an App Store transaction identifier, and dates); it no longer contains your email address, learning content, or audio.
We describe this record as dissociated from your account rather than as fully "anonymised" in the strict sense: the App Store transaction identifier that remains is, in principle, capable of being linked back to a specific purchase by Apple or RevenueCat within their own systems, even though it can no longer be linked to you within SLP Command's own systems once your account no longer exists.
4. Your rights
You may request early deletion, access, or portability of any data described in this Policy at any time by contacting privacy@slpcommand.com, subject to the security audit trail exception described in §2, which cannot be shortened on request because its purpose is specifically to survive account deletion for security-investigation purposes.