Data Retention Policy

Last updated: 31 July 2026

This Policy sets out, in accordance with the storage-limitation principle of Article 5(1)(e) GDPR, exactly how long each category of personal data processed by SLP Command is retained, and what happens to it thereafter.

1. General principle

Except for the security audit trail described in §2, all personal data associated with your account is permanently deleted within 30 days of a verified account deletion request, in accordance with your right to erasure under Article 17 GDPR.

2. The security audit trail exception

3. Retention of subscription and billing records

SLP Command may retain certain minimal technical and transactional records, duly dissociated from your account, where necessary for the reconciliation of transactions, the prevention of fraud, the handling of claims, defence against liability, or compliance with an applicable legal obligation. These records are retained only for as long as necessary for those purposes.

Specifically: when you delete your account, your subscription/billing event records are not deleted outright. Instead, the identifiers capable of linking those records back to you within our systems — your account identifier and the RevenueCat subscriber identifier, alias and subscriber-attribute fields embedded in them — are irreversibly removed. The record that remains keeps only technical and financial fields relevant to the transaction itself (product purchased, price, currency, an App Store transaction identifier, and dates); it no longer contains your email address, learning content, or audio.

We describe this record as dissociated from your account rather than as fully "anonymised" in the strict sense: the App Store transaction identifier that remains is, in principle, capable of being linked back to a specific purchase by Apple or RevenueCat within their own systems, even though it can no longer be linked to you within SLP Command's own systems once your account no longer exists.

4. Your rights

You may request early deletion, access, or portability of any data described in this Policy at any time by contacting privacy@slpcommand.com, subject to the security audit trail exception described in §2, which cannot be shortened on request because its purpose is specifically to survive account deletion for security-investigation purposes.

5. Contact

privacy@slpcommand.com