Data Retention Policy
Appy + Yaar · Last updated 24 April 2026
| Data | Purpose | Retention |
|---|---|---|
| Email address + hashed password | Account sign-in and password reset | For the life of your account, then 30 days after closure |
| Profile (ethnicity, religion, generation, UK region, language, goals) | Tailor content and research (if opted in) | For the life of your account, then deleted on closure |
| Pathway answers | Save progress, resume, generate GP Summary | For the life of your account, then deleted on closure |
| GP Summaries (generated) | Let you re-print past summaries | For the life of your account, then deleted on closure |
| Bookmarks, reflections, tracker entries | Personal record | For the life of your account, then deleted on closure |
| Chatbot messages (session only) | Generate a response | Not stored on our servers beyond the current session |
| Usage events (article read, pathway completed) | Understand which features are used | User-identifiable for 12 months, then anonymised and kept for aggregate trends |
| Consent records | Prove what you agreed to and when | 7 years (regulatory requirement under UK GDPR / Art. 7(1)) |
| Research data (if you opt in) | De-identified contribution to studies | Indefinitely in de-identified form; identifiable link destroyed 6 months after study completion |
| Account closure audit log | Handle reopening requests and legal queries | 30 days after account closure, then deleted |
How deletion works
When you delete your account, we immediately remove your access to the service. Your data is flagged for deletion, and the actual database removal happens within 30 days. Backups are rotated out on a 35-day cycle, so a full deletion cycle completes within 65 days.
If you have contributed to research with explicit consent, the de-identified data already in a research dataset cannot be retrospectively withdrawn from that dataset, this is standard research practice and is disclosed at consent. Any future use of your identifiable data stops immediately.
Backups
We back up our database daily and keep backups for 35 days. Backups are encrypted at rest. Access to backups is restricted and logged. Restoration from backup only happens in the case of a technical incident.
Where your data lives
Supabase (our database) hosts your data in EU (Ireland) data centres. Vercel (our hosting) operates a global edge network but we have configured it to run functions in the UK region (London). Anthropic (our chatbot API provider) processes messages in the US under their data processing terms.
Changes
We will update this policy if retention periods change. Material changes will be notified in-app and by email.
© Her Holistic Health Ltd 2026. This policy is reviewed regularly and will be updated if our retention practices change.