Control
Children's personal information copied into AI stores is kept without a retention limit or deletion
Personal information collected from a child (chat transcripts, voice recordings, photos, embeddings, model inputs and outputs, training sets) is kept only as long as reasonably necessary for the purpose it was collected for, under a written retention policy that states the purposes, the business need and a deletion timeframe, and is then deleted from every store, including AI stores.
Informational data, not legal advice. Summaries and rules have not been reviewed by a lawyer: always verify official law text for decisions. A suggested guard is intended to address each rule; adding it is not a statement of compliance to that law.
Reach
Law in force in United States (federal) (US).
Trust and provenance
How far the rules this guard addresses have been checked. Each rule links to its provision, with its citation, official text and its own panel.
- This control
- Audit-grade: meets all 3 checks of the TwinEthos audit standard that apply to it.
- Lanes
- Binding law — in force 1
- Verification
- Sources last verified 4 Oct 2026; each provision states how.
- Data release
- Data release 2026.10.04.3, data as of 4 Oct 2026, schema 0.3.10.
- Legal review
- None of the 1 rule has been reviewed by a lawyer; no TwinEthos rule has been legally reviewed yet. Treat each as research to check against the official text; it is not legal advice. Open questions for counsel on them: 1.
- Audit standard
- 1 of 1 rule audit-grade. The audit standard is TwinEthos's own quality bar for provenance, dates, applicability, detectors, fixtures, remediation and licences; it is not a legal review.
- Detectors
- 1 detector, all experimental: written from the rule's text and not yet measured for precision on real code, so treat a hit as a lead to verify. Each provision lists its detectors' known limits.
The guard to add
Give every store of children's data in an AI feature (transcripts, audio, embeddings, training sets) a retention period from a written policy and delete on schedule.
Writes of children's transcripts, audio, images and embeddings set an expiry (TTL, object lifecycle rule or expires_at) taken from the retention policy; a scheduled job deletes expired records from the database, the vector index, object storage and provider-stored files; the written policy (purposes, business need, deletion timeframe) is in the children's privacy notice.
Where it goes: 1 application source code, 6 API calls and integrations, 2 data models.
What reviewers look for: an expiry or lifecycle setting on every write of child audio, transcripts, images or embeddings; a deletion job that reaches vector stores and provider files; a retention section in the children's privacy notice.
Example (Python + Redis + vector store), before:
transcript = client.audio.transcriptions.create(model='whisper-1', file=audio)
db.child_messages.insert({'child_id': child.id, 'text': transcript.text})
index.upsert([(msg_id, embed(transcript.text), {'child_id': child.id})])After:
RETENTION = timedelta(days=CHILD_DATA_RETENTION_DAYS) # from the written retention policy
transcript = client.audio.transcriptions.create(model='whisper-1', file=audio)
db.child_messages.insert({'child_id': child.id, 'text': transcript.text, 'expires_at': now() + RETENTION})
index.upsert([(msg_id, embed(transcript.text), {'child_id': child.id, 'expires_at': (now() + RETENTION).isoformat()})])
# purge_expired_child_data() runs daily over db, index and provider filesEngineering guidance, not legal advice. Each provision below may add its own details (a cadence, a deadline, a required notice element): open it for those.
Every rule this guard addresses
Binding law — in force (1)
- United States (federal) (US)
- Keep children's data in AI stores only as long as reasonably necessary, under a written retention policy (COPPA 2025) 16 CFR 312.10 · AI-adjacent law
Informational data, not legal advice. Summaries are TwinEthos's own words and rules have not been reviewed by a lawyer: check the official text before relying on any of it. A guard addresses an item; adding it is not a statement that your code meets any law.