Lesson recordings · 90 days
Auto-purge 90 days after lesson date unless explicitly pinned by parent or admin (max pin: 12 months). Pinned recordings still purge at 12 months from pin date.
Homework submissions + grades · school year + 90 days
Retained for the full school year of submission plus 90 days. Aggregate (de-identified) gradebook metrics retained 7 years for accreditation.
Engagement events · 18 months
Per-event rows (vocab_gain, pron_attempt_in_tolerance, etc.) retained 18 months. Aggregated per-cohort + per-learner metrics derived from these events retained 7 years; raw events purged at 18 months.
Parent-tutor messages · school year + 30 days
Retained for the school year of sending plus 30 days. After purge, only metadata (count, participants, dates) retained for audit purposes.
IEP records · school year + 7 years (per IDEA)
IEPs and 504 plans retained per IDEA requirements (typically 7 years post-graduation; per-state variations apply). Stored encrypted at rest; access logged.
Stripe payment metadata · 7 years (tax law)
Payment + payout metadata retained 7 years per US tax retention requirements. Full card data never stored — Stripe holds it.
Audit logs · 1 year minimum
Authentication, role-change, and admin-action logs retained 12 months minimum. Enterprise tenants can extend to 7 years per contract.
Contract termination
On contract termination: PII purge initiated within 7 days, completed within 30 days. Aggregate de-identified metrics retained. Backups retained per backup-rotation schedule (then purged).
Right to be forgotten (GDPR Art 17)
Per-data-subject deletion request executed within 30 days. Confirmation email sent on completion. Aggregated metrics that have lost the identifier are retained; everything that can be traced back to the subject is deleted.