Skip to main content
← All legal documents

Data Retention and Deletion Policy

Effective July 24, 2026

Policy Owner: Privacy Team
Approved By: SchoolToolz / Proctorly
Effective Date: July 24, 2026
Version: 1.0
Review Cycle: At least annually
Last Reviewed: July 24, 2026

1. Purpose

This Data Retention and Secure Deletion Policy ("Policy") establishes the requirements of SchoolToolz, operating Proctorly ("Provider," "Company," "we," "us," or "our") for:

  1. retaining information only for legitimate business, contractual, security, and legal purposes;
  2. establishing documented retention periods;
  3. responding to deletion requests;
  4. securely deleting or anonymizing information when it is no longer required;
  5. managing information stored in backups, archives, logs, and third-party systems; and
  6. documenting exceptions, including litigation holds and legal retention obligations.

This Policy is intended to reduce unnecessary data storage while supporting the operation, security, reliability, and legal compliance of the Proctorly platform and related services.

2. Scope

This Policy applies to information created, received, maintained, transmitted, or otherwise processed by Provider in connection with:

  1. the Services;
  2. Provider websites and applications;
  3. customer and user accounts;
  4. customer support;
  5. billing and financial administration;
  6. security and system monitoring;
  7. Subprocessors acting on Provider's behalf; and
  8. Provider’s vendors, service providers, and subprocessors.

This Policy applies to information stored in:

  • production systems;
  • databases;
  • file-storage systems;
  • email and communication systems;
  • customer-support systems;
  • analytics platforms;
  • development and testing environments;
  • archives;
  • backups; and
  • systems operated by third parties on Provider’s behalf.

3. Definitions

3.1 Customer Data

"Customer Data" means data, information, files, records, or content submitted to, stored in, transmitted through, or otherwise processed by the Services on behalf of a customer.

3.2 Personal Data

"Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identifiable individual or household.

3.3 Production Data

"Production Data" means information maintained in live systems used to provide the Services to customers and users.

3.4 Deletion

"Deletion" means rendering information inaccessible or removing it from active systems so that it is no longer available for ordinary business use.

3.5 Anonymization

"Anonymization" means processing information so that it can no longer reasonably be associated with an identifiable customer, user, or individual.

3.6 Backup

"Backup" means a copy of information maintained primarily for disaster recovery, operational resilience, system restoration, or business continuity.

"Legal Hold" means an instruction to preserve information that might otherwise be deleted because it may be relevant to litigation, an investigation, an audit, a regulatory matter, or another legal obligation.

3.8 Subprocessor

"Subprocessor" means a third party engaged by Provider to process Customer Data on Provider’s behalf in connection with the Services.

4. Policy Principles

Provider will manage information according to the following principles.

4.1 Purpose Limitation

Information will be retained only when Provider has a legitimate business, contractual, operational, security, or legal reason to retain it.

4.2 Data Minimization

Provider will seek to collect and retain only the information reasonably necessary for the identified purpose.

4.3 Defined Retention Periods

Each material category of information will have:

  1. an identified business owner;
  2. a stated retention purpose;
  3. a retention period or deletion trigger;
  4. an approved deletion method; and
  5. any applicable legal or contractual exception.

4.4 Secure Storage

Information will remain subject to Provider’s applicable security safeguards throughout its retention period.

4.5 Timely Deletion

Information will be deleted, anonymized, aggregated, or rendered inaccessible after the applicable retention period expires, unless continued retention is authorized under this Policy.

4.6 Consistency

Retention and deletion requirements will be applied consistently across Provider-controlled systems, subject to technical limitations and documented exceptions.

4.7 No Indefinite Retention by Default

Information will not be retained indefinitely merely because storage is available or deletion is inconvenient.

5. Determining Retention Periods

Provider will consider the following factors when establishing a retention period:

  1. the purpose for which the information was collected;
  2. whether the information remains necessary to provide the Services;
  3. customer instructions and contractual commitments;
  4. applicable legal and regulatory requirements;
  5. tax, accounting, insurance, and audit obligations;
  6. limitation periods for potential legal claims;
  7. fraud-prevention and information-security needs;
  8. the sensitivity and volume of the information;
  9. the risk of harm from unauthorized access;
  10. whether the information can be anonymized;
  11. technical deletion capabilities;
  12. backup and disaster-recovery requirements; and
  13. whether a Legal Hold applies.

6. Data Classification

Information covered by this Policy should be classified according to Provider’s applicable data-classification standard.

ClassificationDescription
PublicInformation approved for public disclosure
InternalNon-public business information intended for internal use
ConfidentialSensitive business, customer, employee, or contractual information
RestrictedHighly sensitive or regulated information requiring enhanced protection

7. Retention Schedule

Provider will maintain a retention schedule identifying the approved retention period for material categories of information.

The schedule in Schedule 1 may be adapted to Provider’s actual systems, contractual obligations, and legal requirements.

A retention period may be based on:

  1. a fixed period;
  2. the duration of an active customer relationship;
  3. account closure;
  4. contract expiration or termination;
  5. completion of a transaction;
  6. resolution of a support request;
  7. expiration of a legal requirement;
  8. the date of an individual’s deletion request; or
  9. another documented business event.

8. Active Customer Accounts

While a customer account remains active, Provider may retain Customer Data as necessary to:

  1. provide the Services;
  2. maintain customer configurations;
  3. authenticate users;
  4. process transactions;
  5. provide customer support;
  6. maintain security and prevent fraud;
  7. generate customer-requested reports;
  8. comply with the Agreement; and
  9. comply with applicable law.

9. Account Termination and Expiration

Following expiration, termination, or cancellation of a customer’s Services:

  1. Provider may disable access to the customer account after any applicable cancellation grace period;
  2. Customer Data will remain available for export for 30 days after the applicable termination or cancellation date, unless the Agreement states otherwise;
  3. Customer Data will be deleted or rendered inaccessible from active production systems within 90 days after the applicable termination or cancellation date, which period includes the 30-day export window and any applicable 30-day cancellation grace period;
  4. residual copies may remain in backups until the applicable backup-rotation period expires;
  5. billing, transaction, contractual, security, and compliance records may be retained separately under the applicable retention schedule; and
  6. information subject to a Legal Hold or another legal obligation will be preserved until the hold or obligation ends.

10. Customer-Requested Deletion

Customers may request deletion of Customer Data by:

  1. using available deletion controls within the Services; or
  2. submitting a request to privacy@proctorly.co.

Provider may require reasonable information to:

  1. verify the request;
  2. confirm the requester’s authority;
  3. identify the relevant account or information;
  4. protect against fraudulent or unauthorized deletion; and
  5. determine whether an exception applies.

Provider will process verified deletion requests within the period required by the Agreement or applicable law.

Where Provider acts as a processor or service provider on behalf of a customer, Provider may direct an individual to submit the request to the applicable customer acting as the controller or business.

11. Individual Privacy Requests

Provider will maintain procedures for responding to valid requests from individuals to delete Personal Data where required by applicable law.

Provider may deny, limit, or delay a deletion request where continued retention is reasonably necessary to:

  1. complete a transaction requested by the individual;
  2. provide a product or service requested by the individual;
  3. maintain account security;
  4. detect and prevent fraud or unlawful activity;
  5. debug or repair errors;
  6. comply with a legal obligation;
  7. establish, exercise, or defend legal claims;
  8. preserve freedom of expression or another protected right;
  9. protect the rights and safety of Provider, its customers, or others;
  10. maintain information subject to a Legal Hold; or
  11. satisfy another legally recognized exception.

12. Customer Data in Production Systems

Deletion from production systems may occur through:

  1. automated retention jobs;
  2. application deletion functions;
  3. database deletion procedures;
  4. removal of storage objects;
  5. expiration policies;
  6. anonymization;
  7. cryptographic erasure; or
  8. authorized administrative procedures.

13. Backup Retention and Deletion

Provider may maintain encrypted backups for disaster recovery, operational resilience, and business continuity.

Unless otherwise stated in an applicable agreement:

  1. backups will be retained on a rolling basis for 30 days, based on the cloud provider’s current Supabase backup plan;
  2. point-in-time recovery is limited to 7 days, based on the cloud provider’s current Supabase plan;
  3. deleted information may remain in backups until the backup containing the information expires or is overwritten;
  4. backups will not ordinarily be modified solely to delete individual records;
  5. information retained in backups will remain protected under Provider’s security program;
  6. access to backups will be restricted;
  7. backups will not be used for ordinary business processing;
  8. backups will be restored only when reasonably necessary for disaster recovery, security, testing, or continuity purposes; and
  9. if deleted information is restored, Provider will take reasonable steps to reapply the applicable deletion instruction.

14. Logs and Security Records

Provider may retain security, audit, application, access, and diagnostic logs for purposes including:

  1. detecting and investigating security events;
  2. preventing fraud and abuse;
  3. troubleshooting errors;
  4. monitoring availability and performance;
  5. maintaining an audit trail;
  6. complying with legal requirements; and
  7. enforcing Provider’s agreements.

Sensitive values such as passwords, authentication secrets, payment-card security codes, and private cryptographic keys must not knowingly be written to logs.

15. Development and Testing Environments

Provider will avoid using Production Data in development or testing environments unless reasonably necessary and appropriately authorized.

Where Production Data is used:

  1. access will be limited;
  2. the environment will be appropriately secured;
  3. the information should be minimized or masked where practicable;
  4. the purpose and duration of use should be documented; and
  5. the information will be deleted when the testing purpose ends.

16. Customer Support Information

Support tickets, chat messages, emails, call records, attachments, and troubleshooting materials may be retained to:

  1. resolve customer issues;
  2. maintain service history;
  3. train authorized support personnel;
  4. improve support quality;
  5. prevent fraud and abuse; and
  6. establish a record of customer instructions.

Provider does not store support messages in Proctorly’s database; messages are forwarded directly to support@proctorly.co via Resend. Copies may remain in Resend and Provider’s email/support systems for up to 30 days after the support request is resolved, and are then deleted or overwritten according to the provider’s retention schedule and normal backup rotation.

17. Financial and Transaction Records

Provider may retain invoices, payment confirmations, refunds, tax records, accounting entries, and related transaction information for the period necessary to comply with:

  1. tax requirements;
  2. accounting requirements;
  3. financial audits;
  4. fraud-prevention obligations;
  5. chargeback or dispute procedures; and
  6. applicable recordkeeping laws.

Provider does not store complete payment-card details; payment processing is performed by Stripe.

18. Marketing and Sales Information

Provider may retain prospect and marketing information while:

  1. a business relationship remains active;
  2. the individual continues to engage with Provider;
  3. Provider has a valid business or legal basis to maintain the information; or
  4. retention is necessary to honor an unsubscribe, objection, or suppression request.

Suppression records may be retained after other marketing information is deleted to ensure that Provider continues to honor opt-out requests.

19. Cookies, Analytics, and Device Information

Cookie identifiers, analytics records, IP addresses, device information, and usage data will be retained according to:

  1. the purpose of the applicable cookie or technology;
  2. Provider’s published Privacy Policy and cookie disclosures;
  3. the settings of the analytics provider;
  4. customer configuration;
  5. user consent or preferences; and
  6. applicable law.

Student-facing routes (/t/*) are excluded from analytics tracking. Only teacher-facing usage is tracked.

20. Artificial Intelligence Data

Where Provider uses artificial intelligence systems in connection with the Services, Provider will establish and document retention rules for:

  1. user prompts;
  2. uploaded content;
  3. model inputs;
  4. generated outputs;
  5. evaluation data;
  6. safety-monitoring data;
  7. model-performance logs; and
  8. data transmitted to an artificial intelligence Subprocessor.

Unless a longer period is required by law, support, safety, or debugging needs:

  1. prompts, model inputs, and uploaded content will be retained for no longer than 30 days after processing;
  2. generated outputs that are stored as part of a customer record will be retained under the retention period that applies to that record (e.g., the applicable session, test, or report retention period);
  3. other generated outputs will be retained for no longer than 30 days after delivery;
  4. evaluation and safety-monitoring data will be retained for no longer than 90 days;
  5. model-performance logs will be retained for no longer than 90 days;
  6. vendor copies will be retained only as long as required by the AI Subprocessor or eliminated through zero-data-retention or equivalent settings where available.

Customer Data will not be retained for the purpose of training a publicly available or generally shared artificial intelligence model.

Provider will configure third-party artificial intelligence services to minimize or disable vendor retention and training use where commercially and technically available.

21. Children’s and Student Data

Provider will retain children’s or student data only:

  1. as directed by the applicable school, district, parent, guardian, or other authorized customer;
  2. for the period necessary to provide the Services;
  3. as required by the applicable contract; or
  4. as required by law.

Upon termination of the applicable school or customer agreement, Provider will delete or return the relevant student data according to:

  1. the customer’s documented instructions;
  2. the applicable student-data agreement;
  3. the applicable Data Processing Addendum; and
  4. applicable education and children’s privacy laws.

Student data will not be retained for unrelated advertising or commercial profiling purposes.

22. Anonymized and Aggregated Information

Provider may retain anonymized or aggregated information for longer periods, including indefinitely, where the information:

  1. cannot reasonably be associated with a customer or identifiable individual;
  2. is not maintained with information capable of reversing the anonymization;
  3. is subject to reasonable controls against re-identification; and
  4. is used for legitimate purposes such as service analytics, research, security, forecasting, or product improvement.

When Provider reasonably anticipates litigation, receives a subpoena, becomes subject to an investigation, or otherwise has a legal duty to preserve information, Provider may suspend ordinary deletion procedures for relevant information.

A Legal Hold notice should identify:

  1. the information to be preserved;
  2. the systems or custodians involved;
  3. the reason for the hold;
  4. the effective date;
  5. the responsible legal or compliance contact; and
  6. the conditions for releasing the hold.

24. Subprocessors and Third-Party Systems

Provider will take reasonable steps to ensure that Subprocessors processing Customer Data:

  1. retain Customer Data only as necessary to provide their contracted services;
  2. delete or return Customer Data following termination of their services;
  3. maintain appropriate security measures during retention;
  4. comply with Provider’s documented deletion instructions;
  5. address information remaining in backups; and
  6. notify Provider of material limitations affecting deletion.

25. Secure Deletion Methods

Provider will select a deletion or sanitization method appropriate to:

  1. the type of storage medium;
  2. the sensitivity of the information;
  3. the risk of recovery;
  4. the intended future use of the media;
  5. contractual requirements; and
  6. applicable legal or industry standards.

Approved methods may include:

  1. logical deletion;
  2. overwriting or clearing;
  3. cryptographic erasure;
  4. purging;
  5. physical destruction; and
  6. anonymization.

26. Equipment and Storage-Media Disposal

Where Provider relies on a cloud infrastructure provider, Provider may rely on the provider’s documented media-sanitization and hardware-disposal controls.

27. Accidental Deletion

Suspected accidental, premature, or unauthorized deletion of material information must be reported promptly to privacy@proctorly.co.

Provider will evaluate:

  1. the information affected;
  2. whether recovery is possible;
  3. the business or customer impact;
  4. whether contractual notification is required;
  5. whether the event constitutes a Security Incident;
  6. whether corrective action is required; and
  7. whether retention or access controls should be modified.

28. Exceptions

Exceptions to this Policy must be:

  1. documented;
  2. limited in scope and duration;
  3. supported by a legitimate business, technical, security, or legal reason;
  4. approved by the Privacy Team; and
  5. reviewed periodically.

29. Compliance Monitoring

Provider may periodically review:

  1. system retention settings;
  2. backup configurations;
  3. cloud-storage lifecycle rules;
  4. inactive accounts;
  5. Subprocessor retention practices;
  6. deletion-request records;
  7. Legal Holds; and
  8. exceptions to this Policy.

30. Policy Review

Provider will review this Policy at least annually and following material changes to:

  1. the Services;
  2. Provider’s data-processing activities;
  3. applicable law;
  4. contractual commitments;
  5. infrastructure or Subprocessors;
  6. backup practices;
  7. security risks; or
  8. deletion capabilities.

31. Contact Information

Questions regarding this Policy should be directed to:

SchoolToolz

Privacy Contact: Privacy Team

Email: privacy@proctorly.co

Security Contact: Security Team

Email: security@proctorly.co

Mailing Address: Durham, North Carolina, United States


SCHEDULE 1

DATA RETENTION SCHEDULE

The periods below reflect Provider’s current configuration as of the Effective Date.

Information CategoryRetention TriggerRetention PeriodDisposal MethodResponsible Owner
Webcam snapshotsAfter session submit30 days by default (1–365 days configurable)Automated database deletion; R2 object deletion via scheduled daily purgeEngineering
Screen snapshotsAfter session submit30 days by default (1–365 days configurable)Automated database deletion; R2 object deletion via scheduled daily purgeEngineering
Short audio clipsAfter session submit30 days by default (1–365 days configurable)Automated database deletion; R2 object deletion via scheduled daily purgeEngineering
ID photos / setup photosExam review completed or session/test deletionManual or cancellation-triggeredSecure deletionEngineering
Short screen-share clipsExam review completed or session/test deletionManual or cancellation-triggeredSecure deletionEngineering
Integrity flagsParent session/test deletion or cancellationManual or cancellation-triggeredSecure deletionEngineering
AI integrity reportsParent session/test deletion or cancellationManual or cancellation-triggeredSecure deletionEngineering
AI prompts and model inputsAfter processing30 daysAutomated deletion; vendor copies governed by AI Subprocessor termsEngineering
Generated AI outputs (not part of a customer record)After delivery30 daysAutomated deletionEngineering
AI evaluation and safety dataAfter collection90 daysAutomated deletionEngineering
AI model-performance logsAfter collection90 daysAutomated deletionEngineering
Activity Insight events180 days after session submit180 daysAutomated daily jobEngineering
Activity Insight reports365 days from creation365 daysAutomated daily jobEngineering
Student session metadataParent session/test deletion or cancellationManual or cancellation-triggeredSecure deletionEngineering
Student name/email associated with a sessionParent session/test deletion or cancellationManual or cancellation-triggeredSecure deletionEngineering
Soft-deleted testsAfter soft deletion90 daysAutomated daily jobEngineering
Institutional data on subscription cancellationAfter cancellation90 days, including a 30-day cancellation grace period and a 30-day export windowAutomated daily jobEngineering
Audit logsDate of event730 daysAutomated daily database jobSecurity / Engineering
Teacher account dataAccount deletion requestManual, via support requestSecure deletionProduct / Privacy
Subscription and billing recordsTransaction or fiscal-year endRequired accounting/tax/legal periodSecure deletionFinance
Transactional emailsNot stored locallyUp to 30 days after delivery in ResendDeleted or overwritten per Resend retentionEngineering
Support messagesNot stored locallyUp to 30 days after the request is resolvedDeleted or overwritten per email/support-system retentionEngineering
Sentry / error logsPer Sentry planVendor retention settingVendor-controlledEngineering
Analytics dataPer PostHog planVendor retention settingVendor-controlledEngineering
BackupsBackup creation30 days; point-in-time recovery limited to 7 days (per current Supabase plan)Automated expirationInfrastructure
Consent / authorization recordsEnd of relationship + legal holdDuration of relationship + legal holdManual / internalPrivacy / Legal
School contracts and DPA recordsContract terminationContract term + legal retentionSecure deletionLegal
Security incident recordsIncident closure5 yearsSecure deletionSecurity / Legal
Vulnerability findingsRemediation or closure3 yearsSecure deletionSecurity
Penetration-test reportsReport date3 yearsSecure deletionSecurity
Deletion-request recordsCompletion of request3 yearsSecure deletionPrivacy
Marketing and waitlist contact informationLast interaction or withdrawal12 monthsDeletion, subject to suppression recordMarketing / Privacy
Website analyticsDate of collectionPer provider settings (12–25 months)Automated expiration or aggregationMarketing / Product
Cookie identifiersDate placedPer published cookie durationAutomated expirationMarketing / Privacy
Anonymized statistical dataCompletion of anonymizationIndefinite, subject to safeguardsN/AProduct / Analytics