Data Retention and Deletion Policy
Effective July 24, 2026
Policy Owner: Privacy Team
Approved By: SchoolToolz / Proctorly
Effective Date: July 24, 2026
Version: 1.0
Review Cycle: At least annually
Last Reviewed: July 24, 2026
1. Purpose
This Data Retention and Secure Deletion Policy ("Policy") establishes the requirements of SchoolToolz, operating Proctorly ("Provider," "Company," "we," "us," or "our") for:
- retaining information only for legitimate business, contractual, security, and legal purposes;
- establishing documented retention periods;
- responding to deletion requests;
- securely deleting or anonymizing information when it is no longer required;
- managing information stored in backups, archives, logs, and third-party systems; and
- documenting exceptions, including litigation holds and legal retention obligations.
This Policy is intended to reduce unnecessary data storage while supporting the operation, security, reliability, and legal compliance of the Proctorly platform and related services.
2. Scope
This Policy applies to information created, received, maintained, transmitted, or otherwise processed by Provider in connection with:
- the Services;
- Provider websites and applications;
- customer and user accounts;
- customer support;
- billing and financial administration;
- security and system monitoring;
- Subprocessors acting on Provider's behalf; and
- Provider’s vendors, service providers, and subprocessors.
This Policy applies to information stored in:
- production systems;
- databases;
- file-storage systems;
- email and communication systems;
- customer-support systems;
- analytics platforms;
- development and testing environments;
- archives;
- backups; and
- systems operated by third parties on Provider’s behalf.
3. Definitions
3.1 Customer Data
"Customer Data" means data, information, files, records, or content submitted to, stored in, transmitted through, or otherwise processed by the Services on behalf of a customer.
3.2 Personal Data
"Personal Data" means information that identifies, relates to, describes, is reasonably capable of being associated with, or could reasonably be linked to an identifiable individual or household.
3.3 Production Data
"Production Data" means information maintained in live systems used to provide the Services to customers and users.
3.4 Deletion
"Deletion" means rendering information inaccessible or removing it from active systems so that it is no longer available for ordinary business use.
3.5 Anonymization
"Anonymization" means processing information so that it can no longer reasonably be associated with an identifiable customer, user, or individual.
3.6 Backup
"Backup" means a copy of information maintained primarily for disaster recovery, operational resilience, system restoration, or business continuity.
3.7 Legal Hold
"Legal Hold" means an instruction to preserve information that might otherwise be deleted because it may be relevant to litigation, an investigation, an audit, a regulatory matter, or another legal obligation.
3.8 Subprocessor
"Subprocessor" means a third party engaged by Provider to process Customer Data on Provider’s behalf in connection with the Services.
4. Policy Principles
Provider will manage information according to the following principles.
4.1 Purpose Limitation
Information will be retained only when Provider has a legitimate business, contractual, operational, security, or legal reason to retain it.
4.2 Data Minimization
Provider will seek to collect and retain only the information reasonably necessary for the identified purpose.
4.3 Defined Retention Periods
Each material category of information will have:
- an identified business owner;
- a stated retention purpose;
- a retention period or deletion trigger;
- an approved deletion method; and
- any applicable legal or contractual exception.
4.4 Secure Storage
Information will remain subject to Provider’s applicable security safeguards throughout its retention period.
4.5 Timely Deletion
Information will be deleted, anonymized, aggregated, or rendered inaccessible after the applicable retention period expires, unless continued retention is authorized under this Policy.
4.6 Consistency
Retention and deletion requirements will be applied consistently across Provider-controlled systems, subject to technical limitations and documented exceptions.
4.7 No Indefinite Retention by Default
Information will not be retained indefinitely merely because storage is available or deletion is inconvenient.
5. Determining Retention Periods
Provider will consider the following factors when establishing a retention period:
- the purpose for which the information was collected;
- whether the information remains necessary to provide the Services;
- customer instructions and contractual commitments;
- applicable legal and regulatory requirements;
- tax, accounting, insurance, and audit obligations;
- limitation periods for potential legal claims;
- fraud-prevention and information-security needs;
- the sensitivity and volume of the information;
- the risk of harm from unauthorized access;
- whether the information can be anonymized;
- technical deletion capabilities;
- backup and disaster-recovery requirements; and
- whether a Legal Hold applies.
6. Data Classification
Information covered by this Policy should be classified according to Provider’s applicable data-classification standard.
| Classification | Description |
|---|---|
| Public | Information approved for public disclosure |
| Internal | Non-public business information intended for internal use |
| Confidential | Sensitive business, customer, employee, or contractual information |
| Restricted | Highly sensitive or regulated information requiring enhanced protection |
7. Retention Schedule
Provider will maintain a retention schedule identifying the approved retention period for material categories of information.
The schedule in Schedule 1 may be adapted to Provider’s actual systems, contractual obligations, and legal requirements.
A retention period may be based on:
- a fixed period;
- the duration of an active customer relationship;
- account closure;
- contract expiration or termination;
- completion of a transaction;
- resolution of a support request;
- expiration of a legal requirement;
- the date of an individual’s deletion request; or
- another documented business event.
8. Active Customer Accounts
While a customer account remains active, Provider may retain Customer Data as necessary to:
- provide the Services;
- maintain customer configurations;
- authenticate users;
- process transactions;
- provide customer support;
- maintain security and prevent fraud;
- generate customer-requested reports;
- comply with the Agreement; and
- comply with applicable law.
9. Account Termination and Expiration
Following expiration, termination, or cancellation of a customer’s Services:
- Provider may disable access to the customer account after any applicable cancellation grace period;
- Customer Data will remain available for export for 30 days after the applicable termination or cancellation date, unless the Agreement states otherwise;
- Customer Data will be deleted or rendered inaccessible from active production systems within 90 days after the applicable termination or cancellation date, which period includes the 30-day export window and any applicable 30-day cancellation grace period;
- residual copies may remain in backups until the applicable backup-rotation period expires;
- billing, transaction, contractual, security, and compliance records may be retained separately under the applicable retention schedule; and
- information subject to a Legal Hold or another legal obligation will be preserved until the hold or obligation ends.
10. Customer-Requested Deletion
Customers may request deletion of Customer Data by:
- using available deletion controls within the Services; or
- submitting a request to privacy@proctorly.co.
Provider may require reasonable information to:
- verify the request;
- confirm the requester’s authority;
- identify the relevant account or information;
- protect against fraudulent or unauthorized deletion; and
- determine whether an exception applies.
Provider will process verified deletion requests within the period required by the Agreement or applicable law.
Where Provider acts as a processor or service provider on behalf of a customer, Provider may direct an individual to submit the request to the applicable customer acting as the controller or business.
11. Individual Privacy Requests
Provider will maintain procedures for responding to valid requests from individuals to delete Personal Data where required by applicable law.
Provider may deny, limit, or delay a deletion request where continued retention is reasonably necessary to:
- complete a transaction requested by the individual;
- provide a product or service requested by the individual;
- maintain account security;
- detect and prevent fraud or unlawful activity;
- debug or repair errors;
- comply with a legal obligation;
- establish, exercise, or defend legal claims;
- preserve freedom of expression or another protected right;
- protect the rights and safety of Provider, its customers, or others;
- maintain information subject to a Legal Hold; or
- satisfy another legally recognized exception.
12. Customer Data in Production Systems
Deletion from production systems may occur through:
- automated retention jobs;
- application deletion functions;
- database deletion procedures;
- removal of storage objects;
- expiration policies;
- anonymization;
- cryptographic erasure; or
- authorized administrative procedures.
13. Backup Retention and Deletion
Provider may maintain encrypted backups for disaster recovery, operational resilience, and business continuity.
Unless otherwise stated in an applicable agreement:
- backups will be retained on a rolling basis for 30 days, based on the cloud provider’s current Supabase backup plan;
- point-in-time recovery is limited to 7 days, based on the cloud provider’s current Supabase plan;
- deleted information may remain in backups until the backup containing the information expires or is overwritten;
- backups will not ordinarily be modified solely to delete individual records;
- information retained in backups will remain protected under Provider’s security program;
- access to backups will be restricted;
- backups will not be used for ordinary business processing;
- backups will be restored only when reasonably necessary for disaster recovery, security, testing, or continuity purposes; and
- if deleted information is restored, Provider will take reasonable steps to reapply the applicable deletion instruction.
14. Logs and Security Records
Provider may retain security, audit, application, access, and diagnostic logs for purposes including:
- detecting and investigating security events;
- preventing fraud and abuse;
- troubleshooting errors;
- monitoring availability and performance;
- maintaining an audit trail;
- complying with legal requirements; and
- enforcing Provider’s agreements.
Sensitive values such as passwords, authentication secrets, payment-card security codes, and private cryptographic keys must not knowingly be written to logs.
15. Development and Testing Environments
Provider will avoid using Production Data in development or testing environments unless reasonably necessary and appropriately authorized.
Where Production Data is used:
- access will be limited;
- the environment will be appropriately secured;
- the information should be minimized or masked where practicable;
- the purpose and duration of use should be documented; and
- the information will be deleted when the testing purpose ends.
16. Customer Support Information
Support tickets, chat messages, emails, call records, attachments, and troubleshooting materials may be retained to:
- resolve customer issues;
- maintain service history;
- train authorized support personnel;
- improve support quality;
- prevent fraud and abuse; and
- establish a record of customer instructions.
Provider does not store support messages in Proctorly’s database; messages are forwarded directly to support@proctorly.co via Resend. Copies may remain in Resend and Provider’s email/support systems for up to 30 days after the support request is resolved, and are then deleted or overwritten according to the provider’s retention schedule and normal backup rotation.
17. Financial and Transaction Records
Provider may retain invoices, payment confirmations, refunds, tax records, accounting entries, and related transaction information for the period necessary to comply with:
- tax requirements;
- accounting requirements;
- financial audits;
- fraud-prevention obligations;
- chargeback or dispute procedures; and
- applicable recordkeeping laws.
Provider does not store complete payment-card details; payment processing is performed by Stripe.
18. Marketing and Sales Information
Provider may retain prospect and marketing information while:
- a business relationship remains active;
- the individual continues to engage with Provider;
- Provider has a valid business or legal basis to maintain the information; or
- retention is necessary to honor an unsubscribe, objection, or suppression request.
Suppression records may be retained after other marketing information is deleted to ensure that Provider continues to honor opt-out requests.
19. Cookies, Analytics, and Device Information
Cookie identifiers, analytics records, IP addresses, device information, and usage data will be retained according to:
- the purpose of the applicable cookie or technology;
- Provider’s published Privacy Policy and cookie disclosures;
- the settings of the analytics provider;
- customer configuration;
- user consent or preferences; and
- applicable law.
Student-facing routes (/t/*) are excluded from analytics tracking. Only teacher-facing usage is tracked.
20. Artificial Intelligence Data
Where Provider uses artificial intelligence systems in connection with the Services, Provider will establish and document retention rules for:
- user prompts;
- uploaded content;
- model inputs;
- generated outputs;
- evaluation data;
- safety-monitoring data;
- model-performance logs; and
- data transmitted to an artificial intelligence Subprocessor.
Unless a longer period is required by law, support, safety, or debugging needs:
- prompts, model inputs, and uploaded content will be retained for no longer than 30 days after processing;
- generated outputs that are stored as part of a customer record will be retained under the retention period that applies to that record (e.g., the applicable session, test, or report retention period);
- other generated outputs will be retained for no longer than 30 days after delivery;
- evaluation and safety-monitoring data will be retained for no longer than 90 days;
- model-performance logs will be retained for no longer than 90 days;
- vendor copies will be retained only as long as required by the AI Subprocessor or eliminated through zero-data-retention or equivalent settings where available.
Customer Data will not be retained for the purpose of training a publicly available or generally shared artificial intelligence model.
Provider will configure third-party artificial intelligence services to minimize or disable vendor retention and training use where commercially and technically available.
21. Children’s and Student Data
Provider will retain children’s or student data only:
- as directed by the applicable school, district, parent, guardian, or other authorized customer;
- for the period necessary to provide the Services;
- as required by the applicable contract; or
- as required by law.
Upon termination of the applicable school or customer agreement, Provider will delete or return the relevant student data according to:
- the customer’s documented instructions;
- the applicable student-data agreement;
- the applicable Data Processing Addendum; and
- applicable education and children’s privacy laws.
Student data will not be retained for unrelated advertising or commercial profiling purposes.
22. Anonymized and Aggregated Information
Provider may retain anonymized or aggregated information for longer periods, including indefinitely, where the information:
- cannot reasonably be associated with a customer or identifiable individual;
- is not maintained with information capable of reversing the anonymization;
- is subject to reasonable controls against re-identification; and
- is used for legitimate purposes such as service analytics, research, security, forecasting, or product improvement.
23. Legal Holds
When Provider reasonably anticipates litigation, receives a subpoena, becomes subject to an investigation, or otherwise has a legal duty to preserve information, Provider may suspend ordinary deletion procedures for relevant information.
A Legal Hold notice should identify:
- the information to be preserved;
- the systems or custodians involved;
- the reason for the hold;
- the effective date;
- the responsible legal or compliance contact; and
- the conditions for releasing the hold.
24. Subprocessors and Third-Party Systems
Provider will take reasonable steps to ensure that Subprocessors processing Customer Data:
- retain Customer Data only as necessary to provide their contracted services;
- delete or return Customer Data following termination of their services;
- maintain appropriate security measures during retention;
- comply with Provider’s documented deletion instructions;
- address information remaining in backups; and
- notify Provider of material limitations affecting deletion.
25. Secure Deletion Methods
Provider will select a deletion or sanitization method appropriate to:
- the type of storage medium;
- the sensitivity of the information;
- the risk of recovery;
- the intended future use of the media;
- contractual requirements; and
- applicable legal or industry standards.
Approved methods may include:
- logical deletion;
- overwriting or clearing;
- cryptographic erasure;
- purging;
- physical destruction; and
- anonymization.
26. Equipment and Storage-Media Disposal
Where Provider relies on a cloud infrastructure provider, Provider may rely on the provider’s documented media-sanitization and hardware-disposal controls.
27. Accidental Deletion
Suspected accidental, premature, or unauthorized deletion of material information must be reported promptly to privacy@proctorly.co.
Provider will evaluate:
- the information affected;
- whether recovery is possible;
- the business or customer impact;
- whether contractual notification is required;
- whether the event constitutes a Security Incident;
- whether corrective action is required; and
- whether retention or access controls should be modified.
28. Exceptions
Exceptions to this Policy must be:
- documented;
- limited in scope and duration;
- supported by a legitimate business, technical, security, or legal reason;
- approved by the Privacy Team; and
- reviewed periodically.
29. Compliance Monitoring
Provider may periodically review:
- system retention settings;
- backup configurations;
- cloud-storage lifecycle rules;
- inactive accounts;
- Subprocessor retention practices;
- deletion-request records;
- Legal Holds; and
- exceptions to this Policy.
30. Policy Review
Provider will review this Policy at least annually and following material changes to:
- the Services;
- Provider’s data-processing activities;
- applicable law;
- contractual commitments;
- infrastructure or Subprocessors;
- backup practices;
- security risks; or
- deletion capabilities.
31. Contact Information
Questions regarding this Policy should be directed to:
SchoolToolz
Privacy Contact: Privacy Team
Email: privacy@proctorly.co
Security Contact: Security Team
Email: security@proctorly.co
Mailing Address: Durham, North Carolina, United States
SCHEDULE 1
DATA RETENTION SCHEDULE
The periods below reflect Provider’s current configuration as of the Effective Date.
| Information Category | Retention Trigger | Retention Period | Disposal Method | Responsible Owner |
|---|---|---|---|---|
| Webcam snapshots | After session submit | 30 days by default (1–365 days configurable) | Automated database deletion; R2 object deletion via scheduled daily purge | Engineering |
| Screen snapshots | After session submit | 30 days by default (1–365 days configurable) | Automated database deletion; R2 object deletion via scheduled daily purge | Engineering |
| Short audio clips | After session submit | 30 days by default (1–365 days configurable) | Automated database deletion; R2 object deletion via scheduled daily purge | Engineering |
| ID photos / setup photos | Exam review completed or session/test deletion | Manual or cancellation-triggered | Secure deletion | Engineering |
| Short screen-share clips | Exam review completed or session/test deletion | Manual or cancellation-triggered | Secure deletion | Engineering |
| Integrity flags | Parent session/test deletion or cancellation | Manual or cancellation-triggered | Secure deletion | Engineering |
| AI integrity reports | Parent session/test deletion or cancellation | Manual or cancellation-triggered | Secure deletion | Engineering |
| AI prompts and model inputs | After processing | 30 days | Automated deletion; vendor copies governed by AI Subprocessor terms | Engineering |
| Generated AI outputs (not part of a customer record) | After delivery | 30 days | Automated deletion | Engineering |
| AI evaluation and safety data | After collection | 90 days | Automated deletion | Engineering |
| AI model-performance logs | After collection | 90 days | Automated deletion | Engineering |
| Activity Insight events | 180 days after session submit | 180 days | Automated daily job | Engineering |
| Activity Insight reports | 365 days from creation | 365 days | Automated daily job | Engineering |
| Student session metadata | Parent session/test deletion or cancellation | Manual or cancellation-triggered | Secure deletion | Engineering |
| Student name/email associated with a session | Parent session/test deletion or cancellation | Manual or cancellation-triggered | Secure deletion | Engineering |
| Soft-deleted tests | After soft deletion | 90 days | Automated daily job | Engineering |
| Institutional data on subscription cancellation | After cancellation | 90 days, including a 30-day cancellation grace period and a 30-day export window | Automated daily job | Engineering |
| Audit logs | Date of event | 730 days | Automated daily database job | Security / Engineering |
| Teacher account data | Account deletion request | Manual, via support request | Secure deletion | Product / Privacy |
| Subscription and billing records | Transaction or fiscal-year end | Required accounting/tax/legal period | Secure deletion | Finance |
| Transactional emails | Not stored locally | Up to 30 days after delivery in Resend | Deleted or overwritten per Resend retention | Engineering |
| Support messages | Not stored locally | Up to 30 days after the request is resolved | Deleted or overwritten per email/support-system retention | Engineering |
| Sentry / error logs | Per Sentry plan | Vendor retention setting | Vendor-controlled | Engineering |
| Analytics data | Per PostHog plan | Vendor retention setting | Vendor-controlled | Engineering |
| Backups | Backup creation | 30 days; point-in-time recovery limited to 7 days (per current Supabase plan) | Automated expiration | Infrastructure |
| Consent / authorization records | End of relationship + legal hold | Duration of relationship + legal hold | Manual / internal | Privacy / Legal |
| School contracts and DPA records | Contract termination | Contract term + legal retention | Secure deletion | Legal |
| Security incident records | Incident closure | 5 years | Secure deletion | Security / Legal |
| Vulnerability findings | Remediation or closure | 3 years | Secure deletion | Security |
| Penetration-test reports | Report date | 3 years | Secure deletion | Security |
| Deletion-request records | Completion of request | 3 years | Secure deletion | Privacy |
| Marketing and waitlist contact information | Last interaction or withdrawal | 12 months | Deletion, subject to suppression record | Marketing / Privacy |
| Website analytics | Date of collection | Per provider settings (12–25 months) | Automated expiration or aggregation | Marketing / Product |
| Cookie identifiers | Date placed | Per published cookie duration | Automated expiration | Marketing / Privacy |
| Anonymized statistical data | Completion of anonymization | Indefinite, subject to safeguards | N/A | Product / Analytics |