Updated 19 September 2026

Data retention, deletion and handover

The table describes current storage and deletion boundaries. It is not a claim that a complete automated retention schedule has been deployed. Institution-specific periods and backup arrangements must be agreed before rollout.

RecordRetention and removal
Browser draftsRemain until removed through the relevant tool or browser storage controls; your browser may also evict them.
Saved career records and versionsRetained until deleted through the authenticated career-data controls or reviewed request. No automatic age-based purge is represented here.
Encrypted vault copiesIndividual records can be removed; export an encrypted backup before deletion. Keep the original passphrase separately. Other copies and backups require separate handling.
Accounts, invitations and usage recordsAccount-wide requests require review; switching off new activity collection does not automatically erase previous records.
Payments, support, security logs and privacy requestsRetention periods and any applicable recordkeeping duties need an approved operational schedule. No unsupported statutory number of years is asserted.
Providers and backupsProvider deletion and backup expiry are separate from application deletion. Their deployed schedules must be confirmed; instant or universal erasure is not promised.
Cookie choicesExpire after 180 days. Optional affiliate attribution expires after 30 days.

Institutional exit and continuity

Agree the export scope, ownership, student access after subscription expiry, authorised recipients, retention periods, backup expiry and deletion confirmation in writing. Aggregate reporting is not a complete export of every student’s private documents. Private vault recovery requires the student’s passphrase.

Download the proposed handover checklist. It is a planning template, not evidence of a completed handover.