Updated 19 September 2026
Data retention, deletion and handover
The table describes current storage and deletion boundaries. It is not a claim that a complete automated retention schedule has been deployed. Institution-specific periods and backup arrangements must be agreed before rollout.
| Record | Retention and removal |
|---|---|
| Browser drafts | Remain until removed through the relevant tool or browser storage controls; your browser may also evict them. |
| Saved career records and versions | Retained until deleted through the authenticated career-data controls or reviewed request. No automatic age-based purge is represented here. |
| Encrypted vault copies | Individual records can be removed; export an encrypted backup before deletion. Keep the original passphrase separately. Other copies and backups require separate handling. |
| Accounts, invitations and usage records | Account-wide requests require review; switching off new activity collection does not automatically erase previous records. |
| Payments, support, security logs and privacy requests | Retention periods and any applicable recordkeeping duties need an approved operational schedule. No unsupported statutory number of years is asserted. |
| Providers and backups | Provider deletion and backup expiry are separate from application deletion. Their deployed schedules must be confirmed; instant or universal erasure is not promised. |
| Cookie choices | Expire after 180 days. Optional affiliate attribution expires after 30 days. |
Institutional exit and continuity
Agree the export scope, ownership, student access after subscription expiry, authorised recipients, retention periods, backup expiry and deletion confirmation in writing. Aggregate reporting is not a complete export of every student’s private documents. Private vault recovery requires the student’s passphrase.
Download the proposed handover checklist. It is a planning template, not evidence of a completed handover.